IMF logo

Security Analyst / Senior Security Analyst (Application Security)

IMFWashington, D.C., United States
Category | Grade:Professional | A-11 / A-12Deadline:5 Aug 2026Job ID:26-R9579Posted on:21 Jul 2026
Apply now

Overview

Leads application-security vulnerability management across IMF enterprise systems, integrating testing into software delivery, prioritising risk and guiding remediation while strengthening secure-development controls, metrics and reporting for cloud and on-premises applications.

Department: Project Portfolio Management Section, Information Technology Department

Languages

Required: English

Job Areas

  1. Cybersecurity
  2. Software Engineering & Development

Minimum Experience

4 years

Estimated Salary

Not available

Responsibilities

  • Lead vulnerability identification, validation, prioritisation, tracking and remediation
  • Manage vulnerability workflows, exceptions, compensating controls and critical-issue escalation
  • Provide risk-based remediation guidance to application owners and engineering teams
  • Integrate security requirements, threat modelling and design reviews into software delivery
  • Deploy and govern application-security testing in continuous-delivery pipelines
  • Report vulnerability severity, ageing, ownership, exceptions and remediation trends
  • Enable developers through security guidance, awareness and process improvement

Requirements

  • Advanced university degree in computer science, cybersecurity or a related field with at least four years of relevant experience, or a university degree with ten years of relevant experience
  • Experience in vulnerability management, application security, secure development or a related cybersecurity discipline
  • Knowledge of OWASP Top 10, NIST SSDF, NIST CSF and ISO 27001
  • Programming or scripting experience with Java, Python, .NET, PowerShell or a comparable language
  • Hands-on experience with static, dynamic and component-analysis testing, vulnerability assessment and penetration testing
  • Experience integrating security controls throughout the software development lifecycle

Skills

Application SecurityVulnerability ManagementRisk PrioritisationSecure Software DevelopmentThreat ModellingSecurity TestingPenetration TestingCloud SecurityRemediation GuidanceSecurity Governance

Tools

SASTDASTSCAOWASP Top 10NIST SSDFNIST CSFISO 27001ServiceNowAzure DevOps

Additional info

  • One-year contractual appointment
  • Appointment may be renewed for up to four cumulative contractual years subject to performance, budget and business need