Job Posting Organization: The International Monetary Fund (IMF) is an international organization established in 1944, headquartered in Washington, D.C. Its mission is to promote global economic stability and growth by providing financial assistance, policy advice, and technical assistance to its member countries. The IMF has a diverse workforce of approximately 2,700 employees from over 150 countries, working collaboratively to address global economic challenges. The organization operates in over 190 countries, focusing on fostering international monetary cooperation and facilitating balanced growth of international trade.
Job Overview: The security" style="border-bottom: 1px dotted #007bff !important;">Security Analyst (Application Security) plays a crucial role in ensuring that security is integrated throughout the Software Development Lifecycle (SDLC). This position requires collaboration with development, infrastructure, and application teams to embed secure development practices and implement security requirements effectively. The analyst will be responsible for identifying, validating, prioritizing, tracking, and supporting the remediation of application security vulnerabilities. This role also involves driving risk-based vulnerability management activities and application security initiatives across both on-premises and cloud environments. The successful candidate will combine hands-on expertise in application security and vulnerability management with the ability to provide actionable guidance, support secure software development, and continuously improve security outcomes through governance, metrics, reporting, and adherence to security best practices.
Duties and Responsibilities:
Lead the identification, validation, prioritization, tracking, and remediation of application security vulnerabilities, ensuring that risks are addressed in accordance with established timelines and organizational priorities.
Partner with application owners and engineering teams to manage vulnerability workflows, including intake, analysis, assignment, risk-based prioritization, exception handling, remediation tracking, and escalation of critical issues.
Provide risk-based remediation recommendations and guidance to application teams to support informed security decisions and risk reduction efforts.
Support the integration of security throughout the Software Development Lifecycle (SDLC) by promoting secure coding practices, implementing security requirements, participating in threat modeling and design reviews, and helping implement security controls across on-premises and cloud environments.
Lead and support the adoption of application security testing capabilities, including SAST, DAST, and SCA solutions within CI/CD pipelines, while reviewing security findings, validating results, and providing remediation guidance.
Maintain visibility into application security posture through tracking, analysis, and reporting of vulnerability status, severity, aging, ownership, exceptions, remediation progress, and risk trends using enterprise platforms.
Stay current with emerging threats, vulnerabilities, and industry best practices while supporting security awareness, developer enablement, and continuous improvement of application security processes and standards.
Required Qualifications:
Educational development typically acquired by the completion of an advanced university degree, or equivalent, in Computer Science, Cybersecurity, or a related field, supplemented by a minimum of four (4) years of relevant professional work experience, or alternatively, a university degree, or equivalent, and ten (10) years of relevant professional experience.
Experience in Vulnerability Management, Application Security, Secure Development, or related cybersecurity disciplines.
Strong knowledge of application security principles, secure software development practices, and industry frameworks such as OWASP Top 10, NIST SSDF, NIST CSF, and ISO 2700
Experience with one or more programming or scripting languages (e.g., Java, Python, .NET, PowerShell) and the ability to analyze application security findings and support remediation efforts.
Understanding of secure architecture principles for web, cloud, and enterprise applications, including common attack vectors and mitigation techniques.
Hands-on experience with application security testing methodologies and tools, including SAST, DAST, SCA, vulnerability assessments, and penetration testing.
Strong understanding of vulnerability management processes, including vulnerability validation, risk-based prioritization, remediation tracking, exception management, compensating controls, and vulnerability lifecycle management.
Experience collaborating with development and engineering teams to integrate security requirements and controls throughout the Software Development Lifecycle (SDLC).
Ability to analyze security risks, communicate technical findings to diverse audiences, and provide actionable remediation guidance. 1
Strong communication, analytical, stakeholder management, and collaboration skills, with the ability to influence security outcomes across cross-functional teams.
Educational Background: The position requires an advanced university degree in Computer Science, Cybersecurity, or a related field. Alternatively, a university degree with significant professional experience in relevant areas is acceptable. The educational background should provide a strong foundation in technical skills and knowledge necessary for application security and vulnerability management.
Experience: Candidates should have a minimum of four (4) years of relevant professional work experience in the fields of Vulnerability Management, Application Security, Secure Development, or related cybersecurity disciplines. Alternatively, candidates with a university degree and ten (10) years of relevant professional experience will also be considered. Experience should include hands-on work with application security testing methodologies and tools, as well as collaboration with development teams to integrate security practices into the SDLC.
Languages: While the job posting does not specify mandatory languages, proficiency in English is typically required for positions at the IMF due to its international nature. Additional languages may be beneficial but are not explicitly stated as requirements.
Additional Notes: This position is a one-year contractual appointment, with the possibility of renewal for up to four years of cumulative contractual service, depending on the incumbent's performance, budget availability, and continuous business need. The IMF is committed to diversity and inclusion, ensuring that employment, classification, promotion, and assignment of staff are made without discrimination against any person. The organization welcomes requests for reasonable accommodations for disabilities during the selection process, and information on how to request accommodations will be provided during the application process.
Info
Job Posting Disclaimer
This job posting is provided for informational purposes only. The accuracy of the job description, qualifications, and other details mentioned is the sole responsibility of the employer or the organization listing the job. We do not guarantee the validity or legitimacy of this job posting. Candidates are advised to conduct their own due diligence and verify the details directly with the employer before applying.
We are not liable for any decisions or actions taken by applicants in response to this job listing. By applying, you agree that all application processes, interviews, and potential job offers are managed exclusively by the listed employer or organization.
Beware of fraudulent job offers. Do not provide sensitive personal information or make any payments to secure a job.