Source description
About the role
Job Description SENIOR SECURITY ANALYST AI & APPLICATION SECURITY Location: India Remote Employment: Full-Time with InnoveusIT,Inc Working for InnoveusIT's Customer : Enterprise SaaS Product Company Energy, Utilities & Asset-Intensive Industries About InnoveusIT InnoveusIT, Inc. is a U.S.-based IT consulting and talent solutions company headquartered in Atlanta, with a global delivery network ecosystem of 1,000+ technology professionals. We support organizations across Cloud, Infrastructure, Cybersecurity, Data & AI, Digital Engineering, Salesforce, SAP, ITSM, and Digital Transformation. Our specialized executive-search and talent practice helps leading IT services and technology companies identify high-performing professionals for niche technology, enterprise sales, business development, and leadership roles across the United States. For this opportunity, InnoveusIT is supporting the hiring organization as its recruitment and talent partner. We are seeking a Senior Security Analyst AI & AI & Application Security to join our Information Security & Compliance team. This is a hands-on, high-impact role responsible for strengthening our application security posture, driving vulnerability management maturity, governing AI tool adoption and compliance, and supporting security operations across our cloud-hosted SaaS environment. The successful candidate will serve as a technical security practitioner embedded within our engineering and operations ecosystem, partnering closely with IT, business, DevOps, and compliance teams. To be successful in this role, you should have extensive experience with CrowdStrike Falcon, including its Next-Gen SIEM, Data Protection, CSPM, and Threat Intelligence capabilities, as well as experience coordinating penetration tests and running vulnerability assessments with Qualys. You should have hands-on experience with Rapid7, CI/CD pipeline hardening, cloud security in AWS and/or Azure, and security architecture. Experience implementing process improvements and driving program maturity aligned with NIST CSF 2.0 is essential. Familiarity with AI governance frameworks (ISO/IEC 42001, NIST AI RMF) and experience evaluating AI and SaaS tools for security and compliance risk is strongly desired. You should also have excellent communication, problem-solving, and analytical skills, as well as the ability to work independently and as part of a team. ESSENTIAL DUTIES AND RESPONSIBILITIES Application Security (AppSec) - Lead application security testing activities including SAST, DAST, and software composition analysis (SCA) across the SDLC. Coordinate and manage third-party penetration tests for web applications, APIs, and cloud infrastructure; track remediation to closure.Leverage Qualys for vulnerability scanning, asset discovery, and prioritized remediation tracking across application and infrastructure layers.Evaluate, implement, and manage a centralized application vulnerability management platform (such as DefectDojo) to consolidate findings from all scanning tools, penetration tests, and manual assessments into a single pane of glass view across customer's application portfolio; drive consistent tracking, prioritization, and remediation workflows across teams.Integrate security testing tooling into CI/CD pipelines including pipeline hardening, automated scanning gates, and secrets detection.Conduct security architecture reviews for new features, integrations, and third-party components. Security Operations & Detection - Operate and optimize CrowdStrike Next-Gen SIEM for threat detection, alert triage, investigation, and incident response. Leverage CrowdStrike Threat Intelligence and Data Protection capabilities to identify, investigate, and contain emerging threats.Use Rapid7 for vulnerability management, risk prioritization, and reporting; correlate findings with CrowdStrike telemetry for enriched context.Conduct proactive threat hunting and perform root cause analysis on security incidents.Develop and refine detection rules, correlation logic, and response playbooks.Prepare and maintain security reports, logs, and documentation. AI Tool Governance & Procured Technology Compliance - Maintain and enforce customer's AI Tool Inventory; conduct periodic reviews to validate that all IT-procured and employee-adopted AI tools are catalogued, risk-classified, and reviewed against customer AI policies.Partner with Legal and IT to perform security reviews of AI and SaaS tools prior to onboarding; evaluate vendor security posture using UpGuard, complete AI-specific controls in vendor onboarding questionnaires, and document findings in the vendor risk register.Monitor procured AI tools and IT-managed platforms for compliance with data handling, access control, Job Description SENIOR SECURITY ANALYST AI & APPLICATION SECURITY Location: India Remote Employment: Full-Time with InnoveusIT,Inc Working for InnoveusIT's Customer : Enterprise SaaS Product C