Application Security Analyst — wHTa Networks
wHTa Networks · Mar 2025 – Present
Current, paid role focused on identifying, mitigating, and preventing vulnerabilities across web applications and CI/CD pipelines, applying a frontend development background to bridge engineering and security. Work spans SAST/DAST assessment (XSS, CSRF, injection flaws) early in the SDLC; enforcing secure coding practices aligned to OWASP Top 10 and CWE/SANS with developers, including remediation guidance and fix verification; secure authentication/authorization flow design (least privilege, session hardening, token management); reviewing API endpoints and client-server data transmission (HTTPS/TLS, input validation, output encoding); embedding security controls and automated vulnerability detection into CI/CD with DevOps/engineering teams; implementing CSPs and secure headers against client-side and browser-based attacks; and delivering internal security training and reviews.
Tools: Burp Suite, OWASP ZAP, SonarQube, Snyk
Skills demonstrated: SAST, DAST, secure SDLC, OWASP-aligned code review, secure authentication/authorization design, API security review, CI/CD security integration, content security policy (CSP) implementation, vulnerability remediation guidance, DevSecOps collaboration
Frameworks: OWASP Top 10, CWE/SANS Top 25 -- see Framework & Regulatory Knowledge
Outcome: Ongoing role since Mar 2025.