Apply with hirly
Offensive Application Security Analyst
Countryfinancial · Bloomington, IL
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Experience more with a career at COUNTRY Financial! We’re excited you’re interested in a career at COUNTRY as we strive toward our vision
- to enrich lives in the communities we serve. Our footprint spans coast to coast. But more important than where we operate, is the people who do the work. Apply today to help our organization grow and make a difference for our clients. About the role The Offensive Application Security Analyst helps improve the security of COUNTRY Financial's applications and technology platforms through a blend of application security assessment and adversary emulation activities. This role spends approximately 50% of time supporting the Application Security program and 50% supporting Threat Intelligence & Emulation initiatives. The individual will perform application security testing, assist with secure development practices, support penetration testing activities, participate in threat emulation exercises, and help validate the effectiveness of enterprise security controls. This role serves as a technical contributor who works closely with developers, infrastructure teams, incident responders, and other security professionals to identify and reduce cybersecurity risk. The position supports both secure software development and offensive security objectives Primary Responsibilities Application Security (50%)
- Perform application security assessments against web, API, mobile, and cloud applications.
- Analyze and triage findings from SAST, DAST, dependency scanning, and other security testing platforms.
- Assist development teams with vulnerability remediation guidance and secure coding recommendations.
- Participate in threat modeling and architecture review activities.
- Help improve application security automation and security testing within CI/CD pipelines.
- Support dependency management and software supply chain security initiatives.
- Collaborate with technology teams to improve secure development lifecycle practices.
- Demonstrate an understanding of Git and Git-based development workflows, including branching, pull requests, code reviews, and secure code management practices Threat Emulation (50%)
- Execute red team, purple team, and adversary emulation activities under established rules of engagement.
- Assist with internal penetration testing exercises and third-party penetration testing coordination.
- Conduct security control validation and threat-informed testing using
Mitre Att&ck
methodologies.
- Research adversary tactics, techniques, and procedures and help translate intelligence into testing scenarios.
- Perform offensive security assessments against enterprise infrastructure, cloud environments, and applications.
- Document findings and provide actionable recommendations to improve detection and prevention capabilities.
- Partner with defensive security teams to validate response and monitoring effectiveness. How does this role make an impact?
- Participates in projects and assessments on risk.
- Analyzes and defines security policies and standards.
- Monitors, alerts and responds to security events.
- Performs computer forensic and investigative activities; and penetration and vulnerability testing.
- Defines and administers identity & access roles and workflows. Do you have what we're looking for? Required Skills Technical Knowledge
- Secure software development principles and common application vulnerabilities.
- Web application security concepts including OWASP Top 10.
- Security testing methodologies including SAST, DAST, and penetration testing.
- Basic understanding of red team and purple team methodologies.
- Scripting and automation experience using PowerShell, Python, Bash, or similar languages.
- Knowledge of cloud security concepts and modern application architectures.
- Familiarity with
Mitre Att&ck
Framework concepts.
- Typically requires 3+ years of relevant experience or a combination of related experience, education and training. Professional Skills
- Strong analytical and problem-solving abilities.
- Effective written and verbal communication.
- Ability to explain technical findings to both technical and non-technical audiences.
- Strong collaboration and teamwork skills.
- Self-motivated with a desire to continuously learn and develop offensive and application security expertise. #LI-CORP #LI-Hybrid Base Pay Range: $94,400-$129,800 The base pay range represents the typical range of potential salary offers for candidates hired. Factors used to determine your actual salary include your specific skills, qualifications and experience. Incentive Pay: In addition to base salary, this position is eligible for a Short-Term Incentive plan. Why work with us? Our employees and representatives serve nearly one million households with our diverse range of personal and business insurance products as well as retirement and investment services. We build relationships and work together to create a stronger, more secure future for our clients and our communities. We’re a big company, yet small enough you can make an impact and won’t get lost in the shuffle. You’ll have the opportunity to learn and grow throughout your career, either within this role or by exploring other areas of our business. You’ll be able to take advantage of our benefits package, which includes insurance benefits (medical, dental, vision, disability, and life), 401(k) with company match. COUNTRY Financial is committed to providing equal opportunity in all areas of employment, and in providing employees with a work environment free of discrimination and harassment. Employment decisions are made without regard to race, color, religion, age, gender, sexual orientation, veteran status, national origin, disability, or any other status protected by applicable laws or regulations. Come join our team at COUNTRY today!