CybersecurityJobs.io
← Back to all jobs

Job Description

CCC Intelligent Solutions Inc. is seeking an Application Security Analyst to help embed application security across the software development lifecycle. In this onsite role in Chicago, IL, you will work closely with development and engineering teams to identify, assess, prioritize, and remediate application security risks, strengthening both engineering practices and the organization’s security posture.

What you’ll do

  • Conduct application security assessments using static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), and manual validation of results.
  • Review and triage security findings by separating true positives from false positives and support development teams in prioritizing remediation.
  • Support secure software development lifecycle (SSDLC) initiatives and security-by-design practices across engineering teams.
  • Perform threat modeling and security reviews for new applications, services, and technology implementations.
  • Collaborate with development teams to identify security weaknesses and provide remediation guidance.
  • Assist with penetration testing coordination and validate remediation activities.
  • Develop and maintain application security metrics, reporting, and dashboards tied to application security risk.
  • Support vulnerability management processes, including identification, prioritization, tracking, and verification of remediation.
  • Create automation, scripts, and integrations to improve security workflows and reduce manual effort.
  • Evaluate software supply chain risks and support secure use of open-source components.
  • Help develop security standards, procedures, and secure coding guidance.
  • Deliver security awareness and secure coding training to engineering teams.
  • Support incident response activities involving application security vulnerabilities when required.
  • Be familiar with AI workflows and support AI enablement.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
  • Understanding of common web application vulnerabilities, including the OWASP Top 10.
  • Experience with security testing tools such as SAST, DAST, SCA, and secrets detection platforms.
  • Knowledge of application architectures, APIs, cloud-native applications, and modern development practices.
  • Scripting experience with Python, PowerShell, JavaScript, Go, or similar languages.
  • Familiarity with CI/CD pipelines and source control platforms such as GitHub, GitLab, or Azure DevOps.
  • Strong analytical, troubleshooting, and communication skills.
  • Ability to communicate technical findings to both technical and non-technical stakeholders.

Technologies you may work with

  • OWASP Top 10
  • SAST, DAST, SCA, secrets detection platforms
  • Python, PowerShell, JavaScript, Go
  • CI/CD pipelines, GitHub, GitLab, Azure DevOps
  • Endor Labs, Wiz, GitHub Advanced Security, Veracode, Checkmarx, Burp Suite
  • Azure, AWS, GCP
  • Security+, GSEC, CSSLP, GWAPT, OSCP

Benefits

  • 401K Match
  • Paid time off
  • Annual Incentive Plan Performance Bonus
  • Comprehensive health insurance
  • Adoption Assistance
  • Tuition Reimbursement
  • Wellness Programs
  • Stock Purchase Plan options
  • Employee Resource Groups

Preferred qualifications

  • Experience with software supply chain security programs.
  • Familiarity with tools such as Endor Labs, Wiz, GitHub Advanced Security, Veracode, Checkmarx, Burp Suite, or similar technologies.
  • Knowledge of cloud security concepts across Azure, AWS, or GCP.
  • Experience automating security processes and workflow integrations.
  • Relevant certifications such as Security+, GSEC, CSSLP, GWAPT, OSCP, or related credentials.
  • Experience participating in secure architecture reviews and threat modeling exercises.

Salary and education

  • Location: Chicago, IL (onsite)
  • Salary: USD 56,930 - 70,000 per yearly
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience

Success measures

  • Reduction in application security risk through effective vulnerability identification and remediation.
  • Timely validation and prioritization of security findings.
  • Increased adoption of secure development practices across engineering teams.
  • Improvements in security automation and operational efficiency.
  • Strong partnership and engagement with developers, architects, and product teams.
  • Contribution to measurable improvements in the organization’s security posture.

Interview policy & privacy notice

  • A video interview is required for this position.
  • Video interviews are transcribed.
  • Transcriptions are retained and may be reviewed by CCC and our recruiters.
  • Candidates are not permitted to use generative AI or automated assistance during the interviews unless explicitly allowed by the interview team for a specific exercise.

Similar Jobs