Offensive Application Security Analyst
Application Security
Application Security Engineering
Cybersecurity Tools
Data Analysis
Data Security
Dependency Scanning
Dynamic Application Security Testing
Facilities Management
Information Security
Information Technology (IT)
InfoSec
Mitre Att&ck
Risk Management
Security
Security Automation
Security Standards
Security Testing
Software Security
Static Application Security Testing
Threat Modeling
Job Description
The Offensive Application Security Analyst supports the improvement of COUNTRY Financial applications and technology platforms through application security assessments and adversary emulation. This role is split evenly between the Application Security program and Threat Intelligence & Emulation initiatives, with responsibilities spanning assessment, testing, automation, and collaboration across teams.
Core Responsibilities
- Perform application security assessments targeting web, API, mobile, and cloud applications.
- Analyze and triage findings from SAST, DAST, dependency scanning, and other security testing platforms.
- Provide vulnerability remediation guidance and secure coding recommendations to development teams.
- Participate in threat modeling and architecture review activities.
- Improve application security automation and security testing within CI/CD pipelines.
- Support dependency management and software supply chain security initiatives.
- Collaborate with technology teams to strengthen secure development lifecycle practices.
- Demonstrate working knowledge of Git and Git-based workflows, including branching, pull requests, code reviews, and secure code management.
- Execute red team, purple team, and adversary emulation activities in line with established rules of engagement.
- Assist with internal penetration testing efforts and support coordination of third-party penetration testing.
- Conduct security control validation and threat-informed testing using MITRE ATT&CK methodologies.
- Research adversary tactics, techniques, and procedures, and translate intelligence into testing scenarios.
- Perform offensive security assessments against enterprise infrastructure, cloud environments, and applications.
- Document findings and provide actionable recommendations to improve detection and prevention capabilities.
- Partner with defensive security teams to validate response and monitoring effectiveness.
- Participate in projects and assessments related to risk.
- Analyze and define security policies and standards.
- Monitor, alert, and respond to security events.
- Perform computer forensic and investigative activities, including penetration and vulnerability testing.
- Define and administer identity and access roles and workflows.
Required Qualifications
- Secure software development principles and knowledge of common application vulnerabilities.
- Web application security concepts, including OWASP Top 10.
- Security testing methodologies such as SAST, DAST, and penetration testing.
- Basic understanding of red team and purple team methodologies.
- Scripting and automation experience with PowerShell, Python, Bash, or similar languages.
- Knowledge of cloud security concepts and modern application architectures.
- Familiarity with MITRE ATT&CK Framework concepts.
- Typically requires 3+ years of relevant experience, or a combination of related experience, education, and training.
- Strong analytical and problem-solving abilities.
- Effective written and verbal communication.
- Ability to explain technical findings to both technical and non-technical audiences.
- Strong collaboration and teamwork skills.
- Self-motivated with a desire to continuously learn and develop offensive and application security expertise.
Technologies
- PowerShell
- Python
- Bash
- Git
- SAST
- DAST
- MITRE ATT&CK Framework
- OWASP Top 10
- CI/CD
- MITRE ATT&CK
Location and Work Arrangement
Bloomington, IL (hybrid).
Compensation
Base pay range: $94,400 to $129,800 per year.
Benefits
- Insurance benefits (medical, dental, vision, disability, and life)
- 401(k) with company match
- Short-Term Incentive plan