Назад
Company hidden
5 дней назад

Offensive Application Security Analyst (Cybersecurity)

94 400 - 129 800$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Offensive Application Security Analyst (Cybersecurity): Assessing web, API, mobile, cloud, and enterprise applications while supporting red team, purple team, and adversary emulation initiatives with an accent on secure development, vulnerability analysis, and threat-informed testing. Focus on improving CI/CD security automation, validating enterprise security controls, and translating MITRE ATT&CK intelligence into actionable testing scenarios.

Location: Bloomington, Illinois; hybrid work arrangement

Base pay: $94,400–$129,800 per year, plus eligibility for a short-term incentive plan.

Company

hirify.global provides personal and business insurance products, retirement services, and investment services.

What you will do

  • Perform application security assessments across web, API, mobile, cloud, and enterprise applications.
  • Analyze SAST, DAST, dependency scanning, and other security testing findings, then provide remediation and secure coding guidance.
  • Improve secure development lifecycle practices, CI/CD security automation, dependency management, and software supply chain security.
  • Execute red team, purple team, adversary emulation, penetration testing, and threat-informed security control validation activities.
  • Research adversary tactics and techniques using MITRE ATT&CK and translate intelligence into testing scenarios.
  • Document findings and collaborate with developers, infrastructure teams, incident responders, and defensive security teams to improve detection and response.

Requirements

  • At least 3 years of relevant experience, or an equivalent combination of experience, education, and training.
  • Knowledge of secure software development, common application vulnerabilities, web application security, and the OWASP Top 10.
  • Experience with SAST, DAST, penetration testing, and basic red team and purple team methodologies.
  • Scripting and automation experience with PowerShell, Python, Bash, or similar languages.
  • Knowledge of cloud security, modern application architectures, Git-based workflows, and MITRE ATT&CK concepts.
  • Strong analytical, communication, problem-solving, collaboration, and continuous-learning skills.

Culture & Benefits

  • Work in a collaborative environment with developers, infrastructure teams, incident responders, and security professionals.
  • Opportunities to learn and grow within the role or across other areas of the business.
  • Medical, dental, vision, disability, and life insurance benefits.
  • 401(k) plan with company match.
  • Equal-opportunity workplace committed to a work environment free from discrimination and harassment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →