About the roleThe Offensive Application Security Analyst helps improve the security of COUNTRY Financial's applications and technology platforms through a blend of application security assessment and adversary emulation activities. This role spends approximately 50% of time supporting the Application Security program and 50% supporting Threat Intelligence & Emulation initiatives.
The individual will perform application security testing, assist with secure development practices, support penetration testing activities, participate in threat emulation exercises, and help validate the effectiveness of enterprise security controls. This role serves as a technical contributor who works closely with developers, infrastructure teams, incident responders, and other security professionals to identify and reduce cybersecurity risk. The position supports both secure software development and offensive security objectives
Primary Responsibilities
Application Security (50%)
• Perform application security assessments against web, API, mobile, and cloud applications.
• Analyze and triage findings from SAST, DAST, dependency scanning, and other security testing platforms.
• Assist development teams with vulnerability remediation guidance and secure coding recommendations.
• Participate in threat modeling and architecture review activities.
• Help improve application security automation and security testing within CI/CD pipelines.
• Support dependency management and software supply chain security initiatives.
• Collaborate with technology teams to improve secure development lifecycle practices.
• Demonstrate an understanding of Git and Git-based development workflows, including branching, pull requests, code reviews, and secure code management practices
Threat Emulation (50%)
• Execute red team, purple team, and adversary emulation activities under established rules of engagement.
• Assist with internal penetration testing exercises and third-party penetration testing coordination.
• Conduct security control validation and threat-informed testing using MITRE ATT&CK methodologies.
• Research adversary tactics, techniques, and procedures and help translate intelligence into testing scenarios.
• Perform offensive security assessments against enterprise infrastructure, cloud environments, and applications.
• Document findings and provide actionable recommendations to improve detection and prevention capabilities.
• Partner with defensive security teams to validate response and monitoring effectiveness.
How does this role make an impact?- Participates in projects and assessments on risk.
- Analyzes and defines security policies and standards.
- Monitors, alerts and responds to security events.
- Performs computer forensic and investigative activities; and penetration and vulnerability testing.
- Defines and administers identity & access roles and workflows.
Do you have what we're looking for?Required SkillsTechnical Knowledge- Secure software development principles and common application vulnerabilities.
- Web application security concepts including OWASP Top 10.
- Security testing methodologies including SAST, DAST, and penetration testing.
- Basic understanding of red team and purple team methodologies.
- Scripting and automation experience using PowerShell, Python, Bash, or similar languages.
- Knowledge of cloud security concepts and modern application architectures.
- Familiarity with MITRE ATT&CK Framework concepts.
- Typically requires 3+ years of relevant experience or a combination of related experience, education and training.
Professional Skills- Strong analytical and problem-solving abilities.
- Effective written and verbal communication.
- Ability to explain technical findings to both technical and non-technical audiences.
- Strong collaboration and teamwork skills.
- Self-motivated with a desire to continuously learn and develop offensive and application security expertise.
#LI-CORP
#LI-Hybrid
Base Pay Range:$94,400-$129,800
The base pay range represents the typical range of potential salary offers for candidates hired. Factors used to determine your actual salary include your specific skills, qualifications and experience.
Incentive Pay:In addition to base salary, this position is eligible for a Short-Term Incentive plan.
You'll be able to take advantage of our benefits package, which includes insurance benefits (medical, dental, vision, disability, and life), 401(k) with company match.
Come join our team at COUNTRY today!