Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
COUNTRY Financial®

Offensive Application Security Analyst

COUNTRY Financial®

. Perform application security assessments against web, API, mobile, and cloud applications .

Posted 9/30/2026full-timeBloomington • Illinois • United StatesMid-LevelSenior💰 $94,400 - $129,800 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security assessments, vulnerability remediation, and secure coding practices. Proficient in security testing methodologies and automation within CI/CD pipelines, with a strong understanding of cloud security and threat modeling.

Highest-signal resume keywords
Application Security AssessmentsSAST and DASTVulnerability Remediation GuidanceSecure Software Development PrinciplesMITRE ATT&CK Framework

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityVulnerability TestingPenetration TestingScriptingAutomationThreat ModelingSecurity Control ValidationCloud SecurityRed Team MethodologiesPurple Team Methodologies
Soft Skills
Analytical SkillsProblem-SolvingEffective CommunicationCollaborationSelf-Motivation
Tools & Technologies
PowerShellPythonBashCI/CD PipelinesSecurity Testing PlatformsDependency Scanning ToolsAdversary Emulation ToolsComputer Forensics ToolsMonitoring ToolsSecurity Event Management Systems
Industry Keywords
OWASP Top 10Secure Development LifecycleSoftware Supply Chain SecurityRisk AssessmentSecurity Policies and Standards

Tech Stack

Tools & technologies
CloudPython

About the role

Key responsibilities & impact
  • Perform application security assessments against web, API, mobile, and cloud applications
  • Analyze and triage findings from SAST, DAST, dependency scanning, and other security testing platforms
  • Assist development teams with vulnerability remediation guidance and secure coding recommendations
  • Participate in threat modeling and architecture review activities
  • Improve application security automation and security testing within CI/CD pipelines
  • Support dependency management and software supply chain security initiatives
  • Collaborate with technology teams to improve secure development lifecycle practices
  • Execute red team, purple team, and adversary emulation activities under established rules of engagement
  • Assist with internal penetration testing exercises and third-party penetration testing coordination
  • Conduct security control validation and threat-informed testing using MITRE ATT&CK methodologies
  • Research adversary tactics, techniques, and procedures and translate intelligence into testing scenarios
  • Perform offensive security assessments against enterprise infrastructure, cloud environments, and applications
  • Document findings and provide actionable recommendations to improve detection and prevention capabilities
  • Partner with defensive security teams to validate response and monitoring effectiveness
  • Participate in risk-related projects and assessments
  • Analyze and define security policies and standards
  • Monitor, alert, and respond to security events
  • Perform computer forensic and investigative activities, penetration testing, and vulnerability testing
  • Define and administer identity and access roles and workflows

Requirements

What you’ll need
  • Secure software development principles and common application vulnerabilities
  • Web application security concepts including OWASP Top 10
  • Security testing methodologies including SAST, DAST, and penetration testing
  • Basic understanding of red team and purple team methodologies
  • Scripting and automation experience using PowerShell, Python, Bash, or similar languages
  • Knowledge of cloud security concepts and modern application architectures
  • Familiarity with MITRE ATT&CK Framework concepts
  • Typically requires 3+ years of relevant experience or a combination of related experience, education and training
  • Strong analytical and problem-solving abilities
  • Effective written and verbal communication
  • Ability to explain technical findings to both technical and non-technical audiences
  • Strong collaboration and teamwork skills
  • Self-motivated with a desire to continuously learn and develop offensive and application security expertise

Benefits

Comp & perks
  • Short-Term Incentive plan
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Disability insurance
  • Life insurance
  • 401(k) with company match
  • Opportunities to learn and grow throughout your career
  • Equal opportunity employment and a work environment free of discrimination and harassment