Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
RLI Insurance Company

Senior Information Security Analyst

RLI Insurance Company

. Improve RLI's security operations while driving application vulnerability management and automation .

Posted 9/28/2026full-timeUnited StatesSenior💰 $96,264 - $137,657 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in vulnerability management and application security, with a strong focus on translating technical findings into actionable guidance for development teams. Proficient in incident response, security operations, and automation using scripting and AI-enabled tools.

Highest-signal resume keywords
Vulnerability ManagementApplication SecurityIncident ResponseSIEM ExperienceScripting with Python

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability ManagementApplication SecurityIncident ResponseScriptingAPIsSecurity OperationsSecurity TestingCloud SecurityAutomationTechnical Investigation
Soft Skills
CollaborationPrioritizationCommunicationIndependent WorkProblem-Solving
Tools & Technologies
SIEMGitLabGitHubAzure DevOpsGenerative AILLMsSASTDASTCloud EnvironmentsKubernetes
Certifications & Qualifications
CISSPGIACCSSLPOSCPMicrosoft Security Certifications
Industry Keywords
NISTCISISO 27001SOXPCI DSS

Tech Stack

Tools & technologies
AzureCloudCyber SecurityKubernetesPython

About the role

Key responsibilities & impact
  • Improve RLI's security operations while driving application vulnerability management and automation
  • Lead application-focused vulnerability management from finding identification through validated remediation
  • Translate penetration test, application security, dependency, and vulnerability findings into developer-actionable remediation guidance
  • Prioritize vulnerabilities based on severity, exploitability, application criticality, data sensitivity, exposure, and business risk
  • Build remediation patterns, templates, examples, and technical guidance for recurring application vulnerabilities
  • Analyze vulnerability trends and identify recurring root causes
  • Partner with development leadership and product teams to improve remediation expectations, time-to-fix, and fix-rate outcomes
  • Validate remediation and support documented risk acceptance
  • Support penetration testing, security assessments, technical risk assessments, audits, vulnerability assessments, and compliance activities
  • Operate and support SIEM and security monitoring capabilities, including event investigation, log analysis, alert tuning, dashboards, enrichment, and investigation workflows
  • Monitor, investigate, and respond to security events and incidents across endpoint, identity, network, cloud, and application environments
  • Lead or participate in incident response, including containment, recovery, analysis, and post-incident review
  • Perform independent technical investigations when automated conclusions are incomplete, uncertain, or incorrect
  • Monitor emerging threats, vulnerability intelligence, and attack techniques
  • Maintain investigation playbooks, incident response procedures, security standards, technical documentation, and operational runbooks
  • Use automation, generative AI, LLMs, and AI-enabled security capabilities to assist with triage, investigation, documentation, vulnerability analysis, and remediation guidance
  • Develop or maintain scripts, API integrations, orchestration, and workflow automation
  • Serve as a senior technical resource and share knowledge with security and technology partners

Requirements

What you’ll need
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field preferred
  • 5+ years of relevant information security experience or an equivalent combination of education and experience
  • Demonstrated experience in vulnerability management or application security
  • Hands-on security operations or incident response experience
  • Experience working with software development teams
  • Experience using scripting, APIs, or other automation to improve security workflows
  • Strong vulnerability management experience and ability to prioritize findings and drive remediation
  • Working knowledge of application security and common vulnerability classes, including the OWASP Top 10
  • Ability to translate technical security findings into actionable guidance for developers and technology teams
  • Hands-on SIEM experience, including event investigation, log analysis, and alert review or tuning
  • Demonstrated incident response and technical investigation experience
  • Experience with GitLab, GitHub, Azure DevOps, or a comparable development platform, including security scanning workflows
  • Ability to script or automate using Python, PowerShell, APIs, or comparable technologies
  • Ability to work independently, prioritize competing security risks, and collaborate across security, infrastructure, cloud, and development teams
  • Practical experience using generative AI/LLMs or AI-enabled security tools preferred
  • Experience with SAST, DAST, SCA, secrets scanning, dependency scanning, or automated security testing preferred
  • Experience with Microsoft Azure or other cloud environments and familiarity with cloud security concepts preferred
  • Familiarity with containers, Kubernetes, infrastructure-as-code, or related cloud-native security practices preferred
  • Experience contributing to detection engineering, threat hunting, or advanced security monitoring activities preferred
  • Knowledge of NIST, CIS, ISO 27001, SOX, PCI DSS, and related security or regulatory frameworks preferred
  • Relevant certifications such as CISSP, GIAC, CSSLP, OSCP, Microsoft security certifications, or equivalent preferred

Benefits

Comp & perks
  • Annual bonus plans
  • Employee stock ownership plan (ESOP)
  • 401(k) — automatic 3% company contribution
  • Annual 401k and ESOP profit-sharing contributions (Up to 15% of eligible earnings)
  • Paid time off (PTO) and holidays
  • Paid volunteer time off (VTO) to support our communities
  • Parental and family care leave
  • Flexible & hybrid work arrangements
  • Fitness center discounts and free virtual fitness platform
  • Employee assistance program
  • Comprehensive medical, dental and vision benefits
  • Flexible spending and health savings accounts
  • 2x base salary for group life and AD&D insurance
  • Voluntary life, critical illness, & accident insurance for purchase
  • Short-term and long-term disability benefits
  • Training & certification opportunities
  • Tuition reimbursement
  • Education bonuses
  • Professional development and educational opportunities, including insurance courses, in-house training and other educational programs