Summary
Kemper is a specialized insurer seeking an Application Security Analyst to embed security throughout the software development lifecycle. The role assesses application security across modern applications, APIs, cloud-native services, and software supply chains while partnering with developers and architects to identify, prioritize, and remediate exploitable risks.
Responsibilities
- Integrate security requirements and threat modeling into architecture, design, development, testing, release, and exception processes
- Perform and validate SAST, DAST, SCA, API, mobile, and manual security testing; distinguish exploitable weaknesses from tool noise
- Conduct security design and architecture reviews for web, API, cloud-native, containerized, and distributed applications
- Partner with developers to provide code-level or design-level remediation guidance and verify closure
- Build or improve CI/CD security controls, scanning integrations, secure coding standards, and developer enablement
- Use risk, exploitability, asset criticality, and business context to prioritize application vulnerabilities and security debt
- Analyze recurring defect patterns and drive preventive control improvements across engineering teams
Skills
- Hands-on experience with application security testing, secure code review, and vulnerability validation
- Strong knowledge of OWASP Top 10/API risks, authentication/authorization patterns, session management, cryptography fundamentals, input validation, and common web/application attack techniques
- Working knowledge of SAST, DAST, SCA, API testing, secrets scanning, and CI/CD security tooling
- Understanding of modern software architectures, REST/GraphQL APIs, containers, cloud services, and software supply-chain dependencies
- Ability to engage developers at a technical level and provide actionable remediation guidance
- Applied secure SDLC, threat modeling, architecture review, risk-based exception, and application-risk prioritization experience
- Ability to translate exploitability into business impact and risk treatment decisions
- Understanding of security-control objectives for application development and deployment
- BS Computer Science, Software Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent relevant professional experience
Qualifications
Must Haves
- Hands-on experience with application security testing, secure code review, and vulnerability validation
- Strong knowledge of OWASP Top 10/API risks, authentication/authorization patterns, session management, cryptography fundamentals, input validation, and common web/application attack techniques
- Working knowledge of SAST, DAST, SCA, API testing, secrets scanning, and CI/CD security tooling
- Understanding of modern software architectures, REST/GraphQL APIs, containers, cloud services, and software supply-chain dependencies
- Ability to engage developers at a technical level and provide actionable remediation guidance
- Applied secure SDLC, threat modeling, architecture review, risk-based exception, and application-risk prioritization experience
- Ability to translate exploitability into business impact and risk treatment decisions
- Understanding of security-control objectives for application development and deployment
- BS Computer Science, Software Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent relevant professional experience
Benefits
- Medical
- Dental
- Vision
- PTO
- 401K