Application Security Analyst

Posted Yesterday
Be an Early Applicant
4 Locations
Remote
94K-156K Annually
Entry level
Automotive • Insurance
The Role
Embeds security throughout the software development lifecycle by performing application, API, mobile, cloud, and software supply-chain security assessments. Conducts threat modeling, architecture reviews, secure code reviews, and vulnerability validation; partners with developers on remediation; improves CI/CD security controls and secure coding standards; and prioritizes application risk based on exploitability, asset criticality, and business impact.
Summary Generated by Built In

Location(s)

Remote-AL, Remote-FL, Remote-GA, Remote-IL

Details

Kemper is one of the nation’s leading specialized insurers. Our success is a direct reflection of the talented and diverse people who make a positive difference in the lives of our customers every day. We believe a high-performing culture, valuable opportunities for personal development and professional challenge, and a healthy work-life balance can be highly motivating and productive. Kemper’s products and services are making a real difference to our customers, who have unique and evolving needs. By joining our team, you are helping to provide an experience to our stakeholders that delivers on our promises. 

Kemper Insurance is hiring an Application Security Analyst. The Application Security Analyst is one who embeds security into the software development lifecycle and performs technically credible application-security assessment across modern applications, APIs, cloud-native services, and software supply chains. The role partners directly with developers and architects to prevent, identify, validate, and remediate exploitable application risk. 

Key Responsibilities 

  • Integrate security requirements and threat modeling into architecture, design, development, testing, release, and exception processes. 

  • Perform and validate SAST, DAST, SCA, API, mobile, and manual security testing; distinguish exploitable weaknesses from tool noise. 

  • Conduct security design and architecture reviews for web, API, cloud-native, containerized, and distributed applications. 

  • Partner with developers to provide code-level or design-level remediation guidance and verify closure. 

  • Build or improve CI/CD security controls, scanning integrations, secure coding standards, and developer enablement. 

  • Use risk, exploitability, asset criticality, and business context to prioritize application vulnerabilities and security debt. 

  • Analyze recurring defect patterns and drive preventive control improvements across engineering teams. 

Qualifications

  • Hands-on experience with application security testing, secure code review, and vulnerability validation. 
  • Strong knowledge of OWASP Top 10/API risks, authentication/authorization patterns, session management, cryptography fundamentals, input validation, and common web/application attack techniques. 
  • Working knowledge of SAST, DAST, SCA, API testing, secrets scanning, and CI/CD security tooling. 
  • Understanding of modern software architectures, REST/GraphQL APIs, containers, cloud services, and software supply-chain dependencies. 
  • Ability to engage developers at a technical level and provide actionable remediation guidance. 
  • Applied secure SDLC, threat modeling, architecture review, risk-based exception, and application-risk prioritization experience. 
  • Ability to translate exploitability into business impact and risk treatment decisions. 
  • Understanding of security-control objectives for application development and deployment.
  • BS Computer Science, Software Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent relevant professional experience. ​

The range for this position is 93,500-155,500. When determining candidate offers, we consider experience, skills, education, certifications, and geographic location among other factors. This job is also eligible for our Kemper benefits package (Medical, Dental, Vision, PTO, 401K, etc.)

Kemper is proud to be an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, disability status or any other status protected by the laws or regulations in the locations where we operate. We are committed to supporting diversity and equality across our organization and we work diligently to maintain a workplace free from discrimination.  
Kemper does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Kemper and Kemper will not be obligated to pay a placement fee. 

Kemper will never request personal information, such as your social security number or banking information, via text or email.  Additionally, Kemper does not use external messaging applications like WireApp or Skype to communicate with candidates.  If you receive such a message, delete it.  

Skills Required

  • Hands-on experience with application security testing, secure code review, and vulnerability validation
  • Knowledge of OWASP Top 10 and API risks
  • Knowledge of authentication and authorization patterns, session management, cryptography fundamentals, input validation, and common web application attack techniques
  • Working knowledge of SAST, DAST, SCA, API testing, secrets scanning, and CI/CD security tooling
  • Understanding of REST and GraphQL APIs, containers, cloud services, modern software architectures, and software supply-chain dependencies
  • Ability to engage developers technically and provide actionable remediation guidance
  • Experience with secure SDLC, threat modeling, architecture review, risk-based exceptions, and application-risk prioritization
  • Ability to translate exploitability into business impact and risk treatment decisions
  • Understanding of security-control objectives for application development and deployment
  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, Information Technology, or a related discipline, or equivalent relevant professional experience

Kemper Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kemper and has not been reviewed or approved by Kemper.

  • Retirement Support — A 401(k) with company match and immediate vesting is paired with an Employee Stock Purchase Program, and an HSA employer contribution is noted for the HDHP option. These features strengthen long-term savings and financial security beyond base pay.
  • Healthcare Strength — Comprehensive coverage includes medical, dental, vision, prescription, life and disability insurance, an EAP, and wellness programs. While plan costs vary by option and location, the breadth of core coverage is a clear pillar of the package.
  • Leave & Time Off Breadth — PTO, paid holidays, sick time, and paid volunteer time are available alongside paid parental leave and other leave programs. This scope supports time away for rest, family needs, and community engagement.

Kemper Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
6,436 Employees
Year Founded: 1990

What We Do

The Kemper family of companies is one of the nation’s leading specialized insurers. With approximately $15 billion in assets, Kemper is improving the world of insurance by providing affordable and easy-to-use personalized solutions to individuals, families and businesses through its Auto, Personal Insurance, Life and Health brands. Kemper serves over 6.6 million policies, is represented by approximately 34,000 agents and brokers, and has approximately 10,000 associates dedicated to meeting the ever-changing needs of its customers.

Similar Jobs

MWDN Logo MWDN

Machine Learning Engineer

Information Technology • Consulting
Remote
Albania
143 Employees

Tribe.xyz Logo Tribe.xyz

Junior Talent Sourcer (German speaker) - Immediate Start

Agency • HR Tech • Professional Services • Analytics
In-Office or Remote
20 Locations
In-Office or Remote
18 Locations
813 Employees

n8n Logo n8n

Platform Engineer

Artificial Intelligence • Software • Automation
In-Office or Remote
30 Locations
61 Employees

Similar Companies Hiring

HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account