Jobs › Companies › RLI Corp › Sr. Information Security Analyst

Über diese Sr. Information Security Analyst Stelle bei RLI Corp

RLI Corp · Vor Ort · Peoria, IL

About Us 

We’re not like other insurance companies. From our specialty products to our business model, our culture to our results — we’re different. Different is who we are, and how we work, interact, deliver and succeed together. Creating a different and better insurance experience doesn’t just happen. It takes focus and a shared passion for going beyond the expected to forge relationships and deliver care that makes a difference. This approach rises from and is supported by our talented, ethical and smart team of employee owners united around a single purpose: to work alongside our customers and partners when they need us, in unexpected ways, with exceptional results. Apply today to make a difference with us. 

RLI is a Glassdoor Best Places to Work company with a strong, successful background. For decades, our financial track record has been stellar — a testament to our culture and validation of our reputation as an excellent underwriting company.

Senior Information Security Analyst

 

Position Purpose

The Senior Information Security Analyst is a senior technical member of the Information Security team responsible for improving RLI's security operations while driving application vulnerability management, and automation. The role combines hands-on security operations and incident response.  The primary focus of this position is application vulnerability management and remediation. The role also requires strong security operations and incident response fundamentals, along with the ability to automate recurring work and collaborate effectively with software development teams.


Principal Duties & Responsibilities


Application Security & Vulnerability Management

  • Lead application-focused vulnerability management and help technology teams move findings from identification through validated remediation.
  • Translate penetration test, application security, dependency, and vulnerability findings into clear, developer-actionable remediation guidance.
  • Prioritize vulnerabilities using severity, exploitability, application criticality, data sensitivity, exposure, and business risk.
  • Build reusable remediation patterns, templates, examples, and technical guidance for recurring application vulnerabilities.
  • Analyze vulnerability trends to identify recurring root causes.
  • Partner with development leadership and product teams to improve remediation expectations, time-to-fix, and fix-rate outcomes.
  • Validate remediation and support documented risk acceptance when remediation is not feasible within required timelines.
  • Support penetration testing, security assessments, and technical risk assessments.
  • Assist with internal and external audits, vulnerability assessments, penetration tests, and regulatory or compliance activities.

Security Operations, SIEM, & Incident Response

  • Operate and support SIEM and security monitoring capabilities, including event investigation, log analysis, alert tuning, dashboards, enrichment, and investigation workflows.
  • Monitor, investigate, and respond to security events and incidents across endpoint, identity, network, cloud, and application environments.
  • Lead or participate in incident response activities based on incident scope and experience, including containment, recovery, analysis, and post-incident review.
  • Perform independent technical investigation when automated conclusions are incomplete, uncertain, or incorrect.
  • Monitor emerging threats, vulnerability intelligence, and attack techniques using current and/or Open-Source Intelligence capabilities.
  • Maintain investigation playbooks and incident response procedures, and contribute to detection and monitoring improvements.
  • Use automation to reduce repetitive, low-value case handling while preserving hands-on investigative and troubleshooting skills.
  • Partner with internal teams and security service providers to coordinate response and remediation activities.
  • Maintain security standards, procedures, technical documentation, and operational runbooks.
  • Serve as a senior technical resource to security and technology partners and share knowledge with other team members.

AI, Automation & Scripting

  • Identify repetitive security activities that can be simplified or automated and help implement practical, maintainable solutions.
  • Use automation, generative AI, large language models (LLMs), or AI-enabled security capabilities to assist with triage, investigation, documentation, vulnerability analysis, and remediation guidance.
  • Develop or maintain scripts, API integrations, orchestration, or workflow automation using Python, PowerShell, REST APIs, or comparable technologies.
  • Apply AI-assisted analysis to vulnerability and penetration-testing data to identify recurring themes, remediation patterns, and opportunities for improvement.

Education & Experience


  • Typically requires a Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field preferred.
  • Typically requires 5+ years of relevant information security experience or an equivalent combination of education and experience.
  • Demonstrated experience in vulnerability management or application security, along with hands-on security operations or incident response experience.
  • Experience working with software development teams. Experience using scripting, APIs, or other automation to improve security workflows.
  • Relevant certifications such as CISSP, GIAC, CSSLP, OSCP, Microsoft security certifications, or equivalent are preferred.

Knowledge, Skills & Competencies


Core Capabilities

  • Strong vulnerability management experience with the ability to prioritize findings and drive remediation across technical teams.
  • Working knowledge of application security and common vulnerability classes, including the OWASP Top 10.
  • Ability to translate technical security findings into clear, actionable guidance for developers and technology teams.
  • Hands-on SIEM experience, including event investigation, log analysis, and alert review or tuning.
  • Demonstrated incident response and technical investigation experience.
  • Experience with GitLab, GitHub, Azure DevOps, or a comparable development platform, including security scanning workflows.
  • Ability to script or automate using Python, PowerShell, APIs, or comparable technologies.
  • Ability to work independently, prioritize competing security risks, and collaborate across security, infrastructure, cloud, and development teams.

Preferred / Additional Experience

  • Practical experience using generative AI/LLMs or AI-enabled security tools to improve analysis, automation, documentation, or vulnerability remediation.
  • Experience with application security technologies such as SAST, DAST, SCA, secrets scanning, dependency scanning, or automated security testing.
  • Experience with Microsoft Azure or other cloud environments and familiarity with cloud security concepts.
  • Familiarity with containers, Kubernetes, infrastructure-as-code, or related cloud-native security practices.
  • Experience contributing to detection engineering, threat hunting, or advanced security monitoring activities.
  • Knowledge of NIST, CIS, ISO 27001, SOX, PCI DSS, and related security or regulatory frameworks.

Compensation Overview

The base salary range for the position is listed below. Please note that the base salary is only one component of our robust total rewards package at RLI. The salary offered will take into account a number of factors including, but not limited to, geographic location, experience, scope & responsibilities of the role, qualifications/credentials, talent availability & specialization, as well as business needs. The below range may be modified in the future.

Base Pay Range

$96,264.00 - $137,657.00

Total Rewards

At RLI, we're all owners. We hire the best and the brightest employees and allow them to share in the company's success through our Total Rewards. With the Employee Stock Ownership plan at its core, the Total Rewards program includes all compensation, benefits and perks that come with being an RLI employee.

Financial Incentives

  • Annual bonus plans

  • Employee stock ownership plan (ESOP)

  • 401(k) — automatic 3% company contribution

  • Annual 401k and ESOP profit-sharing contributions (Up to 15% of eligible earnings)

Work & Life

  • Paid time off (PTO) and holidays

  • Paid volunteer time off (VTO) to support our communities

  • Parental and family care leave

  • Flexible & hybrid work arrangements

  • Fitness center discounts and free virtual fitness platform

  • Employee assistance program

Health & Wellness

  • Comprehensive medical, dental and vision benefits

  • Flexible spending and health savings accounts

  • 2x base salary for group life and AD&D insurance

  • Voluntary life, critical illness, & accident insurance for purchase

  • Short-term and long-term disability benefits

Personal & Professional Growth

RLI encourages its employees to pursue professional development work in insurance and job-related areas. We make a commitment to employees to provide educational opportunities that help them enhance their skills and further their career advancement. RLI fosters a true learning culture and encourages professional growth through insurance courses, in-house training and other educational programs. RLI covers the cost for most programs and employees typically earn a bonus upon successful completion of approved courses and certifications. Our personal and professional growth benefits include:

  • Training & certification opportunities

  • Tuition reimbursement

  • Education bonuses

Diversity & Inclusion

Our goal is to attract, develop and retain the best employee talent from diverse backgrounds while promoting an environment where all viewpoints are valued and individuals feel respected, are treated fairly, and have an opportunity to excel in their chosen careers. We actively support, and participate in, initiatives led by the American Property Casualty Insurance Association that aim to increase diversity in the insurance industry. Cultivating an exceptional and diverse workforce to deliver excellent customer service reinforces our culture and is a key to achieving superior business results.

RLI is an equal opportunity employer and does not discriminate in hiring or employment on the basis of race, color, religion, national origin, citizenship, gender, marital status, sexual orientation, age, disability, veteran status, or any other characteristic protected by federal, state, or local law.

Bereit, sich bei RLI Corp zu bewerben?
Bei RLI Corp bewerben

Wie sich dieses Gehalt für Cybersecurity vergleicht

Diese Stelle zahlt $116,961/yr — im Einklang mit der üblichen Spanne für Cybersecurity Stellen.

$79,472 dem Median $126,500 $184,800

Übliche Spanne $100,782–$152,500/yr, aus 531 vergleichbaren Cybersecurity Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Cybersecurity ansehen →

Über RLI Corp

RLI is a specialty insurance company that helps customers navigate the world of insurance and risk. For more than a half century, we’ve been helping people and companies safeguard their assets through our innovative portfolio of property and casualty coverages and surety products. We’re not what you’d expect from a typical insurance company. From our products to our business model, our culture to our results — we’re different. WHAT MAKES RLI DIFFERENT Our remarkable people. Our people are among the smartest and most knowledgeable in the business. They are experts at building relationships that last with our brokers and customers by providing outstanding service and creating ideal coverages w

Alle Jobs bei RLI Corp ansehen →

Ähnliche Jobs

Reviverx
Sr Cybersecurity Engineer
Reviverx
⚡ Früh bewerben Texas · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
SpaceX
Sr. Industrial Security Analyst (MDSO)
SpaceX
⚡ Früh bewerben Hawthorne, CA Vor Ort $130,000–$195,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Exiger
Threat Cybersecurity Engineer
Exiger
⚡ Früh bewerben McLean, Virginia, United State... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
JRC Careers
Cybersecurity Engineer
JRC Careers
⚡ Früh bewerben Washington, DC Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
2K
Lead Security Analyst
2K
⚡ Früh bewerben Austin, Texas, United States Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
FSAStore.com
Application Security Analyst
FSAStore.com
⚡ Früh bewerben United States Vor Ort $75,000–$95,000
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
Accenture Federal Services
Government Security Personnel Analyst
Accenture Federal Services
⚡ Früh bewerben Arlington, VA Vor Ort $64,000–$109,400
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
Accenture Federal Services
Cybersecurity Engineer
Accenture Federal Services
⚡ Früh bewerben Arlington, VA Vor Ort $78,600–$160,200
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
Accenture Federal Services
Cybersecurity Engineer
Accenture Federal Services
⚡ Früh bewerben Fort Meade, MD Vor Ort $126,300–$243,100
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei RLI Corp

Alle Jobs bei RLI Corp ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos