Cybersecurity Offense Analyst
content_copyAlso posted 1 other times
Job description
This is an opportunity to join Ascot Group - one of the world’s preeminent specialty risk underwriting organizations.
Designed as a modern-era company operating through an ecosystem of interconnected global operating platforms, we’re bound by a common mission and purpose: One Ascot. Our greatest strength is a talented team who flourishes in a collaborative, inclusive, and entrepreneurial culture, steeped in underwriting excellence, integrity, and a passion to find a better way, The Ascot Way.
The Ascot Way guides our people and our organization. Our underwriting platforms collaborate to find creative ways to deploy our capital in a true cross-product and cross-platform approach. These platforms work as one, deploying our capital creatively through our Client Centric, Risk Centric, and Technology Centric strategies.
Built to be resilient, Ascot maximizes client financial security while delivering bespoke products and world class service — both pre- and post-claims. Ascot exists to solve our clients’ brightest tomorrow, through agility, collaboration, resilience, and discipline.
Ascot is embedding artificial intelligence (AI) and automation across the organisation to enhance decision‑making, efficiency, and quality of outcomes. In this role, you will be expected to work confidently alongside AI‑enabled tools, apply sound judgment when interpreting insights, and adapt as technology continues to evolve. We value curiosity, critical thinking, and a willingness to embrace change as part of how we work.
Summary
As part of Ascot’s Cybersecurity team, the Cyber Offense Analyst has a key role in helping deliver its cybersecurity strategic objectives. This individual will be instrumental in helping the program prepare and respond against the ever-changing threat actor’s tactics, techniques and procedures. This is a hands-on role where the successful candidate will be required to provide effective outcomes in determining weaknesses and threats specific to Ascot while also supporting the day-to-day processes and procedures. The job includes routine metrics and outcome measurements of the effectiveness of the cyber offense deliverables. This role will be in the office with a hybrid work schedule.
Responsibilities
- Perform cyber offense functions including vulnerability scanning, coordination of penetration testing activities, overseeing remediation of vulnerabilities, continuous monitoring, application security testing, and process rollout and management. The scope of work is global covering people, process and technology across Ascot Group.
- Assist in delivering a comprehensive offensive security strategy including identifying vulnerabilities, weaknesses and exposures in the organization’s environment, systems and applications.
- Assist in implementing best in class solutions and tooling that will help achieve the cyber offense strategic objectives.
- Manage vulnerability detection, coordinate patch management activities, and manage the application security program by supporting relevant processes and continuous monitoring.
- Support penetration testing, purple and red team exercises with external and internal reviews of the environment by running, managing, and supporting remediation of those assessments.
- Coordinate penetration testing (ethical hacking) activities and/or perform them to pinpoint vulnerabilities and consult on action plans for remediation that considers industry benchmark SLAs, asset criticality and severity rating of the vulnerabilities.
- Integrate application security best practices into the development processes to facilitate a secure system development life cycle.
- Leverage vulnerability databases, tooling, intelligence sources, and reports to build metrics as defined by leadership to identify the risks and tracking of risk reduction in the cyber offense space.
- Research new tactics, techniques and procedures in public and closed forums and communicate those with security leadership.
- Work with the cybersecurity resilience and defense team to collaborate on the presence of indicators of compromise (IOC’s) within or relevant to the environment along with determining the relevant corrective action.
- Communicate and collaborate with technical and non-technical functions across the company and vendors to share, receive, and interpret various cyber threats, vulnerabilities, and risks related to cyber offense.
- Embody The Ascot Way in daily interactions with colleagues, fostering engagement, development, collaboration, inclusivity, individual accountability, and a shared commitment to finding a better way.
Requirements
- Bachelor’s degree or higher in Computer Science, Application Development, Software Engineering, or a related discipline.
- Minimum 3 years of experience in application or network security role.
- Excellent analytical skills and keen attention to detail for identifying and addressing security vulnerabilities.
- Experience with offensive security and exposure-management tools such as Burp Suite, Metasploit, Nmap, Wireshark, Tenable, automated penetration-testing platforms, attack-path-management solutions, adversary-emulation frameworks, application security testing platforms, and equivalent commercial or open-source technologies.
- Experience using AI-assisted security tooling to support vulnerability discovery, source-code analysis, attack-path identification, penetration testing, threat research, and remediation validation.
- Working knowledge of security risks affecting generative AI and machine-learning systems, including prompt injection, sensitive-data disclosure, insecure tool or plugin use, model and supply-chain risks, excessive agency, and unsafe output handling.
- Must have a strong technical background to understand and provide consulting to application, infrastructure, and network teams.
- OSCP, PNPT, CEH or equivalent certifications are preferred.
- Understanding of OWASP, OSINT, CVSS/CVE, the MITRE ATT&CK framework and the software development lifecycle.
- Experience with successful cloud security and vulnerability processes, technologies, and techniques.
- Knowledge and experience rolling out and performing application security testing functions (SAST/SCA/DAST & Application Pen Tests)
- Ability to independently validate AI-generated findings, exploit recommendations, and remediation guidance before operational use.
- Ability to automate offensive workflows and integrate results with vulnerability-management or remediation systems using Python, PowerShell, Bash, APIs, or equivalent technologies.
Compensation:
Actual base pay could vary and may be above or below the listed range based on factors including but not limited to experience, subject matter expertise, and skills. The base pay is just one component of Ascot’s total compensation package for employees. Other rewards may include an annual cash bonus, long-term incentives, and other forms of discretionary compensation awarded by the Company.
The annualized base pay range for this role is $90,000 – 100,000.
The base salary range listed is for New Jersey, Connecticut, Colorado, and Chicago.
Company
Benefits
The Company provides a competitive benefits package that includes the following (eligibility requirements apply):
- Health and Welfare
Benefits
- Medical (including prescription coverage), Dental, Vision, Health Savings Account, Commuter Account, Health Care and Dependent Care Flexible Spending Accounts, Life Insurance, AD&D, Work/Life Resources (including Employee Assistance Program), and more
- Leave
Benefits
- Paid holidays, annual Paid Time Off (includes paid state /local paid leave where required), Short-term Disability, Long-term Disability, Other leaves (e.g., Bereavement, FMLA, Adoption, Maternity, Military, Primary & Non-Primary Caregiver)
- Retirement
Benefits
- Contributory Savings Plan (401k)
#LI-Hybrid
#LI-MR1
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to Ascot Group. Check the destination before entering personal information.

