Sr. Information Security Analyst

RLI Insurance Company•Peoria, IL
•$96,264 - $137,657•Hybrid

About The Position

The Senior Information Security Analyst is a senior technical member of the Information Security team responsible for improving RLI's security operations while driving application vulnerability management, and automation. The role combines hands-on security operations and incident response. The primary focus of this position is application vulnerability management and remediation. The role also requires strong security operations and incident response fundamentals, along with the ability to automate recurring work and collaborate effectively with software development teams.

Requirements

  • Typically requires a Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field preferred.
  • Typically requires 5+ years of relevant information security experience or an equivalent combination of education and experience.
  • Demonstrated experience in vulnerability management or application security, along with hands-on security operations or incident response experience.
  • Experience working with software development teams.
  • Experience using scripting, APIs, or other automation to improve security workflows.
  • Strong vulnerability management experience with the ability to prioritize findings and drive remediation across technical teams.
  • Working knowledge of application security and common vulnerability classes, including the OWASP Top 10.
  • Ability to translate technical security findings into clear, actionable guidance for developers and technology teams.
  • Hands-on SIEM experience, including event investigation, log analysis, and alert review or tuning.
  • Demonstrated incident response and technical investigation experience.
  • Experience with GitLab, GitHub, Azure DevOps, or a comparable development platform, including security scanning workflows.
  • Ability to script or automate using Python, PowerShell, APIs, or comparable technologies.
  • Ability to work independently, prioritize competing security risks, and collaborate across security, infrastructure, cloud, and development teams.

Nice To Haves

  • Relevant certifications such as CISSP, GIAC, CSSLP, OSCP, Microsoft security certifications, or equivalent are preferred.
  • Practical experience using generative AI/LLMs or AI-enabled security tools to improve analysis, automation, documentation, or vulnerability remediation.
  • Experience with application security technologies such as SAST, DAST, SCA, secrets scanning, dependency scanning, or automated security testing.
  • Experience with Microsoft Azure or other cloud environments and familiarity with cloud security concepts.
  • Familiarity with containers, Kubernetes, infrastructure-as-code, or related cloud-native security practices.
  • Experience contributing to detection engineering, threat hunting, or advanced security monitoring activities.
  • Knowledge of NIST, CIS, ISO 27001, SOX, PCI DSS, and related security or regulatory frameworks.

Responsibilities

  • Lead application-focused vulnerability management and help technology teams move findings from identification through validated remediation.
  • Translate penetration test, application security, dependency, and vulnerability findings into clear, developer-actionable remediation guidance.
  • Prioritize vulnerabilities using severity, exploitability, application criticality, data sensitivity, exposure, and business risk.
  • Build reusable remediation patterns, templates, examples, and technical guidance for recurring application vulnerabilities.
  • Analyze vulnerability trends to identify recurring root causes.
  • Partner with development leadership and product teams to improve remediation expectations, time-to-fix, and fix-rate outcomes.
  • Validate remediation and support documented risk acceptance when remediation is not feasible within required timelines.
  • Support penetration testing, security assessments, and technical risk assessments.
  • Assist with internal and external audits, vulnerability assessments, penetration tests, and regulatory or compliance activities.
  • Operate and support SIEM and security monitoring capabilities, including event investigation, log analysis, alert tuning, dashboards, enrichment, and investigation workflows.
  • Monitor, investigate, and respond to security events and incidents across endpoint, identity, network, cloud, and application environments.
  • Lead or participate in incident response activities based on incident scope and experience, including containment, recovery, analysis, and post-incident review.
  • Perform independent technical investigation when automated conclusions are incomplete, uncertain, or incorrect.
  • Monitor emerging threats, vulnerability intelligence, and attack techniques using current and/or Open-Source Intelligence capabilities.
  • Maintain investigation playbooks and incident response procedures, and contribute to detection and monitoring improvements.
  • Use automation to reduce repetitive, low-value case handling while preserving hands-on investigative and troubleshooting skills.
  • Partner with internal teams and security service providers to coordinate response and remediation activities.
  • Maintain security standards, procedures, technical documentation, and operational runbooks.
  • Serve as a senior technical resource to security and technology partners and share knowledge with other team members.
  • Identify repetitive security activities that can be simplified or automated and help implement practical, maintainable solutions.
  • Use automation, generative AI, large language models (LLMs), or AI-enabled security capabilities to assist with triage, investigation, documentation, vulnerability analysis, and remediation guidance.
  • Develop or maintain scripts, API integrations, orchestration, or workflow automation using Python, PowerShell, REST APIs, or comparable technologies.
  • Apply AI-assisted analysis to vulnerability and penetration-testing data to identify recurring themes, remediation patterns, and opportunities for improvement.

Benefits

  • Annual bonus plans
  • Employee stock ownership plan (ESOP)
  • 401(k) — automatic 3% company contribution
  • Annual 401k and ESOP profit-sharing contributions (Up to 15% of eligible earnings)
  • Paid time off (PTO) and holidays
  • Paid volunteer time off (VTO) to support our communities
  • Parental and family care leave
  • Flexible & hybrid work arrangements
  • Fitness center discounts and free virtual fitness platform
  • Employee assistance program
  • Comprehensive medical, dental and vision benefits
  • Flexible spending and health savings accounts
  • 2x base salary for group life and AD&D insurance
  • Voluntary life, critical illness, & accident insurance for purchase
  • Short-term and long-term disability benefits
  • Training & certification opportunities
  • Tuition reimbursement
  • Education bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service