Back to jobs

Cybersecurity Offense Analyst

Hybrid / United StatesFull timeMid level (2–4 years)
Apply

About the role

Job Description

This is an opportunity to join Ascot Group - one of the world’s preeminent specialty risk underwriting organizations.

Designed as a modern-era company operating through an ecosystem of interconnected global operating platforms, we’re bound by a common mission and purpose: One Ascot. Our greatest strength is a talented team who flourishes in a collaborative, inclusive, and entrepreneurial culture, steeped in underwriting excellence, integrity, and a passion to find a better way, The Ascot Way.

The Ascot Way guides our people and our organization. Our underwriting platforms collaborate to find creative ways to deploy our capital in a true cross-product and cross-platform approach. These platforms work as one, deploying our capital creatively through our Client Centric, Risk Centric, and Technology Centric strategies.

Built to be resilient, Ascot maximizes client financial security while delivering bespoke products and world class service — both pre- and post-claims. Ascot exists to solve our clients’ brightest tomorrow, through agility, collaboration, resilience, and discipline.

Ascot is embedding artificial intelligence (AI) and automation across the organisation to enhance decision‑making, efficiency, and quality of outcomes. In this role, you will be expected to work confidently alongside AI‑enabled tools, apply sound judgment when interpreting insights, and adapt as technology continues to evolve. We value curiosity, critical thinking, and a willingness to embrace change as part of how we work.

Job Summary

As part of Ascot’s Cybersecurity team, the Cyber Offense Analyst has a key role in helping deliver its cybersecurity strategic objectives. This individual will be instrumental in helping the program prepare and respond against the ever-changing threat actor’s tactics, techniques and procedures. This is a hands-on role where the successful candidate will be required to provide effective outcomes in determining weaknesses and threats specific to Ascot while also supporting the day-to-day processes and procedures. The job includes routine metrics and outcome measurements of the effectiveness of the cyber offense deliverables. This role will be in the office with a hybrid work schedule.

Responsibilities

  • Perform cyber offense functions including vulnerability scanning, coordination of penetration testing activities, overseeing remediation of vulnerabilities, continuous monitoring, application security testing, and process rollout and management. The scope of work is global covering people, process and technology across Ascot Group.
  • Assist in delivering a comprehensive offensive security strategy including identifying vulnerabilities, weaknesses and exposures in the organization’s environment, systems and applications.
  • Assist in implementing best in class solutions and tooling that will help achieve the cyber offense strategic objectives.
  • Manage vulnerability detection, coordinate patch management activities, and manage the application security program by supporting relevant processes and continuous monitoring.
  • Support penetration testing, purple and red team exercises with external and internal reviews of the environment by running, managing, and supporting remediation of those assessments.
  • Coordinate penetration testing (ethical hacking) activities and/or perform them to pinpoint vulnerabilities and consult on action plans for remediation that considers industry benchmark SLAs, asset criticality and severity rating of the vulnerabilities.
  • Integrate application security best practices into the development processes to facilitate a secure system development life cycle.
  • Leverage vulnerability databases, tooling, intelligence sources, and reports to build metrics as defined by leadership to identify the risks and tracking of risk reduction in the cyber offense space.
  • Research new tactics, techniques and procedures in public and closed forums and communicate those with security leadership.
  • Work with the cybersecurity resilience and defense team to collaborate on the presence of indicators of compromise (IOC’s) within or relevant to the environment along with determining the relevant corrective action.
  • Communicate and collaborate with technical and non-technical functions across the company and vendors to share, receive, and interpret various cyber threats, vulnerabilities, and risks related to cyber offense.
  • Embody The Ascot Way in daily interactions with colleagues, fostering engagement, development, collaboration, inclusivity, individual accountability, and a shared commitment to finding a better way.

Requirements

  • Bachelor’s degree or higher in Computer Science, Application Development, Software Engineering, or a related discipline.
  • Minimum 3 years of experience in application or network security role.
  • Excellent analytical skills and keen attention to detail for identifying and addressing security vulnerabilities.
  • Experience with offensive security and exposure-management tools such as Burp Suite, Metasploit, Nmap, Wireshark, Tenable, automated penetration-testing platforms, attack-path-management solutions, adversary-emulation frameworks, application security testing platforms, and equivalent commercial or open-source technologies.
  • Experience using AI-assisted security tooling to support vulnerability discovery, source-code analysis, attack-path identification, penetration testing, threat research, and remediation validation.
  • Working knowledge of security risks affecting generative AI and machine-learning systems, including prompt injection, sensitive-data disclosure, insecure tool or plugin use, model and supply-chain risks, excessive agency, and unsafe output handling.
  • Must have a strong technical background to understand and provide consulting to application, infrastructure, and network teams.
  • OSCP, PNPT, CEH or equivalent certifications are preferred.
  • Understanding of OWASP, OSINT, CVSS/CVE, the MITRE ATT&CK framework and the software development lifecycle.
  • Experience with successful cloud security and vulnerability processes, technologies, and techniques.
  • Knowledge and experience rolling out and performing application security testing functions (SAST/SCA/DAST & Application Pen Tests)
  • Ability to independently validate AI-generated findings, exploit recommendations, and remediation guidance before operational use.
  • Ability to automate offensive workflows and integrate results with vulnerability-management or remediation systems using Python, PowerShell, Bash, APIs, or equivalent technologies.

Compensation

Actual base pay could vary and may be above or below the listed range based on factors including but not limited to experience, subject matter expertise, and skills. The base pay is just one component of Ascot’s total compensation package for employees. Other rewards may include an annual cash bonus, long-term incentives, and other forms of discretionary compensation awarded by the Company.

The annualized base pay range for this role is $90,000 – 100,000.

  • The base salary range listed is for New Jersey, Connecticut, Colorado, and Chicago.

Company Benefits

The Company provides a competitive benefits package that includes the following (eligibility requirements apply):

  • Health and Welfare Benefits: Medical (including prescription coverage), Dental, Vision, Health Savings Account, Commuter Account, Health Care and Dependent Care Flexible Spending Accounts, Life Insurance, AD&D, Work/Life Resources (including Employee Assistance Program), and more
  • Leave Benefits: Paid holidays, annual Paid Time Off (includes paid state /local paid leave where required), Short-term Disability, Long-term Disability, Other leaves (e.g., Bereavement, FMLA, Adoption, Maternity, Military, Primary & Non-Primary Caregiver)
  • Retirement Benefits: Contributory Savings Plan (401k)

Search the jobs. Check the details. Make your move.

Compare recent openings by location, work format, pay, and experience level in one place.

Explore jobs
Smiling man pointing at a “Job offer!” notification on his phone

Excellent

Rated 4.8 out of 5 based on 617 reviewsTrustpilot

by Megan F.

Job seeker

The filters made it easier to see roles that actually matched the way I want to work. I could compare options without opening dozens of tabs.

by Daniel B.

Developer

I liked being able to narrow the search to remote roles and check the requirements before taking the next step.

by Rachel A.

People operations

The listings are easy to scan. Work format, location, and experience level are right where I expect them.

by Marcus H.

Data analyst

Salary and location filters helped me focus on roles that were worth a closer look.

by Aisha K.

QA engineer

I found the job details clear and useful. It was simple to see which skills mattered for each role.

by Olivia G.

Support specialist

The search felt straightforward, and I could quickly switch between different kinds of jobs.

by Kevin T.

Account manager

It is easy to revisit roles that fit my experience. I would like to see even more openings in my area.

by Sophia R.

Product designer

I could check work format and salary before reading the full description. That made my search feel much clearer.

by Hannah S.

Project coordinator

The job pages put the important details together, so I knew what to expect before deciding to continue.

by Victor A.

DevOps engineer

The remote filter is useful and the listings are quick to scan. A few more country options would make it even better.

by Brandon L.

Job seeker

After a break from work, a simple search and clear filters helped me start looking again without feeling overwhelmed.

by Jessica M.

Marketing coordinator

The search is straightforward. I can move from a short result to the full role description in one click.

by Christopher H.

Operations manager

I like seeing salary, location, and experience level next to each role. It saves time when comparing openings.

by Ethan M.

Sales representative

The layout is clean and the job cards are easy to read. I am looking forward to a larger selection of listings.

by David R.

Support specialist

I found the different work formats easy to browse and could quickly open roles that matched my schedule.

Frequently asked questions

Answers about finding your next role

What can I search for?

Search by job title or keyword, then browse remote, hybrid, and onsite openings in one list.

Where can I find remote jobs?

Browse remote openings on Remote Amigo. Search by job title or keyword, then choose Remote in the work format filter. Check each listing for location or country requirements.

How do I narrow the results?

Choose a country, work format, minimum annual salary, and experience level. You can change or clear the filters at any time.

What will I see on a job page?

Each listing shows the role, company, location, work format, salary when available, skills when provided, and a job description.

Do I need an account to browse jobs?

No. You can search and read the available listings without signing in.

Does this site submit job applications for me?

No. You can search and review listings here. The Apply button starts the job preference quiz; it does not submit an application to an employer.

Where do the jobs come from?

Listings are imported from public job feeds and job sites. Job details may change at the original source, so confirm the latest information before applying.

How recent are the listings?

Search results include listings with a publication date in the last 30 days. If a source provides no publication date, the import date is used; the actual posting may be older.

Can I search for remote jobs only?

Yes. Select Remote in the job type filter to show remote listings. You can switch to Hybrid or Onsite whenever you want.

What is the difference between remote, hybrid, and onsite?

Remote roles are intended to be done away from an office. Hybrid roles combine remote and office work. Onsite roles are based at a workplace. Always read the listing for its exact location requirements.

Can I filter jobs by country?

Yes. Choose a country in the search form to narrow the listings. A remote role may still have country restrictions, so check its description before applying.

Why do some jobs have no salary listed?

Some listings do not include pay information. We show a salary when it is available and leave it out when it is not provided.

Is the salary filter a monthly or annual amount?

The minimum salary field uses US dollars per year. It filters listings that have comparable salary information.

Can I change or clear my search filters?

Yes. Change the keyword, country, job type, salary, or level in the search form. You can clear individual fields and run a broader search again.