The posting
Salary range is:
$56,930.88 - $70,000.00
This position is bonus and/or commission eligible.
CCC Intelligent Solutions Inc. (CCC) is a leading cloud platform for the multi-trillion-dollar insurance economy, creating intelligent experiences for insurers, repairers, automakers, part suppliers, and more. At CCC, we’re making life just work by empowering more than 35,000 businesses with industry-leading technology to get drivers back on the road and to health quickly and seamlessly. We’re pushing boundaries with innovative AI solutions that simplify and enhance the claims and repair journey. Through purposeful innovation and the strength of its connections, CCC technologies empower the people and industry relied upon to keep lives moving forward when it matters most. Learn more about CCC at www.cccis.com.
The Role
The Application Security Analyst is responsible for helping embed security throughout the software development lifecycle. This role partners closely with development, engineering, product, and platform teams to identify, assess, prioritize, and remediate application security risks. The analyst will support vulnerability management, security testing, secure coding initiatives, and security automation efforts that help strengthen the organization's overall security posture.
This position is ideal for an individual with a strong technical foundation, a passion for application security, and the ability to collaborate effectively across engineering teams to drive practical risk reduction.
Key Responsibilities:
- Perform application security assessments, including static analysis, dynamic analysis, software composition analysis, and manual validation of findings.
- Review and triage security findings, distinguishing true positives from false positives and helping development teams prioritize remediation efforts.
- Support secure software development lifecycle (SSDLC) initiatives and security-by-design practices across engineering teams.
- Conduct threat modeling and security reviews for new applications, services, and technology implementations.
- Partner with development teams to identify security weaknesses and provide remediation guidance.
- Assist with penetration testing coordination and validation of remediation activities.
- Develop and maintain security metrics, reporting, and dashboards related to application security risk.
- Support vulnerability management processes, including identification, prioritization, tracking, and verification of remediation efforts.
- Create automation, scripts, and integrations that improve security workflows and reduce manual effort.
- Evaluate software supply chain risks and support secure use of open-source components.
- Assist in developing security standards, procedures, and secure coding guidance.
- Deliver security awareness and secure coding training to engineering teams.
- Support incident response activities involving application security vulnerabilities when required.
- Be familiar with AI workflows and enablement
Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
- Understanding of common web application vulnerabilities, including the OWASP Top 10.
- Experience working with security testing tools such as SAST, DAST, SCA, and secrets detection platforms.
- Knowledge of application architectures, APIs, cloud-native applications, and modern development practices.
- Experience with scripting languages such as Python, PowerShell, JavaScript, Go, or similar.
- Familiarity with CI/CD pipelines and source control platforms such as GitHub, GitLab, or Azure DevOps.
- Strong analytical, troubleshooting, and communication skills.
- Ability to effectively communicate technical findings to both technical and non-technical stakeholders.
Preferred Qualifications
- Experience with software supply chain security programs.
- Familiarity with tools such as Endor Labs, Wiz, GitHub Advanced Security, Veracode, Checkmarx, Burp Suite, or similar technologies.
- Knowledge of cloud security concepts across Azure, AWS, or GCP.
- Experience automating security processes and workflow integrations.
- Relevant certifications such as Security+, GSEC, CSSLP, GWAPT, OSCP, or related credentials.
- Experience participating in secure architecture reviews and threat modeling exercises.
Success Measures
In this role, success will be measured by:
- Reduction in application security risk through effective vulnerability identification and remediation.
- Timely validation and prioritization of security findings.
- Increased adoption of secure development practices across engineering teams.
- Improvements in security automation and operational efficiency.
- Strong partnership and engagement with developers, architects, and product teams.
- Contribution to measurable improvements in the organization’s security posture.
Interview Policy & Privacy Notice:
A video interview is required for this position. Video interviews are transcribed. Transcriptions are retained and may be reviewed by CCC and our recruiters. Candidates are not permitted to use generative AI or automated assistance during the interviews unless explicitly allowed by the interview team for a specific exercise. Our Job Applicant Privacy Notice is available HERE.
About CCC's Commitment to Employees:
CCC Intelligent Solutions understands that our employees play an integral role in our vision to shape a world where life just works. Our team is defined by our values of Integrity, Customer-Focus, Innovation, Inclusion & Diversity, Tenacity, and Connection. Through diverse perspectives, purposeful innovation, and the strength of connections, our technologies empower the people and industry relied upon to keep lives moving forward when it matters most.
At CCC, together everyone can thrive as we innovate and collaborate, creating employee experiences that just work. We are committed to providing opportunities for our people to make real-life impacts, advance in their careers, and contribute to CCC’s success.
CCC offers competitive compensation and benefits to support you and your families, including:
- 401K Match
- Paid time off
- Annual Incentive Plan Performance Bonus
- Comprehensive health insurance
- Adoption Assistance
- Tuition Reimbursement
- Wellness Programs
- Stock Purchase Plan options
- Employee Resource Groups
For more information about our benefits, please check out our careers site.
Here, you belong. You are seen, valued, and respected. We celebrate you for who you are and all you bring. Every voice is heard and is important to our success. You can hear what employees have to say about our culture here
If you require reasonable accommodation to complete a job application, please contact (800) 621-8070.



