I usually get that message any time one or more of the images on a web page (such as a logo) are linking to a different server housing a company's images. Same thing with emails that come into gmail.
You can always click "no" to the message so the the unsecure stuff won't get loaded on the Ally application landing page. I tried it and it didn't negatively affect the functionality of the page, so that is a workaround for the page so you can continue applying without loading anything unsecure.
Their IT area needs to find and fix whatever piece of the app landing page is pointing to something not on the secure server.