Allstate logo
AllstatePosted 3 weeks ago

Exposure Intelligence Analyst – Applications & APIs (OWASP / SAST-DAST / Auth)

$100,000–$170,500 year

RemoteUnited States

Full TimeLarge

Job Summary

Translate application findings into exposure intelligence and exploitability-based prioritization for web apps, APIs, and authentication flows. Identify attack paths involving auth flaws, insecure direct object references, and weak access controls. Partner with engineering teams to produce remediation guidance and validate closure, reducing exploitable app/API attack paths. Own SME coverage for OWASP-class risks and API misuse patterns, driving measurable change in secure software development lifecycle practices.

Required Qualifications

  • 3+ years in application security, AppSec engineering, security operations, or exposure management
  • Understanding of web security fundamentals and common API/application attack patterns
  • Ability to translate technical findings into business risk and practical engineering fixes

Desired Qualifications

  • Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts
  • Familiarity with modern auth patterns (OAuth/OIDC), API gateways, and microservices
  • Strong collaboration skills with engineering orgs; ability to drive measurable change

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce