Exposure Intelligence Analyst – Applications & APIs (OWASP / SAST-DAST / Auth)
$100,000–$170,500 year
RemoteUnited States
United StatesRemoteFull Time$100,000–$170,500 yearLarge
Full TimeLarge
Job Summary
Translate application findings into exposure intelligence and exploitability-based prioritization for web apps, APIs, and authentication flows. Identify attack paths involving auth flaws, insecure direct object references, and weak access controls. Partner with engineering teams to produce remediation guidance and validate closure, reducing exploitable app/API attack paths. Own SME coverage for OWASP-class risks and API misuse patterns, driving measurable change in secure software development lifecycle practices.
Required Qualifications
- 3+ years in application security, AppSec engineering, security operations, or exposure management
- Understanding of web security fundamentals and common API/application attack patterns
- Ability to translate technical findings into business risk and practical engineering fixes
Desired Qualifications
- Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts
- Familiarity with modern auth patterns (OAuth/OIDC), API gateways, and microservices
- Strong collaboration skills with engineering orgs; ability to drive measurable change
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.