Exposure Intelligence Analyst – Applications & APIs, OWASP, SAST-DAST, Auth

🕒 August 4

🇺🇸 United States – Remote

💵 $100k - $170.5k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🕵️ Threat Intelligence Specialist

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 15%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Allstate

Allstate

10,000+ employees

Founded 1931

💼 Consulting

📦 Logistics

🛡️ Insurance

💰 Post-IPO Equity on 2014-01

Consulting • Logistics • Insurance

Allstate is an industry leader in providing insurance solutions, focusing on home, auto, device, and identity protection. With a commitment to customer well-being, Allstate aims to instill peace of mind and financial security for its customers. The company also emphasizes community impact and sustainability through various initiatives, showcasing their dedication to social responsibility and positive change.

📋 Description

• Translate application findings into exposure intelligence and exploitability-based prioritization • Identify attack paths involving authentication flaws, insecure APIs, weak session handling, and privilege boundaries • Produce clear remediation guidance and partner with application owners to validate closure • Own SME coverage for web, application, and API exposure, including OWASP-class risks and API misuse patterns • Identify systemic patterns such as broken authentication, insecure direct object references, injection paths, weak access controls, and insecure secrets handling • Partner with development teams and AppSec stakeholders to improve secure patterns and reduce recurring exposure creation • Connect findings to real attack paths using CTEM principles • Drive remediation that measurably reduces exploitable exposure

🎯 Requirements

• 3+ years in application security, AppSec engineering, security operations, or exposure management • Understanding of web security fundamentals and common API/application attack patterns • Ability to translate technical findings into business risk and practical engineering fixes • Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts preferred • Familiarity with modern authentication patterns such as OAuth/OIDC, API gateways, and microservices preferred • Strong collaboration skills with engineering organizations and ability to drive measurable change preferred • Candidate(s) offered this position must submit to a background investigation • Allstate generally does not sponsor individuals for employment-based visas for this position • Remote employees must have a dedicated, private workspace free from distractions • Reliable internet required, with minimum speeds of 50 MB download and 5 MB upload

🏖️ Benefits

• Comprehensive technology setup including a laptop, monitors, headset, keyboard, and mouse • Monthly connectivity reimbursement to help offset internet costs • Opportunity to challenge the status quo and shape the future of protection • Environment fostering innovative thinking • Meaningful work supporting customers and communities

Apply Now

Similar Jobs

🕒 August 4

Wiz

201 - 500

🔒 Cybersecurity

Threat intelligence researcher tracking advanced cloud attackers for Wiz, a cloud and AI security platform. Analyzing campaigns, malware, infrastructure, and incidents to protect Wiz customers and communicate novel findings.

🕒 August 4

Chainalysis Inc.

501 - 1000

🔌 API

💳 Fintech

🔒 Cybersecurity

DPRK-China crypto intelligence analyst tracing illicit funds and producing actionable threat intelligence for Chainalysis. Representing the blockchain analytics platform on national-security and crypto threats.

🕒 July 30

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Threat Hunter in CrowdStrike's OverWatch FedCloud team analyzing threat actor activity. Engage in proactive threat hunting to enhance detection capabilities across customer environments.

🕒 July 28

TRM Labs

201 - 500

₿ Crypto

📋 Compliance

🤝 B2B

Senior Cyber Threat Intelligence Analyst at TRM Labs conducting investigations and producing threat intelligence reports. Collaborating with experts to enhance investigative methodologies and workflows.

🕒 July 28

TRM Labs

201 - 500

₿ Crypto

📋 Compliance

🤝 B2B

Senior Blockchain Intelligence Analyst at TRM Labs focusing on ransomware investigations and leveraging blockchain analytics. Drive intelligence analysis on criminal crypto activities worldwide.