Exposure Intelligence Analyst – Applications & APIs (OWASP / SAST-DAST / Auth)

AllstateMcCullom Lake, IL
$100,000 - $170,500Hybrid

About The Position

The Exposure Intelligence Analyst – Applications & APIs is the SME responsible for identifying and prioritizing exposure risk across application ecosystems, including web applications, APIs, authentication/authorization flows, and application security testing signals (SAST/DAST). The role applies CTEM principles to connect findings to real attack paths and partners with engineering teams to drive remediation that measurably reduces exploitable exposure. The team operates within a newly established Exposure Management function in the broader cybersecurity organization, focused on modernizing how the enterprise identifies, prioritizes, and mitigates security vulnerabilities shifting from traditional patch approaches to a more strategic focus on true business risk and exploitability. Individual Contributor/ Lead Consultant roles are designed to bring in deep respective domain expertise (network, endpoint, cloud, identity, infrastructure, Databases & Data Stores, Applications, API’s etc.) to bridge the gap between security insights and practical remediation strategies.

Requirements

  • 3+ years in application security, AppSec engineering, security operations, or exposure management.
  • Understanding of web security fundamentals and common API/application attack patterns.
  • Ability to translate technical findings into business risk and practical engineering fixes.

Nice To Haves

  • Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts.
  • Familiarity with modern auth patterns (OAuth/OIDC), API gateways, and microservices.
  • Strong collaboration skills with engineering orgs; ability to drive measurable change.

Responsibilities

  • Translate application findings into exposure intelligence and exploitability-based prioritization.
  • Identify attack paths involving auth flaws, insecure APIs, weak session handling, and privilege boundaries.
  • Produce clear remediation guidance and partner with app owners to validate closure.
  • Own SME coverage for web/app/API exposure including OWASP-class risks and API misuse patterns.
  • Identify systemic patterns: broken auth, insecure direct object references, injection paths, weak access controls, insecure secrets handling.
  • Partner with dev teams and AppSec stakeholders to improve secure patterns and reduce recurring exposure creation.

Benefits

  • Compensation offered for this role is 100,000.00 - 170,500.00 annually and is based on experience and qualifications.
  • Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse.
  • Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service