← Back to jobs

Applications & APIs Service (Lead) Consultant

Location
Remote
Work type
Full Time · On-site
Posted
2026-08-30

Job description

Key Responsibilities (Core + Domain)

Exposure Intelligence (Core)

Translate application findings into exposure intelligence and exploitability-based prioritization.

Identify attack paths involving auth flaws, insecure APIs, weak session handling, and privilege boundaries.

Produce clear remediation guidance and partner with app owners to validate closure.

Applications & APIs (Domain)

Own SME coverage for web/app/API exposure including OWASP-class risks and API misuse patterns.

Identify systemic patterns: broken auth, insecure direct object references, injection paths, weak access controls, insecure secrets handling.

Partner with dev teams and AppSec stakeholders to improve secure patterns and reduce recurring exposure creation.

Required Qualifications

3+ years in application security, AppSec engineering, security operations, or exposure management.

Understanding of web security fundamentals and common API/application attack patterns.

Ability to translate technical findings into business risk and practical engineering fixes.

Preferred Qualifications

Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts.

Familiarity with modern auth patterns (OAuth/OIDC), API gateways, and microservices.

Strong collaboration skills with engineering orgs; ability to drive measurable change.

Original source