Applications & APIs Service (Lead) Consultant
- Location
- Remote
- Work type
- Full Time · On-site
- Posted
- 2026-08-30
Job description
Key Responsibilities (Core + Domain)
Exposure Intelligence (Core)
Translate application findings into exposure intelligence and exploitability-based prioritization.
Identify attack paths involving auth flaws, insecure APIs, weak session handling, and privilege boundaries.
Produce clear remediation guidance and partner with app owners to validate closure.
Applications & APIs (Domain)
Own SME coverage for web/app/API exposure including OWASP-class risks and API misuse patterns.
Identify systemic patterns: broken auth, insecure direct object references, injection paths, weak access controls, insecure secrets handling.
Partner with dev teams and AppSec stakeholders to improve secure patterns and reduce recurring exposure creation.
Required Qualifications
3+ years in application security, AppSec engineering, security operations, or exposure management.
Understanding of web security fundamentals and common API/application attack patterns.
Ability to translate technical findings into business risk and practical engineering fixes.
Preferred Qualifications
Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts.
Familiarity with modern auth patterns (OAuth/OIDC), API gateways, and microservices.
Strong collaboration skills with engineering orgs; ability to drive measurable change.