Exposure Intelligence Analyst, Applications & APIs

Allstate

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
IL
Salary
$100,000–$170,500 / yr
Posted
24 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $171k
This role $135k
$87k most similar roles pay here $222k

This role pays less than 83% of similar roles. Most pay $142,500–$200,025 — the shaded band above. At the midpoint, this role pays about $135k versus about $171k for comparable roles.

Based on 240 similar postings.

Employer

About Allstate

The Allstate Corporation is one of the largest publicly held personal lines insurers in the US, widely recognized for its "You're In Good Hands With Allstate®" slogan.

Allstate currently has 36 open roles on FindRole.

Listed pay typically runs $100,000–$170,500 across 36 roles with salary data.

Most-posted roles

View all roles at Allstate

At a glance

TL;DR · Exposure Intelligence Analyst, Applications & APIs

The Exposure Intelligence Analyst – Applications & APIs (OWASP / SAST-DAST / Auth) serves as a subject matter expert within the Threat & Incident Response Team’s newly established Exposure Management function. This role focuses on identifying, prioritizing, and mitigating security vulnerabilities across web applications, APIs, and authentication flows by shifting from traditional patching to risk-based remediation. The analyst will translate technical findings into exploitability-based intelligence, identify attack paths involving broken authentication or insecure direct object references, and partner with engineering teams to implement secure patterns. Key responsibilities include managing OWASP-class risks and SAST/DAST signals while improving remediation speed for common failure patterns. Required skills include expertise in application security, API security, web security fundamentals, and the secure software development lifecycle. The role addresses the critical business problem of reducing exploitable attack paths within complex enterprise application ecosystems.

What you'll do

  • Translate application findings into exploitability-based prioritization and exposure intelligence.
  • Identify attack paths involving authentication flaws, insecure APIs, and weak session handling.
  • Provide clear remediation guidance to application owners to validate security fixes.
  • Manage SME coverage for web, app, and API risks including OWASP-class vulnerabilities.
  • Identify systemic patterns such as broken access controls and insecure secret handling.
  • Partner with engineering teams to implement secure coding patterns and reduce recurring risks.
  • Analyze SAST/DAST signals to prioritize findings based on real business risk.

What we're looking for

  • Must have at least 3 years of experience in application security, AppSec engineering, security operations, or exposure management.
  • Must possess an understanding of web security fundamentals and common API/application attack patterns.
  • Ability to translate technical findings into business risk and practical engineering fixes.
  • Experience with SAST/DAST tools, vulnerability triage, and secure SDLC concepts is preferred.
  • Familiarity with modern auth patterns (OAuth/OIDC), API gateways, and microservices is preferred.
  • Strong collaboration skills with engineering organizations to drive measurable change are required.

More like this

Similar roles

Exposure Intelligence Analyst, Databases & Data Stores

Allstate

Remote (IL) 24 days ago $100,000$170,500
RDBMS NoSQL Object Storage Cloud Security Data Management Exposure Management CTEM Threat Monitoring Database Hardening Data Access Governance Security Engineering Encryption
3+ yrs exp Remote

Infrastructure & Systems, Service Lead Consultant

Allstate

Remote (IL) 24 days ago $100,000$170,500
Kubernetes Docker Linux Windows Python PowerShell KQL SQL Virtualization Infrastructure Hardening Incident Response Security Engineering CIS Benchmarks Root Cause Analysis System Hardening Threat Assessment
3+ yrs exp Remote

Platform Lead Consultant

Allstate

Remote (TN) 3 days ago $120,000$193,725
Azure C# .NET SQL Cosmos DB Postman Terraform GitHub CI/CD Microservices Event-driven Architecture API Integration Data Migration HITRUST HIPAA OpenAI
7+ yrs exp Remote

Lead Compliance Consultant, Responsible AI & Privacy

Target

Minneapolis, MN 39 days ago $95,000$171,000
Responsible AI Privacy SQL Python R Tableau Power BI NIST AI RMF OECD Principles ISO/IEC 42001 Generative AI Data Science Compliance Governance Control Design Data Mapping
6+ yrs exp Hybrid

Lead Solutions Analyst

JPMorgan Chase

Jersey City, NJ 44 days ago
AWS Python SQL LLM RAG Graph RAG Data Analytics Microservices CI/CD Agile Jira Jira Align Confluence Slack Technical Writing
3+ yrs exp

Applications Support Lead Analyst Vice President

Citi

Remote (Tampa, FL) 57 days ago
AI/ML Generative AI AIOps Python Shell Scripting SQL Unix Linux OpenShift Kubernetes Kafka Tibco EMS IBM MQ Oracle MS SQL Server PostgreSQL MongoDB Cassandra Splunk AppDynamics ITRS Geneos Prometheus Grafana OpenTelemetry ELK Stack Terraform Ansible CI/CD AWS Azure GCP REST APIs NGINX F5
10+ yrs exp Remote