Senior Vulnerability Management Analyst

Posted Yesterday
Be an Early Applicant
Scottsdale, AZ, USA
In-Office
114K-160K Annually
Senior level
Fintech • Payments • Financial Services
The Role
Lead and mature enterprise vulnerability programs across SDLC, external attack surface, and internal infrastructure. Drive vulnerability lifecycle from discovery and triage to remediation validation and metrics. Coordinate pen test readiness, intake, remediation planning, and lessons learned. Partner with Engineering, Cloud/SRE, Networking, and Detection & Response to harden configurations, embed SAST/DAST/IAST/SBOM practices, implement shift-left controls, and review architecture/code for high-risk components. Mentor junior analysts and track findings to closure.
Summary Generated by Built In
Current Employees and Contractors Apply HereOsaic Careers

IT Vulnerability Opportunity in Financial Services

Senior Vulnerability Management Analyst

Location(s):

Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339

La Vista:12325 Port Grace Blvd, La Vista, NE 68128

Oakdale: 7755 3rd St. N, Oakdale, MN 55128

Scottsdale: 18700 N Hayden Rd, Suite 255, Scottsdale, AZ 85255

St. Petersburg: 877 Executive Center Dr. W, Suite 300, St. Petersburg, FL 33702

Osaic has returned to the office on a hybrid schedule requiring a minimum of 4 days weekly in the office. Applicants should be located at one of our hubs listed above and must be willing to work this schedule.

Role Type:        Full-time, Non-Exempt

Salary: $114,000 - $160,000 per year + annual performance-based bonus

Actual compensation offered will be determined individually, based on a number of job-related factors, including location, skills, licensure, experience, and education.

Our competitive compensation is just one component of Osaic’s total compensation package. Additional benefits include health, vision, dental insurance, 401k, paid time away, volunteer days and much more. To view more details of what you can look forward to, visit our careers page: Osaic Benefits.

Summary:

We’re seeking a Senior Vulnerability Analyst to lead and mature our enterprise vulnerability programs across SDLC (secure development lifecycle), external attack surface, and internal infrastructure/applications. This role drives end‑to‑end vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics, while partnering closely with Engineering, Product, Cloud/SRE, and IT. You’ll also coordinate penetration testing readiness, evidence collection, and remediation plans, and help embed security into the development workflow. The ideal candidate has strong application development experience, practical threat modeling skills, and a pragmatic approach to risk.

Education Requirements:

Bachelor’s degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.

Responsibilities:

  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross-team resolution.
  • Mentor junior analysts and help improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Help with pen test pre‑work: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder comms.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internet‑exposed services, DNS, certificates, cloud perimeters, API endpoints, and third‑party exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement “shift‑left” controls (pre‑commit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for high‑risk components (authN/Z, crypto, secrets handling, supply chain, multi‑tenant boundaries).
  • All other duties as assigned.

Basic Requirements:

  • Deep technical/domain expertise and ability to lead initiatives.
  • Strong understanding of OS, cloud environments, and vulnerability lifecycles.
  • Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses.
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.

Preferred Requirements:

  • Experience with KEV catalog operationalization and threat-intel integrations.
  • Knowledge of automation platforms
Current Employees and Contractors Apply Here

Skills Required

  • Minimum high school diploma or equivalent
  • Bachelor's degree
  • Deep technical/domain expertise and ability to lead initiatives
  • Strong understanding of operating systems, cloud environments, and vulnerability lifecycles
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP
  • Experience with penetration testing readiness, scope definition, and remediation coordination
  • Practical threat modeling skills and application development experience
  • Experience with SAST/DAST/IAST/OSS/SBOM practices and secure build/CI pipelines
  • Experience operationalizing KEV catalog and threat-intel integrations
  • Knowledge of automation platforms

Osaic Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Osaic and has not been reviewed or approved by Osaic.

  • Leave & Time Off Breadth Paid time away includes PTO, sick time, holidays, and volunteer days available from the start. The breadth supports work–life balance with a Monday–Friday schedule.
  • Healthcare Strength Health coverage spans medical, dental, vision, life, and disability with HSA/FSA options and day-one eligibility. The package also includes wellness initiatives and adoption assistance.
  • Retirement Support A 401(k) with company match and immediate vesting is offered. This supports long-term savings starting on the first day.

Osaic Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Scottsdale, , Arizona
2,194 Employees

What We Do

Osaic provides the support, resources, and community designed for the future of wealth management. Securities and investment advisory services are offered through the firms: Osaic Wealth, Inc., Osaic Institutions, Inc., Osaic FA, Inc., Osaic FS, Inc., and Triad Advisors, LLC, broker-dealers, registered investment advisers, and members of FINRA and SIPC. Securities are offered through Securities America, Inc., American Portfolios Financial Services, Inc., Osaic Services Inc., and Ladenburg Thalmann & Co., broker-dealers and member of FINRA and SIPC. Advisory services are offered through Arbor Point Advisors, LLC, American Portfolios Advisors, Inc., Ladenburg Thalmann Asset Management, Inc., Osaic Advisory Services, LLC, and Securities America Advisors, Inc., registered investment advisers. Advisory programs offered by Osaic Wealth, Inc., Securities America Advisors, Inc., and Triad Advisors, LLC., are sponsored by VISION2020 Wealth Management Corp., an affiliated registered investment adviser.

Similar Jobs

RigUp Logo RigUp

Senior Account Executive

Information Technology • Professional Services • Software • Energy
Remote or Hybrid
US
260 Employees

RigUp Logo RigUp

Senior Account Executive

Information Technology • Professional Services • Software • Energy
Remote or Hybrid
US
260 Employees

RigUp Logo RigUp

Recruiter

Information Technology • Professional Services • Software • Energy
Remote or Hybrid
USA
260 Employees

DraftKings Logo DraftKings

Non-Sports Manager, Predictions Operations

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
112K-140K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account