Hiring.Camp

Senior Vulnerability Management Analyst

Advisorgroup

·

Jun 11, 2026

Salary
$105k – $120k
Location
Scottsdale, AZ, United States of America
Workplace
Hybrid
Type
Full-time
Department
Management
Seniority
Senior
Education
High School
Source
Workday

Description

Current Employees and Contractors Apply Here

Osaic Careers

IT Vulnerability Opportunity in Financial Services

Senior Vulnerability Management Analyst

Location(s):

Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339

La Vista:12325 Port Grace Blvd, La Vista, NE 68128

Oakdale: 7755 3rd St. N, Oakdale, MN 55128

Scottsdale: 18700 N Hayden Rd, Suite 255, Scottsdale, AZ 85255

St. Petersburg: 877 Executive Center Dr. W, Suite 300, St. Petersburg, FL 33702

Osaic has returned to the office on a hybrid schedule requiring a minimum of 4 days weekly in the office. Applicants should be located at one of our hubs listed above and must be willing to work this schedule.

Role Type:        Full-time, Non-Exempt

Salary: $105,000 - $120,000 per year + annual performance-based bonus

Actual compensation offered will be determined individually, based on a number of job-related factors, including location, skills, licensure, experience, and education.

Our competitive compensation is just one component of Osaic’s total compensation package. Additional benefits include health, vision, dental insurance, 401k, paid time away, volunteer days and much more. To view more details of what you can look forward to, visit our careers page: Osaic Benefits.

Summary:

We’re seeking a Senior Vulnerability Analyst to lead and mature our enterprise vulnerability programs across SDLC (secure development lifecycle), external attack surface, and internal infrastructure/applications. This role drives end‑to‑end vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics, while partnering closely with Engineering, Product, Cloud/SRE, and IT. You’ll also coordinate penetration testing readiness, evidence collection, and remediation plans, and help embed security into the development workflow. The ideal candidate has strong application development experience, practical threat modeling skills, and a pragmatic approach to risk.

Education Requirements:

Bachelor’s degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.

Responsibilities:

  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross-team resolution.
  • Mentor junior analysts and help improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Help with pen test pre‑work: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder comms.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internet‑exposed services, DNS, certificates, cloud perimeters, API endpoints, and third‑party exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement “shift‑left” controls (pre‑commit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for high‑risk components (authN/Z, crypto, secrets handling, supply chain, multi‑tenant boundaries).
  • All other duties as assigned.

Basic Requirements:

  • Deep technical/domain expertise and ability to lead initiatives.
  • Strong understanding of OS, cloud environments, and vulnerability lifecycles.
  • Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses.
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.

Preferred Requirements:

  • Experience with KEV catalog operationalization and threat-intel integrations.
  • Knowledge of automation platforms

Current Employees and Contractors Apply Here

Skills

Penetration TestingSRECISSP

Similar Jobs

30

Sr. Analyst Vulnerability Management

Mattel · Hyderabad, India

Today

Senior Vulnerability Management Lead | S4 | CIO | Milton Keynes or Glasgow

Santander · Unity Place - Milton Keynes, United Kingdom +1

Today

Senior Security Engineer, Vulnerability Management

1Password · Remote (United States | Canada) · Remote

6 days ago

Senior Information Security Engineer - Vulnerability Management

Wells Fargo · 111443-IND-HYDERABAD-INTL HYD WF CENTRE BLK B8 Twr-4, India

1 week ago

Senior Vulnerability Management Engineer

LSEG · United Kingdom - Home Based +1 · Remote

1 week ago

Senior Vulnerability Management Engineer

Next · Pontefract, West Yorkshire, United Kingdom, GB

2 weeks ago

Senior Infrastructure Automation & Vulnerability Management Engineer

Unisys · Bangalore - RGA Tech Park, India

2 weeks ago

Senior Security Architect - SecOps and Vulnerability Management

JPMorgan Chase · LONDON, United Kingdom, GB

2 weeks ago

Senior Security Architect - SecOps and Vulnerability Management

JP Morgan Chase · LONDON, United Kingdom, GB

2 weeks ago

Senior Vulnerability Management Engineer

Group1001Wd · Remote Location, United States of America · Remote

3 weeks ago

Vulnerability & Patch Management (Senior) Consultant

SIA · Brussels, Belgium · Hybrid

3 weeks ago

Senior Cybersecurity Analyst – Vulnerability Management

Digital Realty Global · LONDON, United Kingdom, GB · Onsite

3 weeks ago

Senior Staff Software Engineer, Vulnerability Management

Zocdoc · USA Remote +1 · Remote

3 weeks ago

Sr. Associate Cyber Security - Vulnerability Management AI

Att · IND:AP:Hyderabad / Atria Building, Plot 17 - Adm: Atria Building, Plot No 17, India +1 · Remote

1 month ago

Sr. Security Data Engineer, Vulnerability Risk Management

modernatx · 325 Binney St - Cambridge - USA - MA, United States of America +2 · Remote

1 month ago

Vulnerability & Patch Management (Senior) Consultant

SIA · Amsterdam, Netherlands · Hybrid

1 month ago

Sr Vulnerability Management Engineer

Solventum · Remote - Minnesota, United States of America +51 · Remote

1 month ago

Senior Vulnerability & Patch Management Consultant

Trabajos en Demo Datos · Madrid · Hybrid

2 months ago

Senior Vulnerability Management / SSDLC Specialist

Welvaart · Lisbon

2 months ago

Sr. Security Software Engineer, Vulnerability Management - Slack

Slack · Georgia - Atlanta, United States of America +2 · Onsite

2 months ago

Sr. Security Software Engineer, Vulnerability Management - Slack

Salesforce · Georgia - Atlanta, United States of America +2 · Onsite

2 months ago

Senior Vulnerability Management Engineer

Celonis · Raleigh, US, North Carolina · Hybrid

2 months ago

Senior Security Engineer – Vulnerability Management & Penetration Testing

Truveta · Hyderabad, India

3 months ago

Senior Anaylst, Vulnerability and Exposure Management

Dowjones · Bangalore, India

3 months ago

Senior Associate – Vulnerability Management (L3)

Pwc · Argentina AC Olivos

3 months ago

Director/Sr Director, Product Management, Risk-Based Vulnerability Mgmt (RBVM)

Qualys Careers · Foster City, United States of America

4 months ago

Senior Associate Vulnerability Management Automation

Referral Publicisgroupe · San Jose, CR

4 months ago

Senior Security Consultant/Lead – Vulnerability Management

PentagonPlus · MY

5 months ago

Senior Vulnerability Management Engineer

LSEG · IND-BLR-Divyasree Technopolis, India

8 months ago

Cybersecurity Threat & Vulnerability Management | Senior Manager | Cyber Security | Technology Consulting

Pwc · Dublin - One Spencer Dock, Ireland +1

8 months ago