Lead Vulnerability Research Engineer, IT Security
Raymond James Financial, Inc.
St. Petersburg, FL, United States
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.techcareers.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Java (Programming Language)
JavaScript (Programming Language)
Application Programming Interfaces (APIs)
Artificial Intelligence
Amazon Web Services
Software System Penetration Testing
Systems Engineering
JIRA
Audit Trail
Automation of Tests
Microsoft Azure
C Sharp (Programming Language)
+50 more
Client Server Models
Code Review
Cyber Security
Information Systems
Continuous Integration
Github
Statistical Hypothesis Testing
Networking Hardware
Intrusion Detection and Prevention
Information Systems Security Architecture Professional
Python (Programming Language)
Knowledge Management
Machine Learning
Open Source Technology
Open Web Application Security
Pattern Recognition
Windows PowerShell
Cloud Services
Software Safety
Reverse Engineering
Session Management
Software Engineering
TypeScript
Software Vulnerability Management
Data Logging
Data Processing
Google Cloud
Enterprise Software Applications
Spring Cloud
Retrieval-Augmented Generation
Software Security
Malware
Cyber Threat Analysis
Gitlab
GWAPT
Kubernetes
Information Technology
Low Latency
Production Code
Graphql
Data Management
GPT
Devsecops
Api Management
Serverless Computing
Jenkins
Static Application Security Testing
Vulnerability Analysis
Golang
Dynamic Application Security Testing
Job description
- Lead threat-focused vulnerability research across enterprise applications, APIs, operating systems, network devices, cloud services, containers, open-source components, commercial products, and emerging AI-enabled technologies.
- Continuously analyze threat intelligence, vendor advisories, public exploit research, malware and campaign reporting, security-research disclosures, and internal telemetry to identify vulnerabilities with credible relevance to the enterprise.
- Perform authorized, controlled technical research to validate vulnerability conditions, affected versions, attack prerequisites, exploitability, reachability, likely impact, and available mitigations without creating unnecessary operational risk.
- Reproduce vulnerabilities in isolated lab environments; analyze patches, source code, binaries, configurations, protocols, and proof-of-concept artifacts; and create defensible evidence that distinguishes theoretical exposure from actionable risk.
- Develop safe detection and validation content such as authenticated checks, queries, signatures, scripts, test harnesses, configuration assessments, and exposure analytics. Ensure research artifacts are reviewed, version-controlled, documented, and designed to avoid disruption.
- Build production-quality automation and integrations that ingest, normalize, enrich, correlate, deduplicate, prioritize, ticket, route, retest, and close vulnerability findings across scanners, asset inventories, threat-intelligence sources, software inventories, cloud platforms, endpoint tools, and engineering systems.
- Create threat-informed prioritization models that incorporate active exploitation, adversary behavior, exploit maturity, internet exposure, asset criticality, application context, business service dependency, reachability, compensating controls, data sensitivity, and remediation feasibility.
- Use AI-assisted research capabilities to summarize technical evidence, identify likely vulnerable code paths, compare patches, generate and refine test hypotheses, correlate findings, propose validation steps, and draft remediation guidance.
- Evaluate and govern AI-assisted security workflows for accuracy, hallucination, prompt injection, insecure output, sensitive-data exposure, excessive agency, model and dependency supply-chain risk, reproducibility, auditability, and appropriate human oversight.
- Design human-in-the-loop controls and benchmark AI-assisted workflows using measurable outcomes, including precision, recall, false-positive and false-negative rates, analyst time saved, validation quality, remediation quality, and reduction in time to protective action.
- Provide rapid technical analysis for high-risk and actively exploited vulnerabilities, including concise impact assessments, affected-asset logic, interim mitigations, detection opportunities, validation procedures, and executive-ready risk communication.
- Conduct root-cause and recurring-pattern analysis to identify systemic weaknesses in technology selection, configuration, software dependencies, asset visibility, patch processes, or control coverage; recommend durable preventive improvements.
- Partner with remediation owners to explain technical risk, validate fixes and compensating controls, resolve disputed findings, and support risk-based decisions while maintaining clear evidence and accountability.
- Define and report program metrics such as research-to-detection time, time to enterprise impact assessment, vulnerable-asset identification coverage, validation accuracy, remediation aging, recurrence, automation effectiveness, and measurable risk reduction.
- Mentor engineers and analysts, establish research standards and playbooks, contribute to technical strategy and roadmaps, and serve as an escalation point for complex vulnerability questions and significant cybersecurity incidents.
Requirements
Knowledge, Skills, and Abilities:
- Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
- Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
- Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.
- Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.
- Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.
- Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.
- Ability to critically evaluate AI output, recognize hallucinations and insecure recommendations, protect sensitive source code and data, design human-in-the-loop validation, and establish measurable quality and governance controls.
- Knowledge of secure AI-assisted development risks, including prompt injection, insecure output handling, excessive agency, sensitive information disclosure, model or dependency supply-chain concerns, and misuse of generated code.
- Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes.
- Working knowledge of threat modeling, secure architecture principles, software supply-chain security, SBOM/VEX concepts, artifact integrity, dependency governance, and provenance or attestation practices.
- Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and to translate findings into prioritized engineering actions.
- Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs.
Education/Previous Experience:
- Typically requires a Bachelor’s degree in computer science, software engineering, cybersecurity, information systems, artificial intelligence, data science, engineering, or a related field and five or more years of relevant experience. An equivalent combination of education, training, industry research, and demonstrated technical experience may be considered.
- Typically requires three or more years of hands-on experience in vulnerability research, vulnerability management engineering, offensive security, penetration testing, exploit validation, security tooling development, detection engineering, product security, application security, or a closely related discipline.
- Demonstrated hands-on experience using leading large language model platforms, including OpenAI GPT models and Anthropic Claude models, for security research, code and patch analysis, hypothesis generation, finding correlation, exploit-path reasoning, test development, technical writing, and remediation support.
- Experience designing, building, and maintaining reusable AI capabilities such as custom GPTs, Agent Skills, agents, subagents, prompt and context libraries, tool-enabled workflows, and multi-step analysis pipelines that encode repeatable vulnerability-research methods and produce consistent, auditable outputs.
- Experience developing automated or agentic workflows using model APIs and orchestration frameworks, including OpenAI’s Responses API and Agents SDK, Anthropic’s API and agent tooling, function or tool calling, structured outputs, retrieval-augmented generation, Model Context Protocol integrations, and secure connections to enterprise data and systems.
- Demonstrated ability to translate analyst procedures into repeatable AI-assisted workflows for vulnerability intake, advisory and patch analysis, exposure assessment, proof-of-concept review, affected-asset identification, threat-informed prioritization, remediation guidance, retesting, reporting, and knowledge capture.
- Practical experience evaluating multiple models and selecting fit-for-purpose approaches based on reasoning quality, coding performance, context requirements, latency, cost, privacy, data residency, and security constraints rather than relying on a single model or provider.
- Demonstrated experience developing security automation and integrating vulnerability data, AI-assisted analysis, and security controls with CI/CD platforms, source-control systems, scanners, asset inventories, cloud services, ticketing platforms, threat-intelligence sources, and security data platforms.
- Experience implementing AI safety and governance controls, including prompt-injection defenses, input and output validation, least-privilege tool access, sandboxing, human approval gates, sensitive-data handling, secrets protection, logging, traceability, reproducibility, model and dependency risk management, and prevention of unauthorized or disruptive actions.
- Evidence of testing and measuring AI-assisted security workflows using representative evaluation sets and operational metrics such as precision, recall, false-positive and false-negative rates, consistency, analyst time saved, research-to-detection time, remediation quality, and reduction in time to protective action.
- Ability to review model-generated code, queries, tests, detections, and remediation recommendations for hallucinations, unsafe assumptions, insecure code, weak evidence, and operational risk before those outputs are promoted into production or used to drive consequential decisions.
- One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred:
- Offensive Security Certified Professional (OSCP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Web Expert (OSWE), or comparable advanced offensive-security credential.
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or comparable vulnerability-research or assessment certification.
- Relevant cloud, Kubernetes, secure software, reverse-engineering, incident-response, or DevSecOps certification aligned with the assigned environment.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.techcareers.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago