Principle, Vulnerability Analyst
$152,000–$258,000 year
On-siteO'Fallon, Missouri, United States
Job Summary
Validate vulnerabilities identified by AI models by reviewing code context, dependency data, and application architecture to determine exploitable risk. Partner with engineering and product teams to confirm ownership, assess impact, and drive remediation to closure. Triage findings to distinguish true positives from false positives, then assess severity using exploitability, reachability, and business criticality. Translate AI outputs into actionable guidance, verify remediation outcomes, and document rationale in tracking systems. Identify patterns to recommend improvements to secure coding practices and provide feedback to AI teams on workflow gaps. Mentor analysts on risk-based prioritization and create playbooks to standardize validation processes. Prepare executive summaries and status updates for leadership.
Required Qualifications
- Strong experience in vulnerability management, application security, secure software development, or security engineering, with demonstrated ability to validate and drive remediation of software vulnerabilities
- Deep understanding of common vulnerability classes, secure coding practices, OWASP, CWE, CVSS, exploitability analysis, threat modeling, and risk-based prioritization
- Experience reviewing source code, dependency manifests, software composition analysis results, static analysis findings, container findings, configuration evidence, and application architecture to determine real-world risk
- Ability to work directly with application teams to explain vulnerabilities, recommend practical fixes, resolve disagreements, and drive remediation to completion
- Strong analytical judgment to evaluate AI-generated findings, identify false positives, determine missing context, and distinguish theoretical risk from exploitable risk
- Experience with vulnerability tracking, remediation workflows, exception handling, risk acceptance, retesting, and closure evidence
- Familiarity with AI-assisted security workflows, including how model-generated findings can be validated, enriched, prioritized, and improved through analyst feedback
- Ability to communicate complex vulnerability details clearly to developers, product owners, security leaders, and non-technical stakeholders
- Strong written documentation skills, including the ability to produce validation notes, remediation guidance, risk narratives, executive summaries, and operational playbooks
- Experience collaborating across security, software engineering, product, platform, and operations teams in a large enterprise environment
- Strong leadership qualities, including mentoring, influencing without authority, driving accountability, and creating repeatable processes for others to follow
- Comfortable working in ambiguous, evolving environments where new AI-enabled workflows, tools, and processes are being developed and refined
- Ability to identify process improvements that reduce remediation friction, improve customer experience, and increase the quality and speed of vulnerability closure
- Abide by Mastercard's security policies and practices
- Ensure the confidentiality and integrity of the information being accessed
- Report any suspected information security violation or breach
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.