×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Vulnerability Research Engineer, IT Security

Job in Saint Petersburg, Pinellas County, Florida, 33747, USA
Listing for: Raymond James Financial, Inc.
Part Time position
Listed on 2026-08-06
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
** This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.*
* ** _

Please note:

This role is not eligible for Work Visa sponsorship, either currently or in the future._*
* ** Responsibilities*
* + Lead threat-focused vulnerability research across enterprise applications, APIs, operating systems, network devices, cloud services, containers, open-source components, commercial products, and emerging AI-enabled technologies.

+ Continuously analyze threat intelligence, vendor advisories, public exploit research, malware and campaign reporting, security-research disclosures, and internal telemetry to identify vulnerabilities with credible relevance to the enterprise.

+ Perform authorized, controlled technical research to validate vulnerability conditions, affected versions, attack prerequisites, exploitability, reachability, likely impact, and available mitigations without creating unnecessary operational risk.

+ Reproduce vulnerabilities in isolated lab environments; analyze patches, source code, binaries, configurations, protocols, and proof-of-concept artifacts; and create defensible evidence that distinguishes theoretical exposure from actionable risk.

+ Develop safe detection and validation content such as authenticated checks, queries, signatures, scripts, test harnesses, configuration assessments, and exposure analytics. Ensure research artifacts are reviewed, version-controlled, documented, and designed to avoid disruption.

+ Build production-quality automation and integrations that ingest, normalize, enrich, correlate, deduplicate, prioritize, ticket, route, retest, and close vulnerability findings across scanners, asset inventories, threat-intelligence sources, software inventories, cloud platforms, endpoint tools, and engineering systems.

+ Create threat-informed prioritization models that incorporate active exploitation, adversary behavior, exploit maturity, internet exposure, asset criticality, application context, business service dependency, reachability, compensating controls, data sensitivity, and remediation feasibility.

+ Use AI-assisted research capabilities to summarize technical evidence, identify likely vulnerable code paths, compare patches, generate and refine test hypotheses, correlate findings, propose validation steps, and draft remediation guidance.

+ Evaluate and govern AI-assisted security workflows for accuracy, hallucination, prompt injection, insecure output, sensitive-data exposure, excessive agency, model and dependency supply-chain risk, reproducibility, auditability, and appropriate human oversight.

+ Design human-in-the-loop controls and benchmark AI-assisted workflows using measurable outcomes, including precision, recall, false-positive and false-negative rates, analyst time saved, validation quality, remediation quality, and reduction in time to protective action.

+ Provide rapid technical analysis for high-risk and actively exploited vulnerabilities, including concise impact assessments, affected-asset logic, interim mitigations, detection opportunities, validation procedures, and executive-ready risk communication.

+ Conduct root-cause and recurring-pattern analysis to identify systemic weaknesses in technology selection, configuration, software dependencies, asset visibility, patch processes, or control coverage; recommend durable preventive improvements.

+ Partner with remediation owners to explain technical risk, validate fixes and compensating controls, resolve disputed findings, and support risk-based decisions while maintaining clear evidence and accountability.

+ Define and report program metrics such as research-to-detection time, time to enterprise impact assessment, vulnerable-asset identification coverage, validation accuracy, remediation aging, recurrence, automation effectiveness, and measurable risk reduction.

+ Mentor engineers and analysts, establish research standards and playbooks, contribute to technical strategy and roadmaps, and serve as an escalation point for complex vulnerability questions and significant cybersecurity incidents.

** Qualifications*
* ** Knowledge, Skills, and Abilities:*
* + Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.

+ Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.

+ Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.

+ Strong automation and software engineering capability in Python and at least one of Power Shell,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary