×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Vulnerability Management Analyst

Job in Scottsdale, Maricopa County, Arizona, 85261, USA
Listing for: Advisor Group Inc.
Full Time position
Listed on 2026-07-30
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 105000 - 120000 USD Yearly USD 105000.00 120000.00 YEAR
Job Description & How to Apply Below

Overview

Senior Vulnerability Analyst for Osaic, focused on maturing enterprise vulnerability programs across SDLC, external attack surface, and internal infrastructure/applications. The role drives end‑to‑end vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics. Collaboration with Engineering, Product, Cloud/SRE, and IT is required. The position supports penetration testing readiness, evidence collection, remediation plans, and embedding security into the development workflow.

Location

and Schedule

Location options across hubs:
Atlanta, GA;
La Vista, NE;
Oakdale, MN;
Scottsdale, AZ;
St. Petersburg, FL. Osaic has returned to a hybrid schedule requiring a minimum of 4 days in the office weekly. Applicants should be located at one of the listed hubs and be willing to work this schedule.

Role Type and Compensation

Role Type:
Full-time, Non-Exempt

Salary: $105,000 - $120,000 per year + annual performance-based bonus. Actual compensation offered will be determined individually based on location, skills, licensure, experience, and education. Benefits include health, vision, dental insurance, 401k, paid time away, volunteer days, and more. To view details, visit the careers page:
Osaic Benefits.

Responsibilities
  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross‑team resolution.
  • Mentor junior analysts and improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Assist with pen test pre‑work: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder communications.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internet‑exposed services, DNS, certificates, cloud perimeters, API endpoints, and third‑party exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement shift‑left controls (pre‑commit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for high‑risk components (authN/Z, crypto, secrets handling, supply chain, multi‑tenant boundaries).
  • All other duties as assigned.
Qualifications
  • Basic Requirements: Deep technical/domain expertise and ability to lead initiatives. Strong understanding of OS, cloud environments, and vulnerability life cycles. Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses. Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.
  • Preferred Requirements: Experience with KEV catalog operationalization and threat‑intel integrations. Knowledge of automation platforms.
Education

Education Requirements:

Bachelor’s degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.

Application Note

Current Employees and Contractors Apply Here. Don’t see a job that works for you? You can still introduce yourself by clicking Get Started.

#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary