Senior Vulnerability Management Analyst

Advisor Group Inc.

Scottsdale (AZ)

Hybrid

USD 105,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, vision, dental insurance
401k retirement plan
Paid time off
Annual performance-based bonus

Job summary

Advisor Group Inc. is looking for a Senior Vulnerability Analyst to oversee the entire vulnerability lifecycle, including risk triage, remediation validation, and metrics. The role entails collaboration with various teams and supports critical security enhancements.

This full-time position requires a strong technical background, knowledge of OS and cloud environments, and a proactive approach toward vulnerability management. The hired individual will also mentor junior analysts and lead complex investigations.

Qualifications

  • Deep technical/domain expertise and ability to lead initiatives.
  • Strong understanding of OS, cloud environments, and vulnerability lifecycles.
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.

Responsibilities

  • Lead vulnerability prioritization using CVSS and asset criticality.
  • Own complex vulnerability investigations and coordinate resolutions.
  • Manage findings intake, severity validation, and remediation plans.

Skills

Technical/domain expertise
Understanding of OS and cloud environments
Vulnerability lifecycle management
Mentoring skills
Strong communication

Education

Bachelor's degree preferred

Tools

Automation platforms
Security tools (CISSP, GIAC certifications)

Job description

Overview

Senior Vulnerability Analyst for Osaic, focused on maturing enterprise vulnerability programs across SDLC, external attack surface, and internal infrastructure/applications. The role drives end‑to‑end vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics. Collaboration with Engineering, Product, Cloud/SRE, and IT is required. The position supports penetration testing readiness, evidence collection, remediation plans, and embedding security into the development workflow.

Location and Schedule

Location options across hubs: Atlanta, GA; La Vista, NE; Oakdale, MN; Scottsdale, AZ; St. Petersburg, FL. Osaic has returned to a hybrid schedule requiring a minimum of 4 days in the office weekly. Applicants should be located at one of the listed hubs and be willing to work this schedule.

Role Type and Compensation

Role Type: Full-time, Non-Exempt

Salary: $105,000 - $120,000 per year + annual performance-based bonus. Actual compensation offered will be determined individually based on location, skills, licensure, experience, and education. Benefits include health, vision, dental insurance, 401k, paid time away, volunteer days, and more. To view details, visit the careers page: Osaic Benefits.

Responsibilities
  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross‑team resolution.
  • Mentor junior analysts and improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Assist with pen test pre‑work: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder communications.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internet‑exposed services, DNS, certificates, cloud perimeters, API endpoints, and third‑party exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement shift‑left controls (pre‑commit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for high‑risk components (authN/Z, crypto, secrets handling, supply chain, multi‑tenant boundaries).
  • All other duties as assigned.
Qualifications
  • Basic Requirements: Deep technical/domain expertise and ability to lead initiatives. Strong understanding of OS, cloud environments, and vulnerability lifecycles. Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses. Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.
  • Preferred Requirements: Experience with KEV catalog operationalization and threat‑intel integrations. Knowledge of automation platforms.
Education

Education Requirements: Bachelor’s degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.

Application Note

Current Employees and Contractors Apply Here. Don’t see a job that works for you? You can still introduce yourself by clicking Get Started.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability Management Analyst
Senior Vulnerability Management Analyst

Advisor Group • Scottsdale (AZ)

Hybrid
USD 105,000 - 120,000
Health insurance
401k
Paid time away
+1
Senior Vulnerability Management Lead - Hybrid IT Security
Senior Vulnerability Management Lead - Hybrid IT Security

Osaic • Scottsdale (AZ)

Hybrid
USD 105,000 - 120,000
Health insurance
401k
Paid time off
+1
Cloud Engineer
Cloud Engineer

Osaic • La Vista (NE)

Hybrid
USD 140,000 - 160,000
Health insurance
Vision insurance
Dental insurance
+3
Cloud Engineer
Cloud Engineer

Osaic • Saint Petersburg (FL)

Hybrid
USD 140,000 - 160,000
Health, vision, dental insurance
401k
Paid time away
+1
Cloud Engineer
Cloud Engineer

Osaic • Scottsdale (AZ)

Hybrid
USD 140,000 - 160,000
Health insurance
Vision insurance
Dental insurance
+3
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Risk and Vulnerability Analyst II
Risk and Vulnerability Analyst II

SOSi • Washington

On-site
USD 80,000 - 100,000
Vulnerability Assessment Analyst with Security Clearance
Vulnerability Assessment Analyst with Security Clearance

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 90,000 - 130,000
PTO 144 hours per year
11 holidays
Health insurance 85% premium covered
+2
Vulnerability Assessment Analyst
Vulnerability Assessment Analyst

ShorePoint • Albuquerque (NM)

On-site
USD 90,000 - 120,000
PTO 144 hours
Holidays 11
Health insurance
+3
Sr. IT Project Manager
Sr. IT Project Manager

Advisor Group • Scottsdale (AZ)

Hybrid
USD 120,000 - 124,000
Health insurance
401k
Paid time off