{"schemaVersion":"jobsearcher.job.v1","id":"5aeef11e533a19d5b0db84ad","url":"https://jobsearcher.com/jobs/5aeef11e533a19d5b0db84ad","canonicalUrl":"https://jobsearcher.com/jobs/5aeef11e533a19d5b0db84ad","title":"Principle Vulnerability Analyst","description":"Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.\r\nTitle and Summary Principle, Vulnerability Analyst Overview\r\nThe AI Vulnerability Operations team is responsible for turning AI-identified security findings into validated, prioritized, and remediated risk reduction across Mastercard's software environment.\r\nThis position is for a Principal Vulnerability Analyst who will work directly with application, engineering, product, and security teams to validate vulnerabilities identified through AI models and drive them through remediation.\r\nThe role will focus on determining whether AI-generated findings are exploitable, relevant, reachable, and material to the application or service being evaluated.\r\nThis position will help translate AI model outputs into clear technical guidance, remediation actions, risk decisions, and measurable vulnerability reduction outcomes.\r\nThe Principal Vulnerability Analyst will also provide feedback into AI vulnerability workflows to improve model precision, reduce false positives, identify missed context, and strengthen operational processes over time.\r\nRole Validate vulnerabilities identified by AI models by reviewing code context, dependency data, application architecture, runtime exposure, compensating controls, and exploitability evidence.\r\nPartner with application and engineering teams to confirm ownership, assess impact, determine remediation options, and drive vulnerabilities to closure.\r\nTranslate AI-generated vulnerability findings into clear, actionable remediation guidance that engineering teams can implement efficiently.\r\nTriage AI findings to distinguish true positives, false positives, duplicates, accepted risks, configuration issues, dependency issues, and findings requiring additional analysis.\r\nAssess vulnerability severity using available evidence, including exploitability, reachability, data sensitivity, business criticality, external exposure, dependency paths, and compensating controls.\r\nFacilitate remediation discussions with product owners, developers, security engineers, and platform teams to remove blockers and maintain momentum on high-risk issues.\r\nVerify remediation outcomes by reviewing code changes, dependency updates, configuration changes, compensating controls, retest results, and supporting evidence.\r\nDocument validation rationale, remediation decisions, residual risk, and closure evidence in vulnerability tracking and reporting systems.\r\nIdentify patterns across AI-generated findings and recommend improvements to secure coding practices, dependency management, build processes, and application security controls.\r\nProvide feedback to AI model, data, and platform teams on finding quality, missing context, false positives, false negatives, prompt or workflow gaps, and opportunities for better prioritization.\r\nSupport prioritization of AI-identified vulnerabilities across critical, externally exposed, and high-risk applications to ensure remediation efforts focus on the areas of greatest risk.\r\nCreate playbooks, decision trees, validation standards, and remediation guidance to make AI vulnerability operations more consistent and scalable.\r\nMentor analysts and engineers on vulnerability validation, risk-based prioritization, secure remediation practices, and effective engagement with application teams.\r\nPrepare executive-ready summaries, risk narratives, metrics, and status updates that communicate remediation progress, blockers, and residual risk.\r\nContinuously improve the AI vulnerability validation lifecycle by reducing manual effort, improving evidence quality, and strengthening handoffs between AI tooling, analysts, and engineering teams.\r\nAll About You Strong experience in vulnerability management, application security, secure software development, or security engineering, with demonstrated ability to validate and drive remediation of software vulnerabilities.\r\nDeep understanding of common vulnerability classes, secure coding practices, OWASP, CWE, CVSS, exploitability analysis, threat modeling, and risk-based prioritization.\r\nExperience reviewing source code, dependency manifests, software composition analysis results, static analysis findings, container findings, configuration evidence, and application architecture to determine real-world risk.\r\nAbility to work directly with application teams to explain vulnerabilities, recommend practical fixes, resolve disagreements, and drive remediation to completion.\r\nStrong analytical judgment to evaluate AI-generated findings, identify false positives, determine missing context, and distinguish theoretical risk from exploitable risk.\r\nExperience with vulnerability tracking, remediation workflows, exception handling, risk acceptance, retesting, and closure evidence.\r\nFamiliarity with AI-assisted security workflows, including how model-generated findings can be validated, enriched, prioritized, and improved through analyst feedback.\r\nAbility to communicate complex vulnerability details clearly to developers, product owners, security leaders, and non-technical stakeholders.\r\nStrong written documentation skills, including the ability to produce validation notes, remediation guidance, risk narratives, executive summaries, and operational playbooks.\r\nExperience collaborating across security, software engineering, product, platform, and operations teams in a large enterprise environment.\r\nStrong leadership qualities, including mentoring, influencing without authority, driving accountability, and creating repeatable processes for others to follow.\r\nComfortable working in ambiguous, evolving environments where new AI-enabled workflows, tools, and processes are being developed and refined.\r\nAbility to identify process improvements that reduce remediation friction, improve customer experience, and increase the quality and speed of vulnerability closure.\r\nMastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.\r\nCorporate Security Responsibility Abide by Mastercard's security policies and practices;\r\nEnsure the confidentiality and integrity of the information being accessed;\r\nReport any suspected information security violation or breach, and\r\nComplete all periodic mandatory security trainings in accordance with Mastercard's guidelines.\r\nIn line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.\r\nPay Ranges O'Fallon, Missouri: $152,000 - $258,000 USD#J-18808-Ljbffr","company":"Socket","rawCompany":"socket","city":"O Fallon","state":"MO","isRemote":false,"isActive":true,"createdAt":"2026-08-13T02:06:14.847Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"522320","title":"Financial Transactions Processing, Reserve, and Clearinghouse Activities","slug":"financial-transactions-processing-reserve-and-clearinghouse-activities"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Principle Vulnerability Analyst","description":"Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.\r\nTitle and Summary Principle, Vulnerability Analyst Overview\r\nThe AI Vulnerability Operations team is responsible for turning AI-identified security findings into validated, prioritized, and remediated risk reduction across Mastercard's software environment.\r\nThis position is for a Principal Vulnerability Analyst who will work directly with application, engineering, product, and security teams to validate vulnerabilities identified through AI models and drive them through remediation.\r\nThe role will focus on determining whether AI-generated findings are exploitable, relevant, reachable, and material to the application or service being evaluated.\r\nThis position will help translate AI model outputs into clear technical guidance, remediation actions, risk decisions, and measurable vulnerability reduction outcomes.\r\nThe Principal Vulnerability Analyst will also provide feedback into AI vulnerability workflows to improve model precision, reduce false positives, identify missed context, and strengthen operational processes over time.\r\nRole Validate vulnerabilities identified by AI models by reviewing code context, dependency data, application architecture, runtime exposure, compensating controls, and exploitability evidence.\r\nPartner with application and engineering teams to confirm ownership, assess impact, determine remediation options, and drive vulnerabilities to closure.\r\nTranslate AI-generated vulnerability findings into clear, actionable remediation guidance that engineering teams can implement efficiently.\r\nTriage AI findings to distinguish true positives, false positives, duplicates, accepted risks, configuration issues, dependency issues, and findings requiring additional analysis.\r\nAssess vulnerability severity using available evidence, including exploitability, reachability, data sensitivity, business criticality, external exposure, dependency paths, and compensating controls.\r\nFacilitate remediation discussions with product owners, developers, security engineers, and platform teams to remove blockers and maintain momentum on high-risk issues.\r\nVerify remediation outcomes by reviewing code changes, dependency updates, configuration changes, compensating controls, retest results, and supporting evidence.\r\nDocument validation rationale, remediation decisions, residual risk, and closure evidence in vulnerability tracking and reporting systems.\r\nIdentify patterns across AI-generated findings and recommend improvements to secure coding practices, dependency management, build processes, and application security controls.\r\nProvide feedback to AI model, data, and platform teams on finding quality, missing context, false positives, false negatives, prompt or workflow gaps, and opportunities for better prioritization.\r\nSupport prioritization of AI-identified vulnerabilities across critical, externally exposed, and high-risk applications to ensure remediation efforts focus on the areas of greatest risk.\r\nCreate playbooks, decision trees, validation standards, and remediation guidance to make AI vulnerability operations more consistent and scalable.\r\nMentor analysts and engineers on vulnerability validation, risk-based prioritization, secure remediation practices, and effective engagement with application teams.\r\nPrepare executive-ready summaries, risk narratives, metrics, and status updates that communicate remediation progress, blockers, and residual risk.\r\nContinuously improve the AI vulnerability validation lifecycle by reducing manual effort, improving evidence quality, and strengthening handoffs between AI tooling, analysts, and engineering teams.\r\nAll About You Strong experience in vulnerability management, application security, secure software development, or security engineering, with demonstrated ability to validate and drive remediation of software vulnerabilities.\r\nDeep understanding of common vulnerability classes, secure coding practices, OWASP, CWE, CVSS, exploitability analysis, threat modeling, and risk-based prioritization.\r\nExperience reviewing source code, dependency manifests, software composition analysis results, static analysis findings, container findings, configuration evidence, and application architecture to determine real-world risk.\r\nAbility to work directly with application teams to explain vulnerabilities, recommend practical fixes, resolve disagreements, and drive remediation to completion.\r\nStrong analytical judgment to evaluate AI-generated findings, identify false positives, determine missing context, and distinguish theoretical risk from exploitable risk.\r\nExperience with vulnerability tracking, remediation workflows, exception handling, risk acceptance, retesting, and closure evidence.\r\nFamiliarity with AI-assisted security workflows, including how model-generated findings can be validated, enriched, prioritized, and improved through analyst feedback.\r\nAbility to communicate complex vulnerability details clearly to developers, product owners, security leaders, and non-technical stakeholders.\r\nStrong written documentation skills, including the ability to produce validation notes, remediation guidance, risk narratives, executive summaries, and operational playbooks.\r\nExperience collaborating across security, software engineering, product, platform, and operations teams in a large enterprise environment.\r\nStrong leadership qualities, including mentoring, influencing without authority, driving accountability, and creating repeatable processes for others to follow.\r\nComfortable working in ambiguous, evolving environments where new AI-enabled workflows, tools, and processes are being developed and refined.\r\nAbility to identify process improvements that reduce remediation friction, improve customer experience, and increase the quality and speed of vulnerability closure.\r\nMastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.\r\nCorporate Security Responsibility Abide by Mastercard's security policies and practices;\r\nEnsure the confidentiality and integrity of the information being accessed;\r\nReport any suspected information security violation or breach, and\r\nComplete all periodic mandatory security trainings in accordance with Mastercard's guidelines.\r\nIn line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.\r\nPay Ranges O'Fallon, Missouri: $152,000 - $258,000 USD#J-18808-Ljbffr","datePosted":"2026-08-13T02:06:14.847Z","dateModified":"2026-08-13T02:06:14.847Z","hiringOrganization":{"@type":"Organization","name":"Socket","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"O Fallon","addressRegion":"MO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5aeef11e533a19d5b0db84ad"},"url":"https://jobsearcher.com/jobs/5aeef11e533a19d5b0db84ad"}}