Lead Vulnerability Research Engineer
Raymond James · Saint Petersburg, United States · 2d ago
Job Description Summary
The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise.The Lead Vulnerability Research Engineer will be a hands-on technical leader within Vulnerability Management, responsible for discovering, validating, and operationalizing knowledge of vulnerabilities that present credible risk to the firm. The role combines threat-informed vulnerability research, offensive security, software engineering, data analysis, and security automation. The engineer will investigate emerging vulnerabilities and attack techniques; determine exploitability, reachability, and enterprise relevance; and convert research into repeatable detection, prioritization, validation, and remediation capabilities at scale.
The engineer will responsibly apply AI-assisted techniques to accelerate hypothesis generation, code and patch analysis, test development, finding correlation, exploit-path reasoning, and remediation guidance. AI output must remain subject to rigorous human validation, security and privacy controls, reproducibility standards, and measurable quality outcomes. The role will partner across threat intelligence, security operations, application security, infrastructure, cloud, engineering, architecture, and technology risk teams to reduce exposure before adversaries can act.
Job Description
This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.
Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.
Responsibilities:
- Lead threat-focused vulnerability research across enterprise applications, APIs, operating systems, network devices, cloud services, containers, open-source components, commercial products, and emerging AI-enabled technologies.
- Continuously analyze threat intelligence, vendor advisories, public exploit research, malware and campaign reporting, security-research disclosures, and internal telemetry to identify vulnerabilities with credible relevance to the enterprise.
- Perform authorized, controlled technical research to validate vulnerability conditions, affected versions, attack prerequisites, exploitability, reachability, likely impact, and available mitigations without creating unnecessary operational risk.
- Develop safe detection and validation content such as authenticated checks, queries, signatures, scripts, test harnesses, configuration assessments, and exposure analytics. Ensure research artifacts are reviewed, version-controlled, documented, and designed to avoid disruption.
- Build production-quality automation and integrations that ingest, normalize, enrich, correlate, deduplicate, prioritize, ticket, route, retest, and close vulnerability findings across scanners, asset inventories, threat-intelligence sources, software inventories, cloud platforms, endpoint tools, and engineering systems.
- Create threat-informed prioritization models that incorporate active exploitation, adversary behavior, exploit maturity, internet exposure, asset criticality, application context, business service dependency, reachability, compensating controls, data sensitivity, and remediation feasibility.
- Use AI-assisted research capabilities to summarize technical evidence, identify likely vulnerable code paths, compare patches, generate and refine test hypotheses, correlate findings, propose validation steps, draft remediation guidance, and help ensure responsible use of AI-assisted security workflows.
- Provide rapid technical analysis for high-risk and actively exploited vulnerabilities, including concise impact assessments, affected-asset logic, interim mitigations, detection opportunities, validation procedures, and executive-ready risk communication.
Knowledge, Skills, and Abilities:
- Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
- Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
- Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.
- Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.
- Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.
- Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.
- Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes.
- Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and to translate findings into prioritized engineering actions.
- Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs.
Previous Experience:
- Typically requires three or more years of hands-on experience in vulnerability research, vulnerability management engineering, offensive security, penetration testing, exploit validation, security tooling development, detection engineering, product security, application security, or a closely related discipline.
- Demonstrated hands-on experience using leading large language model platforms, including OpenAI GPT models and Anthropic Claude models, for security research, code and patch analysis, hypothesis generation, finding correlation, exploit-path reasoning, test development, technical writing, and remediation support.
- Demonstrated ability to translate analyst procedures into repeatable AI-assisted workflows for vulnerability intake, advisory and patch analysis, exposure assessment, proof-of-concept review, affected-asset identification, threat-informed prioritization, remediation guidance, retesting, reporting, and knowledge capture.
- Practical experience evaluating multiple models and selecting fit-for-purpose approaches based on reasoning quality, coding performance, context requirements, latency, cost, privacy, data residency, and security constraints rather than relying on a single model or provider.
- Demonstrated experience developing security automation and integrating vulnerability data, AI-assisted analysis, and security controls with CI/CD platforms, source-control systems, scanners, asset inventories, cloud services, ticketing platforms, threat-intelligence sources, and security data platforms.
Certifications:
One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred:
- Offensive Security Certified Professional (OSCP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Web Expert (OSWE), or comparable advanced offensive-security credential.
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or comparable vulnerability-research or assessment certification.
- Relevant cloud, Kubernetes, secure software, reverse-engineering, incident-response, or DevSecOps certification aligned with the assigned environment.
Education
High School (HS) (Required)Work Experience
General Experience - 6 to 10 yearsCertifications
Travel
Less than 25%Workstyle
HybridThe total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.
At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view.
We expect our associates at all levels to:
• Grow professionally and inspire others to do the same
• Work with and through others to achieve desired outcomes
• Make prompt, pragmatic choices and act with the client in mind
• Take ownership and hold themselves and others accountable for delivering results that matter
• Contribute to the continuous evolution of the firm
At Raymond James – as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.
#LI-TC1