Enter a job title or keyword

Lead Vulnerability Research Engineer, IT Security

Raymond James


Job Location:

Pinellas County, FL - USA

Monthly Salary: Not provided by the employer
Posted: 21 August 2026 (Yesterday)
Application Deadline: 18 November 2026
Vacancies: 1 Vacancy

Job Summary

Job Description Summary

The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify assess and reduce technology risk across the enterprise.


The Lead Vulnerability Research Engineer will be a hands-on technical leader within Vulnerability Management responsible for discovering validating and operationalizing knowledge of vulnerabilities that present credible risk to the firm. The role combines threat-informed vulnerability research offensive security software engineering data analysis and security automation. The engineer will investigate emerging vulnerabilities and attack techniques; determine exploitability reachability and enterprise relevance; and convert research into repeatable detection prioritization validation and remediation capabilities at scale.


The engineer will responsibly apply AI-assisted techniques to accelerate hypothesis generation code and patch analysis test development finding correlation exploit-path reasoning and remediation guidance. AI output must remain subject to rigorous human validation security and privacy controls reproducibility standards and measurable quality outcomes. The role will partner across threat intelligence security operations application security infrastructure cloud engineering architecture and technology risk teams to reduce exposure before adversaries can act.

Job Description

This position follows a hybrid work model with an expectation to be in the office 3 days per week at the St. Petersburg FL Corporate Office location.

Please note: This role is not eligible for Work Visa sponsorship either currently or in the future.

Responsibilities

  • Lead threat-focused vulnerability research across enterprise applications APIs operating systems network devices cloud services containers open-source components commercial products and emerging AI-enabled technologies.

  • Continuously analyze threat intelligence vendor advisories public exploit research malware and campaign reporting security-research disclosures and internal telemetry toidentifyvulnerabilities with credible relevance to the enterprise.

  • Perform authorized controlled technical research tovalidatevulnerability conditions affected versions attack prerequisites exploitability reachabilitylikely impact and available mitigations without creating unnecessary operational risk.

  • Reproduce vulnerabilities in isolated lab environments; analyze patches source code binaries configurations protocols and proof-of-concept artifacts; and create defensible evidence that distinguishes theoretical exposure from actionable risk.

  • Develop safe detection and validation content such as authenticated checks queries signatures scripts test harnesses configuration assessments and exposure analytics. Ensure research artifacts are reviewed version-controlled documented and designed to avoid disruption.

  • Build production-quality automation and integrations that ingest normalize enrich correlate deduplicate prioritize ticket route retest and close vulnerability findings across scanners asset inventories threat-intelligence sources software inventories cloud platforms endpoint tools and engineering systems.

  • Create threat-informed prioritization models that incorporate active exploitation adversary behavior exploit maturity internet exposure asset criticality application context business service dependency reachability compensating controls data sensitivity and remediation feasibility.

  • Use AI-assisted research capabilities to summarize technical evidenceidentifylikely vulnerablecode paths compare patches generate and refine test hypotheses correlate findings propose validation steps and draft remediation guidance.

  • Evaluate and govern AI-assisted security workflows for accuracy hallucination prompt injection insecure output sensitive-data exposure excessive agency model and dependency supply-chain risk reproducibility auditability andappropriate humanoversight.

  • Design human-in-the-loop controls and benchmark AI-assisted workflows using measurable outcomes including precision recall false-positive and false-negative rates analyst time saved validation quality remediation quality and reduction in time to protective action.

  • Provide rapid technical analysis for high-risk and actively exploited vulnerabilities including concise impact assessments affected-asset logic interim mitigations detection opportunities validation procedures and executive-ready risk communication.

  • Conduct root-cause andrecurring-patternanalysis toidentifysystemic weaknesses in technology selection configuration software dependencies asset visibility patch processes or control coverage; recommend durable preventive improvements.

  • Partner with remediation owners to explain technical riskvalidatefixes andcompensatingcontrols resolve disputed findings and support risk-based decisions whilemaintainingclear evidenceand accountability.

  • Define and report program metrics such as research-to-detection time time to enterprise impact assessment vulnerable-asset identification coverage validation accuracy remediation aging recurrence automation effectiveness and measurable risk reduction.

  • Mentor engineers and analystsestablishresearch standards and playbooks contribute to technical strategy and roadmaps and serve as an escalation point for complex vulnerability questions and significant cybersecurity incidents.

Qualifications

Knowledge Skills and Abilities:

  • Demonstratedexpertiseidentifyingvalidating explaining and remediating application and API vulnerabilities including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.

  • Advanced understanding of authentication authorization session management cryptography input handling deserialization server-side request forgery business-logic abuse and modern client/server attack surfaces.

  • Hands-on experience with SAST DAST IAST SCA API testing secrets detection container scanning infrastructure-as-code scanning and penetration-testing tools; ability to tune controls andvalidatetool output rather than rely solely on scanner severity.

  • Strong automation and software engineering capability in Python and at least one of PowerShell JavaScript/TypeScript Go Java C# or shell; experience consuming REST/GraphQLAPIs processing structured data writing tests andmaintainingproduction-quality code.

  • Experience integrating security tools with CI/CD and engineering platforms such as GitHub GitLab Azure DevOps Jenkins Jira or comparable technologies.

  • Demonstratedexperience applying AI-assisted or machine-learning-enabled security tooling to source-code review vulnerability triage exploit-path analysis test generation remediation support or finding correlation.

  • Ability to critically evaluate AI output recognize hallucinations and insecure recommendations protect sensitive source code and data design human-in-the-loop validation andestablishmeasurable quality and governance controls.

  • Knowledge of secure AI-assisted development risks including prompt injection insecure output handling excessive agency sensitive information disclosure model or dependency supply-chain concerns and misuse of generated code.

  • Experience securing cloud-native applications on Microsoft Azure Amazon Web Services and/or Google Cloud Platform including identity secrets workloads APIs containers serverless services and Kubernetes.

  • Working knowledge of threat modeling secure architecture principles softwaresupply-chainsecurity SBOM/VEX concepts artifact integrity dependency governance and provenance or attestation practices.

  • Ability to communicate technical risk clearly to developers architects executives auditors and non-technical stakeholders and to translate findings into prioritized engineering actions.

  • Ability to lead through influence exercise sound judgment under uncertainty mentor others and balance security outcomes with client and business needs.

Education/Previous Experience:

  • Typically requires aBachelors degree in computer science software engineering cybersecurity information systems artificial intelligence data science engineering or a related field and five or more years of relevant experience. An equivalent combination of education training industry research anddemonstratedtechnical experience may be considered.

  • Typically requires three or more years of hands-on experience in vulnerability research vulnerability management engineering offensive security penetration testing exploit validation security tooling development detection engineering product security application security or a closely related discipline.

  • Demonstratedhands-on experience using leading large language model platforms including OpenAI GPT models and Anthropic Claude models for security research code and patch analysis hypothesis generation finding correlation exploit-path reasoning test development technical writing and remediation support.

  • Experience designing building andmaintainingreusable AI capabilities such as custom GPTs Agent Skills agents subagents prompt and context libraries tool-enabled workflows and multi-step analysis pipelines that encode repeatable vulnerability-research methods and produce consistent auditable outputs.

  • Experience developing automated or agentic workflows using model APIs and orchestration frameworks including OpenAIs Responses API and Agents SDKAnthropicsAPI and agent tooling function or tool calling structured outputs retrieval-augmented generation Model Context Protocol integrations and secure connections to enterprise data and systems.

  • Demonstratedability to translate analyst procedures into repeatable AI-assisted workflows for vulnerability intake advisory and patch analysis exposure assessment proof-of-concept review affected-asset identification threat-informed prioritization remediation guidance retesting reporting and knowledge capture.

  • Practical experience evaluating multiple models and selecting fit-for-purpose approaches based on reasoning quality coding performance context requirements latency cost privacy data residency and security constraints rather than relying on a single model or provider.

  • Demonstratedexperience developing security automation and integrating vulnerability data AI-assisted analysis and security controls with CI/CD platforms source-control systems scanners asset inventories cloud services ticketing platforms threat-intelligence sources and security data platforms.

  • Experience implementing AI safety and governance controls including prompt-injection defenses input and output validation least-privilege tool access sandboxing human approval gates sensitive-data handling secrets protection logging traceability reproducibility model and dependency risk management and prevention of unauthorized or disruptive actions.

  • Evidence of testing and measuring AI-assisted security workflows using representative evaluation sets and operational metrics such as precision recall false-positive and false-negative rates consistency analyst time saved research-to-detection time remediation quality and reduction in time to protective action.

  • Ability to review model-generated code queries tests detections and remediation recommendations for hallucinations unsafe assumptions insecure code weak evidence and operational risk before those outputs are promoted into production or used to drive consequential decisions.

Certifications

One or more of the following certifications or the ability to obtain a relevant certification within one year is preferred:

  • Offensive Security Certified Professional (OSCP) Offensive Security Experienced Penetration Tester (OSEP) Offensive Security Web Expert (OSWE) or comparable advanced offensive-security credential.

  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) GIAC Penetration Tester (GPEN) GIAC Web Application Penetration Tester (GWAPT) or comparablevulnerability-researchor assessment certification.

  • Relevant cloud Kubernetes secure softwarereverse-engineering incident-response orDevSecOpscertification aligned with the assigned environment.

Education

Bachelors Bachelors: Data Science Bachelors: Information Technology

Work Experience

General Experience - 6 to 10 years

Certifications

Travel

Less than 25%

Workstyle

Hybrid

The total compensation for this position includes base salary or wages and may include components such as additional compensation (cash or equity) discretionary bonuses or commissions. This position is eligible for a benefits package that may include medical dental and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation holidays and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered visit .

At Raymond James our associates use five guiding behaviors (Develop Collaborate Decide Deliver Improve) to deliver on the firms core values of client-first integrity independence and a conservative long-term view.

We expect our associates at all levels to:
Grow professionally and inspire others to do the same
Work with and through others to achieve desired outcomes
Make prompt pragmatic choices and act with the client in mind
Take ownership and hold themselves and others accountable for delivering results that matter
Contribute to the continuous evolution of the firm

At Raymond James as part of our people-first culture we honor value and respect the uniqueness experiences and backgrounds of all of our Associates. When associates bring their best authentic selves our organization clients and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.


Required Experience:

IC


About Company

Company Logo

A full-service financial firm where progress is driven by connection, delivering extensive wealth management, banking and capital markets capabilities to help clients, institutions and communities reach their goals.

View Profile View Profile