yoinka

Principle, Vulnerability Analyst

Mastercard

O'Fallon, MissouriMid
Sign in to applyVerified 1h ago
Location
O'Fallon, Missouri
Work model
On-Site
Level
Mid
Posted
15h ago

About this role

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Principle, Vulnerability Analyst Overview • The AI Vulnerability Operations team is responsible for turning AI-identified security findings into validated, prioritized, and remediated risk reduction across Mastercard’s software environment. • This position is for a Principal Vulnerability Analyst who will work directly with application, engineering, product, and security teams to validate vulnerabilities identified through AI models and drive them through remediation. • The role will focus on determining whether AI-generated findings are exploitable, relevant, reachable, and material to the application or service being evaluated. • This position will help translate AI model outputs into clear technical guidance, remediation actions, risk decisions, and measurable vulnerability reduction outcomes. • The Principal Vulnerability Analyst will also provide feedback into AI vulnerability workflows to improve model precision, reduce false positives, identify missed context, and strengthen operational processes over time. Role • Validate vulnerabilities identified by AI models by reviewing code context, dependency data, application architecture, runtime exposure, compensating controls, and exploitability evidence. • Partner with application and engineering teams to confirm ownership, assess impact, determine remediation options, and drive vulnerabilities to closure. • Translate AI-generated vulnerability findings into clear, actionable remediation guidance that engineering teams can implement efficiently. • Triage AI findings to distinguish true positives, false positives, duplicates, accepted risks, configuration issues, dependency issues, and findings requiring additional analysis. • Assess vulnerability severity using available evidence, including exploitability, reachability, data sensitivity, business criticality, external exposure, dependency paths, and compensating controls. • Facilitate remediation discussions with product owners, developers, security engineers, and platform teams to remove blockers and maintain momentum on high-risk issues. • Verify remediation outcomes by reviewing code changes, dependency updates, configuration changes, compensating controls, retest results, and supporting evidence. • Document validation rationale, remediation decisions, residual risk, and closure evidence in vulnerability tracking and reporting systems. • Identify patterns across AI-generated findings and recommend improvements to secure coding practices, dependency management, build processes, and application security controls. • Provide feedback to AI model, data, and platform teams on finding quality, missing context, false positives, false negatives, prompt or workflow gaps, and opportunities for better prioritization. • Support prioritization of AI-identified vulnerabilities across critical, externally exposed, and high-risk applications to ensure remediation efforts focus on the areas of greatest risk. • Create playbooks, decision trees, validation standards, and remediation guidance to make AI vulnerability operations more consistent and scalable. • Mentor analysts and engineers on vulnerability validation, risk-based prioritization, secure remediation practices, and effective engagement with application teams. • Prepare executive-ready summaries, risk narratives, metrics, and status updates that communicate remediation progress, blockers, and residual risk. •

Principle, Vulnerability Analyst at Mastercard, O'Fallon, Missouri | Yoinka