Raymond James Financial, Inc

Lead Vulnerability Research Engineer, IT Security

Raymond James Financial, Inc$120K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field or equivalent experience
  • 5+ years in vulnerability research, application security, or related area
  • Hands-on expertise in OWASP vulnerabilities and response
  • Proficient in Python and one additional programming language
  • Experience with AI-assisted security tools and automation workflows
  • Familiar with cloud security practices and technologies
  • Strong communication skills for reporting technical risks

Responsibilities

  • Lead vulnerability research focused on enterprise applications and emerging technologies
  • Analyze threat intelligence to identify relevant vulnerabilities
  • Perform controlled technical research to validate vulnerabilities
  • Develop detection and validation content with an emphasis on safety
  • Build automated workflows to manage and prioritize vulnerabilities
  • Create and govern prioritization models based on threat intelligence
  • Conduct in-depth analysis for high-risk vulnerabilities and communicate risks clearly

Benefits

  • Medical, dental, and vision insurance
  • Life and critical illness insurance
  • Disability benefits and retirement savings plans
  • Paid time off including vacation and sick leave
  • Parental leave options
  • Eligible for hybrid work model with in-office requirements
Full Job Description
Job Description Summary
The Lead Vulnerability Research Engineer will be a hands-on technical leader within Vulnerability Management, responsible for discovering, validating, and operationalizing knowledge of vulnerabilities that present credible risk to the firm. The role combines threat-informed vulnerability research, offensive security, software engineering, data analysis, and security automation. The engineer will investigate emerging vulnerabilities and attack techniques; determine exploitability, reachability, and enterprise relevance; and convert research into repeatable detection, prioritization, validation, and remediation capabilities at scale.
The engineer will responsibly apply AI-assisted techniques to accelerate hypothesis generation, code and patch analysis, test development, finding correlation, exploit-path reasoning, and remediation guidance. AI output must remain subject to rigorous human validation, security and privacy controls, reproducibility standards, and measurable quality outcomes. The role will partner across threat intelligence, security operations, application security, infrastructure, cloud, engineering, architecture, and technology risk teams to reduce exposure before adversaries can act.

Job Description

This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.

Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.

Responsibilities
  • Lead threat-focused vulnerability research across enterprise applications, APIs, operating systems, network devices, cloud services, containers, open-source components, commercial products, and emerging AI-enabled technologies.
  • Continuously analyze threat intelligence, vendor advisories, public exploit research, malware and campaign reporting, security-research disclosures, and internal telemetry to identify vulnerabilities with credible relevance to the enterprise.
  • Perform authorized, controlled technical research to validate vulnerability conditions, affected versions, attack prerequisites, exploitability, reachability, likely impact, and available mitigations without creating unnecessary operational risk.
  • Reproduce vulnerabilities in isolated lab environments; analyze patches, source code, binaries, configurations, protocols, and proof-of-concept artifacts; and create defensible evidence that distinguishes theoretical exposure from actionable risk.
  • Develop safe detection and validation content such as authenticated checks, queries, signatures, scripts, test harnesses, configuration assessments, and exposure analytics. Ensure research artifacts are reviewed, version-controlled, documented, and designed to avoid disruption.
  • Build production-quality automation and integrations that ingest, normalize, enrich, correlate, deduplicate, prioritize, ticket, route, retest, and close vulnerability findings across scanners, asset inventories, threat-intelligence sources, software inventories, cloud platforms, endpoint tools, and engineering systems.
  • Create threat-informed prioritization models that incorporate active exploitation, adversary behavior, exploit maturity, internet exposure, asset criticality, application context, business service dependency, reachability, compensating controls, data sensitivity, and remediation feasibility.
  • Use AI-assisted research capabilities to summarize technical evidence, identify likely vulnerable code paths, compare patches, generate and refine test hypotheses, correlate findings, propose validation steps, and draft remediation guidance.
  • Evaluate and govern AI-assisted security workflows for accuracy, hallucination, prompt injection, insecure output, sensitive-data exposure, excessive agency, model and dependency supply-chain risk, reproducibility, auditability, and appropriate human oversight.
  • Design human-in-the-loop controls and benchmark AI-assisted workflows using measurable outcomes, including precision, recall, false-positive and false-negative rates, analyst time saved, validation quality, remediation quality, and reduction in time to protective action.
  • Provide rapid technical analysis for high-risk and actively exploited vulnerabilities, including concise impact assessments, affected-asset logic, interim mitigations, detection opportunities, validation procedures, and executive-ready risk communication.
  • Conduct root-cause and recurring-pattern analysis to identify systemic weaknesses in technology selection, configuration, software dependencies, asset visibility, patch processes, or control coverage; recommend durable preventive improvements.
  • Partner with remediation owners to explain technical risk, validate fixes and compensating controls, resolve disputed findings, and support risk-based decisions while maintaining clear evidence and accountability.
  • Define and report program metrics such as research-to-detection time, time to enterprise impact assessment, vulnerable-asset identification coverage, validation accuracy, remediation aging, recurrence, automation effectiveness, and measurable risk reduction.
  • Mentor engineers and analysts, establish research standards and playbooks, contribute to technical strategy and roadmaps, and serve as an escalation point for complex vulnerability questions and significant cybersecurity incidents.


Qualifications

Knowledge, Skills, and Abilities:
  • Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
  • Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
  • Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.
  • Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.
  • Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.
  • Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.
  • Ability to critically evaluate AI output, recognize hallucinations and insecure recommendations, protect sensitive source code and data, design human-in-the-loop validation, and establish measurable quality and governance controls.
  • Knowledge of secure AI-assisted development risks, including prompt injection, insecure output handling, excessive agency, sensitive information disclosure, model or dependency supply-chain concerns, and misuse of generated code.
  • Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes.
  • Working knowledge of threat modeling, secure architecture principles, software supply-chain security, SBOM/VEX concepts, artifact integrity, dependency governance, and provenance or attestation practices.
  • Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and to translate findings into prioritized engineering actions.
  • Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs.


Education/Previous Experience:
  • Typically requires a Bachelor's degree in computer science, software engineering, cybersecurity, information systems, artificial intelligence, data science, engineering, or a related field and five or more years of relevant experience. An equivalent combination of education, training, industry research, and demonstrated technical experience may be considered.
  • Typically requires three or more years of hands-on experience in vulnerability research, vulnerability management engineering, offensive security, penetration testing, exploit validation, security tooling development, detection engineering, product security, application security, or a closely related discipline.
  • Demonstrated hands-on experience using leading large language model platforms, including OpenAI GPT models and Anthropic Claude models, for security research, code and patch analysis, hypothesis generation, finding correlation, exploit-path reasoning, test development, technical writing, and remediation support.
  • Experience designing, building, and maintaining reusable AI capabilities such as custom GPTs, Agent Skills, agents, subagents, prompt and context libraries, tool-enabled workflows, and multi-step analysis pipelines that encode repeatable vulnerability-research methods and produce consistent, auditable outputs.
  • Experience developing automated or agentic workflows using model APIs and orchestration frameworks, including OpenAI's Responses API and Agents SDK, Anthropic's API and agent tooling, function or tool calling, structured outputs, retrieval-augmented generation, Model Context Protocol integrations, and secure connections to enterprise data and systems.
  • Demonstrated ability to translate analyst procedures into repeatable AI-assisted workflows for vulnerability intake, advisory and patch analysis, exposure assessment, proof-of-concept review, affected-asset identification, threat-informed prioritization, remediation guidance, retesting, reporting, and knowledge capture.
  • Practical experience evaluating multiple models and selecting fit-for-purpose approaches based on reasoning quality, coding performance, context requirements, latency, cost, privacy, data residency, and security constraints rather than relying on a single model or provider.
  • Demonstrated experience developing security automation and integrating vulnerability data, AI-assisted analysis, and security controls with CI/CD platforms, source-control systems, scanners, asset inventories, cloud services, ticketing platforms, threat-intelligence sources, and security data platforms.
  • Experience implementing AI safety and governance controls, including prompt-injection defenses, input and output validation, least-privilege tool access, sandboxing, human approval gates, sensitive-data handling, secrets protection, logging, traceability, reproducibility, model and dependency risk management, and prevention of unauthorized or disruptive actions.
  • Evidence of testing and measuring AI-assisted security workflows using representative evaluation sets and operational metrics such as precision, recall, false-positive and false-negative rates, consistency, analyst time saved, research-to-detection time, remediation quality, and reduction in time to protective action.
  • Ability to review model-generated code, queries, tests, detections, and remediation recommendations for hallucinations, unsafe assumptions, insecure code, weak evidence, and operational risk before those outputs are promoted into production or used to drive consequential decisions.
  • One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred:
  • Offensive Security Certified Professional (OSCP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Web Expert (OSWE), or comparable advanced offensive-security credential.
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or comparable vulnerability-research or assessment certification.
  • Relevant cloud, Kubernetes, secure software, reverse-engineering, incident-response, or DevSecOps certification aligned with the assigned environment.


Education
Bachelor's: Data Science, Bachelor's: Information Technology, Bachelor's (Required)

Work Experience
General Experience - 6 to 10 years, Manager Experience - 10 to 15 years

Certifications

Travel

Workstyle
Hybrid

The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.

About Raymond James Financial, Inc

The Raymond James Technology and Communications Investment Banking Group is a committed and thoughtful partner that provides a full range of investment banking services and best practices. The group is comprised of experienced professionals that have extensive investment banking expertise. They leverage the industry expertise of Raymond James' award-winning research department. The group focuses on key sectors within technology and communications including: communications software, communication towers, defense electronics, enterprise software, internet infrastructure services, homeland security, IT services, mobile technology, semiconductors, software-as-a-service, telecommunications equipment, telecommunications infrastructure and support services, and wireless & wireline telecommunications services. They take pride in a client-centric approach to M&A, with focus on delivering independent solutions that creates value for the long term. The outcome of this unique approach may be seen in the successful transactions of their clients, including over 80 public offerings totaling $17 billion and over 85 strategic advisory transactions totaling over $5 billion in value since 1998.

Raymond James Financial, Inc Careers

Join the vibrant team at Raymond James Financial, Inc, a leading financial services company where innovation, leadership, and professional growth are at the forefront of our operations. As a hub of diversity and expertise, Raymond James offers unparalleled job opportunities that propel your career to new heights. Work You’ll Do At Raymond James Financial, Inc, you’ll collaborate with some of the most talented professionals in the financial industry. Our team is dedicated to providing strategic financial solutions and advice to our clients, helping them achieve their financial goals while fostering economic growth. With a culture rooted in leadership and diversity training, Raymond James is the perfect place to enhance your skills and thrive professionally. Join our market-leading team to assist a diverse range of clients, from individuals to large corporations, in navigating their financial planning with precision and innovative strategies. Lead in a role where your expertise directly influences the success and stability of our clients' financial futures. Work with a dynamic team of advisors and experts who are committed to pushing the boundaries of the financial sector through continuous innovation and exceptional client service. Raymond James Financial, Inc Job Opportunities Introducing the Raymond James Career Development Program We are committed to nurturing talent through our comprehensive career development program designed to provide every employee—from interns to senior leaders—with the tools and training necessary for success. Whether you’re just starting out with an internship or you’re a seasoned professional, Raymond James offers career paths that align with your ambitions and skills. Do Innovative Work Join a company where innovation is part of the daily routine. At Raymond James Financial, Inc, you’ll engage with cutting-edge financial tools and resources that keep you ahead in the industry. Our commitment to technology and innovation ensures that we stay at the forefront of financial services. Be Part of a Great Team Experience a collaborative environment where teamwork and networking are encouraged. Our inclusive culture supports diversity and offers benefits that ensure the well-being of all team members. At Raymond James, you’re not just an employee; you’re part of a family that values your unique contributions and supports your professional journey. Future-Proof Your Career Advance your career with Raymond James, where opportunities for growth are abundant. Benefit from our industry-leading training programs and gain certifications that will elevate your professional standing. With a focus on career longevity and satisfaction, Raymond James ensures that your professional journey is as rewarding as it is successful. Explore Discover the various positions available at Raymond James Financial, Inc that match your skills and interests. We are continuously hiring across multiple disciplines, eager to welcome passionate, curious, and solution-driven team players. Stay Connected Join Our Team Search open positions at Raymond James Financial, Inc and find the perfect match for your career aspirations. Explore a range of opportunities from financial advising to corporate roles that align with your professional skills and goals. Keep Up to Date Stay informed with the latest career tips, insider perspectives, and industry-leading insights—all from the professionals who thrive at Raymond James. Job Alert Emails Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities waiting for you at Raymond James Financial, Inc. Join Raymond James Financial, Inc today and be part of a company that values innovation, leadership, and professional growth. Your future in the financial industry starts here.
Learn more about Raymond James Financial, Inc
Size
15,000 employees
Market Cap
$22.6 billion
Industry
Net Income
$862 million
5 Year Trend
+11.6%
Revenue
$8.3 billion
NASDAQ

Similar Jobs

More Jobs at Raymond James Financial, Inc

More Information Technology Jobs

Find similar Lead Vulnerability Research Engineer, IT Security jobs: