Coca-Cola

Vulnerability Analyst

Coca-Cola$107K — $125K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years in vulnerability management, application security, SOC, or a related security operations role.
  • Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10).
  • Ability to read and reproduce a proof-of-concept for vulnerabilities.
  • Demonstrated ability to validate findings and assess severity accurately.
  • Familiarity with vulnerability tracking platforms and ticketing workflows.
  • Strong written communication skills for interaction with external researchers.

Responsibilities

  • Review and validate incoming vulnerability reports across VDP, BBP, and ASM programs.
  • Coordinate remediation efforts with asset owners and verify fixes before closing each report.
  • Track and prioritize vulnerabilities to ensure timely resolution within established SLAs.
  • Serve as the primary contact for external security researchers during the disclosure and resolution process.
  • Maintain accurate records and reporting of vulnerabilities in tracking platforms.

Benefits

  • Health benefits including medical and dental coverage.
  • Retirement savings options.
  • Paid time off for vacation and holidays.
  • Opportunities for professional development and training.
  • Flexible work schedule options.
Full Job Description
Job Description Summary:

Position Overview:

The Vulnerability Analyst is responsible for reviewing, validating, and coordinating the resolution of security vulnerabilities across The Coca-Cola Company's systems and digital assets. The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid and in scope, assigning the right owners, and tracking each issue through to a verified fix. Working closely with researchers, asset owners, and remediation teams, the Vulnerability Analyst helps ensure vulnerabilities are prioritized, addressed within established SLAs, and resolved effectively.

Function Related Activities/Key Responsibilities:

  • Review and validate incoming vulnerability reports across the VDP, BBP, and ASM programs, confirming scope and severity.
  • Coordinate remediation with asset owners and internal teams, and verify that fixes are effective before closing each report.
  • Track and prioritize vulnerabilities to ensure they are resolved within established SLAs.
  • Serve as the primary point of contact for external security researchers throughout the disclosure and resolution process.
  • Maintain accurate vulnerability records and reporting in the team's tracking platforms.


Qualifications & Experience requirements:

  • 2+ years in vulnerability management, application security, SOC, or a related security operations role.
  • Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10) and the ability to read and reproduce a proof-of-concept.
  • Demonstrated ability to validate findings, judge scope, and assess severity accurately.
  • Familiarity with vulnerability tracking / disclosure platforms and ticketing workflows.
  • Strong written communication - able to correspond with external researchers and internal owners clearly and diplomatically.
  • Preferred experience - experience running or supporting a VDP, bug bounty program or ASM function; hands-on experience with platforms such as Intigriti, HackerOne, Bugcrowd or an ASM vendor; understanding of enterprise remediation and risk-exception governance process.


The Coca-Cola Company will not offer sponsorship for employment status (including, but not limited to, H1-B visa status and other employment-based nonimmigrant visas) for this position. Accordingly, all applicants must be currently authorized to work in the United States on a full-time basis and must not require The Coca-Cola Company's sponsorship to continue to work legally in the United States.

Skills:
Attack Surface Analysis, Information Security, Security Vulnerability Assessments, Vulnerability Management, Vulnerability Remediation, Vulnerability Scanning

Pay Range:
United States: 107,000 - 125,700 USD

Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.

Annual Incentive Reference Value Percentage:
7.5

Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.

Location(s):
United States of America

City/Cities:
Atlanta

Travel Required:
00% - 25%

Relocation Provided:
No

Job Posting End Date:
September 4, 2026

Similar Jobs

More Jobs at Coca-Cola

More Information Technology Jobs

Find similar Vulnerability Analyst jobs: