Principal Vulnerability Analyst

Mastercard

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
O Fallon
Salary
$152,000–$258,000 / yr
Posted
28 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $160k
This role $205k
$112k most similar roles pay here $274k

This role pays more than 87% of similar roles. Most pay $134,000–$185,500 — the shaded band above. At the midpoint, this role pays about $205k versus about $160k for comparable roles.

Based on 240 similar postings.

Employer

About Mastercard

Mastercard is a global technology company in the payments industry, processing transactions between financial institutions and merchants using its extensive network of credit, debit, and prepaid card products. Industry: Payments Technology & Financial Services

Mastercard currently has 116 open roles on FindRole.

Listed pay typically runs $122,000–$207,000 across 104 roles with salary data.

Most-posted roles

View all roles at Mastercard

At a glance

TL;DR · Principal Vulnerability Analyst

Principle, Vulnerability Analyst joins the AI Vulnerability Operations team to transform AI-identified security findings into validated, prioritized, and remediated risk reductions across the software environment. This role involves validating vulnerabilities by reviewing code context, dependency data, application architecture, and runtime exposure to determine if AI-generated findings are exploitable or material. The analyst will partner with engineering and product teams to provide actionable remediation guidance, triage results to eliminate false positives, and verify outcomes through code changes and retest results. Key responsibilities include creating playbooks, mentoring others, and providing feedback to improve AI model precision. Required expertise includes vulnerability management, application security, OWASP, CWE, CVSS, threat modeling, and source code review. The role addresses the challenge of integrating AI-assisted security workflows into large enterprise environments to streamline remediation for high-risk applications.

What you'll do

  • Validate AI-generated vulnerabilities by analyzing code context, architecture, reachability, and exploitability evidence.
  • Triage findings to distinguish true positives from false positives and determine appropriate risk levels.
  • Translate complex AI model outputs into clear, actionable remediation guidance for engineering teams.
  • Partner with product and engineering teams to drive high-risk vulnerabilities through the full remediation lifecycle.
  • Verify that code changes and configuration updates successfully resolve identified security issues.
  • Provide feedback to data and platform teams to improve AI model precision and reduce false positives.
  • Create playbooks, decision trees, and standard operating procedures to scale AI vulnerability operations.
  • Prepare executive-ready reports and risk narratives regarding remediation progress and residual risks.

What we're looking for

  • Strong experience in vulnerability management, application security, secure software development, or security engineering.
  • Deep understanding of common vulnerability classes, secure coding practices, OWASP, CWE, CVSS, exploitability analysis, threat modeling, and risk-based prioritization.
  • Experience reviewing source code, dependency manifests, SCA results, static analysis findings, container findings, and application architecture.
  • Ability to communicate complex technical details clearly to developers, product owners, security leaders, and non-technical stakeholders.
  • Strong written documentation skills for producing validation notes, remediation guidance, risk narratives, and operational playbooks.
  • Experience with vulnerability tracking, remediation workflows, exception handling, risk acceptance, retesting, and closure evidence.
  • Familiarity with AI-assisted security workflows to validate, enrich, and prioritize model-generated findings.
  • Strong leadership qualities including mentoring, influencing without authority, and creating repeatable processes in a large enterprise environment.

More like this

Similar roles

Principal AI Security Engineer

Mastercard

O Fallon, IL 2 days ago $170,000$281,000
AI Security Machine Learning Adversarial Machine Learning Security Architecture Threat Modeling Penetration Testing Cloud Security Data Protection OWASP MITRE NIST ISO Secure Software Engineering Risk Management

Vice President, AI Vulnerability Operations

Mastercard

O Fallon, IL 17 days ago $212,000$339,000
AI Machine Learning Vulnerability Management Application Security Cloud Security infrastructure-as-code Incident Response Automation CVSS EPSS KEV OWASP MITRE ATT&CK NIST Software Supply-Chain Security
10+ yrs exp

Senior Vulnerability Management Engineer

SoFi

Seattle, WA +1 7 days ago $124,800$234,000
Vulnerability Management Kubernetes Python Go Java Bash SCA SAST DAST CI/CD Qualys Helm Maven Gradle Webhooks OWASP CVE CVSS CWE
4+ yrs exp

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 53 days ago $125,000$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp

Lead Platform Architect

Mastercard

O Fallon, MO 17 days ago $122,000$207,000
AWS Azure Kubernetes Claude Code Amazon Bedrock hybrid-cloud Multi-region Architecture Service-Oriented Architecture Middleware Distributed Systems Microsoft Visio Security Frameworks

Software Engineer II

Mastercard

O Fallon, IL 7 days ago $92,000$147,000
Java Spring Boot REST APIs Angular Node.js Kubernetes AWS Azure PCF CI/CD DevOps Distributed Systems Integration Testing Observability Software Architecture Security Best Practices AI-assisted Development Tools
3+ yrs exp