Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Atlanta, GA, United States
Posted
Yesterday
OWASP
Job Description
Position Overview:
The Vulnerability Analyst is responsible for reviewing, validating, and coordinating the resolution of security vulnerabilities across The Coca-Cola Company's systems and digital assets. The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid and in scope, assigning the right owners, and tracking each issue through to a verified fix. Working closely with researchers, asset owners, and remediation teams, the Vulnerability Analyst helps ensure vulnerabilities are prioritized, addressed within established SLAs, and resolved effectively.
Function Related Activities/Key Responsibilities:
Qualifications & Experience requirements:
The Vulnerability Analyst is responsible for reviewing, validating, and coordinating the resolution of security vulnerabilities across The Coca-Cola Company's systems and digital assets. The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid and in scope, assigning the right owners, and tracking each issue through to a verified fix. Working closely with researchers, asset owners, and remediation teams, the Vulnerability Analyst helps ensure vulnerabilities are prioritized, addressed within established SLAs, and resolved effectively.
Function Related Activities/Key Responsibilities:
- Review and validate incoming vulnerability reports across the VDP, BBP, and ASM programs, confirming scope and severity.
- Coordinate remediation with asset owners and internal teams, and verify that fixes are effective before closing each report.
- Track and prioritize vulnerabilities to ensure they are resolved within established SLAs.
- Serve as the primary point of contact for external security researchers throughout the disclosure and resolution process.
- Maintain accurate vulnerability records and reporting in the team's tracking platforms.
Qualifications & Experience requirements:
- 2+ years in vulnerability management, application security, SOC, or a related security operations role.
- Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10) and the ability to read and reproduce a proof-of-concept.
- Demonstrated ability to validate findings, judge scope, and assess severity accurately.
- Familiarity with vulnerability tracking / disclosure platforms and ticketing workflows.
- Strong written communication - able to correspond with external researchers and internal owners clearly and diplomatically.
- Preferred experience - experience running or supporting a VDP, bug bounty program or ASM function; hands-on experience with platforms such as Intigriti, HackerOne, Bugcrowd or an ASM vendor; understanding of enterprise remediation and risk-exception governance process.
Similar jobs
- CS
CYBERSECURITY ENGINEER
NewComTec Solutions LLC
Rochester, New York🇺🇸Hybrid34 minutes agoMicrosoft OfficeVMwareTechnology - NO
Information Security Specialist III (Log Analyzer)
NewNa Oiwi Kane
Fort Hood, TX🇺🇸$64.7k - $69.3k/yrHybridYesterdayAdministrative - MR
Physical security/surveillance device engineer
NewMotion Recruitment Partners, LLC
Charlotte, NC🇺🇸HybridYesterdayAdministrative - NO
Information Security Specialist II
NewNa Oiwi Kane
Fort Hood, TX🇺🇸$55.8k - $59.8k/yrHybridYesterdayAdministrative - FP
Security Technician
NewFiretrol Protection Systems
Mobile, Alabama🇺🇸On-site13 hours agoUnityAdministrative - IS
Staff Security Researcher
NewInvicti Security
Austin, Texas🇺🇸Hybrid15 hours agoOWASPGraphQLHTTP+6