Full-Time

Lead Vulnerability Research Engineer

IT Security

Raymond James Financial

Raymond James Financial

Wealth management, banking, and investment services

No salary listed

No H1B Sponsorship

St. Petersburg, FL, USA

Hybrid

Three days in the office per week are required.

Bachelor's

Category
Cybersecurity (1)
Required Skills
PowerShell
Bash
Kubernetes
Microsoft Azure
Python
JavaScript
Git
Threat modeling
Machine Learning
Java
GraphQL
RAG
TypeScript
Vulnerability Analysis
C#
AWS
Go
JIRA
Cryptography
Jenkins
REST APIs
Penetration Testing
Data Analysis
Google Cloud Platform

Get referred to Raymond James Financial

See people who can refer or advise you

Requirements
  • Expertise identifying, validating, explaining, and remediating application and application programming interface vulnerabilities, including vulnerability classes represented in the Open Worldwide Application Security Project Top 10 and Open Worldwide Application Security Project API Security Top 10.
  • Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
  • Hands-on experience with static application security testing, dynamic application security testing, interactive application security testing, software composition analysis, application programming interface testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools.
  • Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript or TypeScript, Go, Java, C#, or shell; experience consuming Representational State Transfer and GraphQL application programming interfaces, processing structured data, writing tests, and maintaining production-quality code.
  • Experience integrating security tools with continuous integration and continuous delivery and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.
  • Experience applying artificial intelligence-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.
  • Ability to critically evaluate artificial intelligence output, recognize hallucinations and insecure recommendations, protect sensitive source code and data, design human-in-the-loop validation, and establish measurable quality and governance controls.
  • Knowledge of secure artificial intelligence-assisted development risks, including prompt injection, insecure output handling, excessive agency, sensitive information disclosure, model or dependency supply-chain concerns, and misuse of generated code.
  • Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, application programming interfaces, containers, serverless services, and Kubernetes.
  • Working knowledge of threat modeling, secure architecture principles, software supply-chain security, software bill of materials and vulnerability exploitability exchange concepts, artifact integrity, dependency governance, and provenance or attestation practices.
  • Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and translate findings into prioritized engineering actions.
  • Typically requires a bachelor's degree in computer science, software engineering, cybersecurity, information systems, artificial intelligence, data science, engineering, or a related field and five or more years of relevant experience.
  • Typically requires three or more years of hands-on experience in vulnerability research, vulnerability management engineering, offensive security, penetration testing, exploit validation, security tooling development, detection engineering, product security, application security, or a closely related discipline.
  • Hands-on experience using large language model platforms, including OpenAI GPT models and Anthropic Claude models, for security research, code and patch analysis, hypothesis generation, finding correlation, exploit-path reasoning, test development, technical writing, and remediation support.
  • Experience designing, building, and maintaining reusable artificial intelligence capabilities such as custom GPTs, agent skills, agents, subagents, prompt and context libraries, tool-enabled workflows, and multi-step analysis pipelines that encode repeatable vulnerability-research methods and produce consistent, auditable outputs.
  • Experience developing automated or agentic workflows using model application programming interfaces and orchestration frameworks, including OpenAI's Responses API and Agents SDK, Anthropic's API and agent tooling, function or tool calling, structured outputs, retrieval-augmented generation, Model Context Protocol integrations, and secure connections to enterprise data and systems.
  • Ability to translate analyst procedures into repeatable artificial intelligence-assisted workflows for vulnerability intake, advisory and patch analysis, exposure assessment, proof-of-concept review, affected-asset identification, threat-informed prioritization, remediation guidance, retesting, reporting, and knowledge capture.
  • Practical experience evaluating multiple models and selecting fit-for-purpose approaches based on reasoning quality, coding performance, context requirements, latency, cost, privacy, data residency, and security constraints.
  • Experience developing security automation and integrating vulnerability data, artificial intelligence-assisted analysis, and security controls with continuous integration and continuous delivery platforms, source-control systems, scanners, asset inventories, cloud services, ticketing platforms, threat-intelligence sources, and security data platforms.
  • Experience implementing artificial intelligence safety and governance controls, including prompt-injection defenses, input and output validation, least-privilege tool access, sandboxing, human approval gates, sensitive-data handling, secrets protection, logging, traceability, reproducibility, model and dependency risk management, and prevention of unauthorized or disruptive actions.
  • Evidence of testing and measuring artificial intelligence-assisted security workflows using representative evaluation sets and operational metrics such as precision, recall, false-positive and false-negative rates, consistency, analyst time saved, research-to-detection time, remediation quality, and reduction in time to protective action.
  • Ability to review model-generated code, queries, tests, detections, and remediation recommendations for hallucinations, unsafe assumptions, insecure code, weak evidence, and operational risk before outputs are promoted into production or used to drive consequential decisions.
Responsibilities
  • Lead threat-focused vulnerability research across enterprise applications, application programming interfaces, operating systems, network devices, cloud services, containers, open-source components, commercial products, and emerging artificial intelligence-enabled technologies.
  • Analyze threat intelligence, vendor advisories, public exploit research, malware and campaign reporting, security-research disclosures, and internal telemetry to identify vulnerabilities with credible relevance to the enterprise.
  • Perform authorized, controlled technical research to validate vulnerability conditions, affected versions, attack prerequisites, exploitability, reachability, likely impact, and available mitigations without creating unnecessary operational risk.
  • Reproduce vulnerabilities in isolated lab environments; analyze patches, source code, binaries, configurations, protocols, and proof-of-concept artifacts; and create defensible evidence distinguishing theoretical exposure from actionable risk.
  • Develop safe detection and validation content such as authenticated checks, queries, signatures, scripts, test harnesses, configuration assessments, and exposure analytics; ensure artifacts are reviewed, version-controlled, documented, and designed to avoid disruption.
  • Build production-quality automation and integrations that ingest, normalize, enrich, correlate, deduplicate, prioritize, ticket, route, retest, and close vulnerability findings across scanners, asset inventories, threat-intelligence sources, software inventories, cloud platforms, endpoint tools, and engineering systems.
  • Create threat-informed prioritization models incorporating active exploitation, adversary behavior, exploit maturity, internet exposure, asset criticality, application context, business service dependency, reachability, compensating controls, data sensitivity, and remediation feasibility.
  • Use artificial intelligence-assisted research capabilities to summarize technical evidence, identify likely vulnerable code paths, compare patches, generate and refine test hypotheses, correlate findings, propose validation steps, and draft remediation guidance.
  • Evaluate and govern artificial intelligence-assisted security workflows for accuracy, hallucination, prompt injection, insecure output, sensitive-data exposure, excessive agency, model and dependency supply-chain risk, reproducibility, auditability, and appropriate human oversight.
  • Design human-in-the-loop controls and benchmark artificial intelligence-assisted workflows using measurable outcomes, including precision, recall, false-positive and false-negative rates, analyst time saved, validation quality, remediation quality, and reduction in time to protective action.
  • Provide rapid technical analysis for high-risk and actively exploited vulnerabilities, including impact assessments, affected-asset logic, interim mitigations, detection opportunities, validation procedures, and executive-ready risk communication.
  • Conduct root-cause and recurring-pattern analysis to identify systemic weaknesses in technology selection, configuration, software dependencies, asset visibility, patch processes, or control coverage, and recommend durable preventive improvements.
  • Partner with remediation owners to explain technical risk, validate fixes and compensating controls, resolve disputed findings, and support risk-based decisions while maintaining clear evidence and accountability.
  • Define and report program metrics such as research-to-detection time, time to enterprise impact assessment, vulnerable-asset identification coverage, validation accuracy, remediation aging, recurrence, automation effectiveness, and measurable risk reduction.
  • Mentor engineers and analysts, establish research standards and playbooks, contribute to technical strategy and roadmaps, and serve as an escalation point for complex vulnerability questions and significant cybersecurity incidents.
Desired Qualifications
  • Offensive Security Certified Professional, Offensive Security Experienced Penetration Tester, Offensive Security Web Expert, or comparable advanced offensive-security credential.
  • GIAC Exploit Researcher and Advanced Penetration Tester, GIAC Penetration Tester, GIAC Web Application Penetration Tester, or comparable vulnerability-research or assessment certification.
  • Relevant cloud, Kubernetes, secure software, reverse-engineering, incident-response, or DevSecOps certification aligned with the assigned environment.
Raymond James Financial

Raymond James Financial

View

Diversified financial services provider serving individuals, corporations, and municipalities. Its services span five segments: Private Client Group, Capital Markets, Asset Management, RJ Bank, and Other, including financial planning, investment advisory, investment banking, research, asset management, and banking and lending. The approach centers on personalized, client-centric service and long-term relationships, with advisors tailoring strategies to each client. The goal is to help clients achieve financial objectives through customized guidance and a broad range of financial solutions.

Company Size

N/A

Company Stage

IPO

Headquarters

Saint Petersburg, Florida

Founded

1962

Get referred to Raymond James Financial

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q3 2026 revenue hit $3.93 billion, with record client assets of $1.92 trillion.
  • Independent Bank's $645 million program joins Raymond James on September 18, 2026.
  • Advisor recruiting stayed strong: 2026 added $56 billion in prior-firm client assets.

What critics are saying

  • Cash-sweep litigation raised professional fees $27 million in Q3 2026, and defense costs continue.
  • FINRA fined Raymond James $125,000 in August 2026 for fractional-share reporting failures.
  • Advisor departures to LPL and Morgan Stanley pressure retention; recruiting misses would hit growth.

What makes Raymond James Financial unique

  • Raymond James' advisor-owned culture kept recruiting teams like Baird's $5.4 billion group in August 2026.
  • Clark Capital closed in 2026, adding $36 billion and broadening wealth-management products.
  • Rai, its proprietary AI assistant, rolled out enterprise-wide after the July 2026 pilot.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Professional Development Budget

Company News

Yahoo Finance
Sep 2nd, 2026
Raymond James picks 2 beaten-down stocks with 40%+ upside potential for rest of 2026

Raymond James has highlighted SBA Communications and Somnigroup International as top stock picks for the remainder of 2026, despite both experiencing significant declines this year. SBA Communications, a real estate investment trust owning cellular towers across the Americas and Africa, has been volatile due to slowed carrier network buildouts. The company reported Q2 revenue of $715.3 million, up 2% year-over-year. Analyst Ric Prentiss assigned a Strong Buy rating with a $264 price target, suggesting 41% upside from current levels near $191. Somnigroup International, the world's largest bedding maker with brands including Tempur-Pedic and Sealy, has dropped 30% this year amid integration challenges following its $5 billion Mattress Firm acquisition. Q2 revenue reached $1.82 billion. Analyst Bobby Griffin rates it Strong Buy with a $90 target, implying 44% upside. Both picks represent recovery bets on companies Raymond James believes offer attractive value after market punishment.

FA Magazine
Sep 2nd, 2026
Michigan Bank selects Raymond James for $645M wealth program.

Michigan Bank selects Raymond James for $645M wealth program. September 2, 2026 - FA Staff Raymond James today announced that it's adding a team of eight advisors and three branch professionals who manage about $645 million in client assets to its division partnering with banks and credit unions. Independent Bank, a Michigan-based holding company with total assets of about $5.6 billion, has selected Raymond James's Financial Institutions Division to handle its financial planning and advisory program, IB Wealth Management, according to a Raymond James press release. IB Wealth, based in Grand Rapids, will provide its clients with investment and wealth management services through Raymond James Financial Services. The program was previously affiliated with Cetera Investment Services. It will formally affiliate with Raymond James on September 18th. "We're pleased to welcome the team... and equip its advisors with the breadth of resources, technology and investment capabilities available through Raymond James," said Jon DeMayo, vice president of business development at the Financial Institutions Division, in a statement. "Together, these capabilities will help the team deliver comprehensive advice and address the increasingly complex needs of its clients." Gavin A. Mohr, chief financial officer of Independent Bank, added that the expanded investment platform and comprehensive wealth management resources "will help us serve individuals and families across a broad range of financial goals, including the complex planning requirements of high-net-worth clients, while preserving the personal service and trusted relationships our clients expect."

Family Wealth Report
Aug 31st, 2026
Who's moving where in wealth management? - Raymond James.

Who's moving where in wealth management? - Raymond James. Editorial Staff August 31, 2026 The latest senior wealth management industry moves, appointments and personnel changes in North America. Raymond James Raymond James has welcomed financial advisor David Lazorik to its independent advisor channel. Operating as Lazorik Financial Management in Yakima, Washington, Lazorik has joined from Wells Fargo where he managed more than $160 million in client assets. He specializes in serving business owners, foundations, endowments, nonprofits and retirees. Lazorik brings 35 years of experience in the financial services industry to his role as branch manager.

GlobeNewswire
Aug 26th, 2026
Kashable names Dar Miranda VP of go-to-market as employer demand for financial wellness grows.

Kashable names Dar Miranda VP of go-to-market as employer demand for financial wellness grows. Leader brings HR and product expertise to scale Kashable's reach and impact. 26. August 2026 07:00 ET | Quelle: Kashable NEW YORK, Aug. 26, 2026 (GLOBE NEWSWIRE) - Kashable, a mission-driven fintech platform Redefining Credit for Working Americans(TM), today announced that Darlene "Dar" Miranda has joined the organization as Vice President, Go-to-Market. The newly created role reflects Kashable's momentum as more employers are adding financial wellness to their benefits offerings. Miranda will be responsible for leading Kashable's market strategy, expanding employer and partner adoption, and translating customer and market requirements into product deliverables. Access to low-cost loan support can avert 401(k) depletion, reliance on high-interest rate credit cards, and predatory lenders. When employees face unexpected expenses such as car repairs or high-deductible healthcare costs, the corresponding anxiety and disruption can impact engagement, absenteeism, and even turnover rates. Recent research conducted by SHRM, in conjunction with Raymond James, found that 73 percent of U.S. workers reported experiencing stress related to their financial security. The same report uncovered that most employers' financial wellness programs are underdeveloped, illuminating the gap between what's needed and what's currently in place. Miranda will lead Kashable's go-to-market strategy to help employers close these gaps as they continue to add financial wellness benefits to ensure employee engagement and retention. Miranda commented, "Financial wellness benefits aren't optional. They constitute an integral part of organizational and community resilience, yet many organizations are just starting their journey into this area. By listening closely to the needs of their employees, Kashable is already demonstrating how effective it can be to provide access to financial coaching, credit monitoring, learning resources, and low-cost loans across all worker types. I'm excited to join the company at this pivotal time as fintech and HR converge." Einat Steklov, co-founder and co-CEO of Kashable, said, "Dar brings deep industry expertise and a proven ability to scale financial wellness solutions that build stronger workplaces. Kashable is redefining credit for working Americans through financial wellness benefits with a unique combination of low-cost loans, financial coaching, credit monitoring and other services. As we continue to grow our market position, Dar's leadership will be invaluable." Miranda joins Kashable from DailyPay, an earned wage access provider, where she held vice president positions in customer growth and engagement as well as product management. Earlier in her career, she was vice president, Product Management at Sterling and vice president, Product and User Experience at CommonBond. She also held management roles at American Express in consumer credit and B2B payments. A member of HR.com's Future of Payroll Advisory Board, Miranda holds an MBA in Marketing and Finance from NYU Stern School of Business. She is based in Kashable's New York City headquarters. About Kashable Kashable is a financial technology company that provides access to Socially Responsible Credit(R) and financial wellness solutions for employees, offered as a voluntary benefit. Kashable's platform is available to over 4 million employees across hundreds of large employers nationwide. Founded in 2013, Kashable leverages innovative technology to improve the financial well-being of working Americans with a commitment to both reliability and affordability. Kashable offers a fast, responsible alternative for employees who may otherwise turn to borrowing from retirement plans, high-interest credit cards, or other high-cost options to bridge short-term gaps in their finances, creating a path to greater financial security. For more information, visit Kashable.com.

Yahoo Finance
Aug 25th, 2026
Raymond James shares lag S&P 500 despite analyst optimism and strong earnings growth

Raymond James Financial shares have lagged the broader market over the past year, rising 6.9% compared to the S&P 500's 18.3% gain. However, the Saint Petersburg-based financial services firm has outperformed in 2026, up 10% year-to-date versus the S&P's 11.8%. The company faces headwinds from net interest margin compression as central banks cut rates, reducing earnings from sweep cash accounts. Migration of financial advisors to independent channels with higher payout structures has also pressured margins. Raymond James reported third-quarter revenue of $3.9 billion, up 15.6% year-over-year, with adjusted earnings per share of $3.14, up 44%. Analysts expect full-year EPS growth of 13.2% to $12.07. The company has beaten consensus estimates in each of the past four quarters.