Vulnerability Analyst
0801 the coca-cola
📍 us - georgia - atlanta united states🕐 12d ago🔗 workday
Job Description
**Job Description Summary:**
**Position Overview:**
The Vulnerability Analyst is responsible for reviewing, validating, and coordinating the resolution of security vulnerabilities across The Coca-Cola Company's systems and digital assets. The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations — assessing incoming reports, confirming they are valid and in scope, assigning the right owners, and tracking each issue through to a verified fix. Working closely with researchers, asset owners, and remediation teams, the Vulnerability Analyst helps ensure vulnerabilities are prioritized, addressed within established SLAs, and resolved effectively.
**Function Related Activities/Key Responsibilities:**
* Review and validate incoming vulnerability reports across the VDP, BBP, and ASM programs, confirming scope and severity.
* Coordinate remediation with asset owners and internal teams, and verify that fixes are effective before closing each report.
* Track and prioritize vulnerabilities to ensure they are resolved within established SLAs.
* Serve as the primary point of contact for external security researchers throughout the disclosure and resolution process.
* Maintain accurate vulnerability records and reporting in the team's tracking platforms.
**Qualifications & Experience requirements:**
* 2+ years in vulnerability management, application security, SOC, or a related security operations role.
* Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10) and the ability to read and reproduce a proof-of-concept.
* Demonstrated ability to validate findings, judge scope, and assess severity accurately.
* Familiarity with vulnerability tracking / disclosure platforms and ticketing workflows.
* Strong written communication — able to correspond with external researchers and internal owners clearly and diplomatically.
* Preferred experience - experience running or supporting a VDP, bug bounty program or ASM function; hands-on experience with platforms such as Intigriti, HackerOne, Bugcrowd or an ASM vendor; understanding of enterprise remediation and risk-exception governance process.
The Coca-Cola Company will not offer sponsorship for employment status (including, but not limited to, H1-B visa status and other employment-based nonimmigrant visas) for this position. Accordingly, all applicants must be currently authorized to work in the United States on a full-time basis and must not require The Coca-Cola Company's sponsorship to continue to work legally in the United States.
**Skills:**
Attack Surface Analysis, Information Security, Security Vulnerability Assessments, Vulnerability Management, Vulnerability Remediation, Vulnerability Scanning
**Pay Range:**
United States: 107,000 - 125,700 USD
_Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered._
**Annual Incentive Reference Value Percentage:**
7.5
_Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target._
**Location(s):**
United States of America
**City/Cities:**
Atlanta
**Travel Required:**
00% - 25%
**Relocation Provided:**
No
**Job Posting End Date:**
September 4, 2026
**Our Purpose and Growth Culture:**
We are taking deliberate action to nurture an inclusive culture that is grounded in our company purpose, to refresh the world and make a difference. We act with a growth mindset, take an expansive approach to what’s possible and believe in continuous learning to improve our business and ourselves. We focus on four key behaviors – curious, empowered, inclusive and agile – and value how we work as much as what we achieve. We believe that our culture is one of the reasons our company continues to thrive after 130+ years. Visit [Our Purpose and Vision](https://www.coca-colacompany.com/company/purpose-and-vision) to learn more about these behaviors and how you can bring them to life in your next role at Coca-Cola.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. When we collect your personal information as part of a job application or offer of employment, we do so in accordance with industry standards and best practices and in compliance with applicable privacy laws.