Jobs · Information Technology · Georgia

Vulnerability Analyst

The Coca-Cola Company · Atlanta, GA · Yesterday
Information TechnologyFull-time

About the role

The Vulnerability Analyst is responsible for reviewing, validating, and coordinating the resolution of security vulnerabilities across The Coca-Cola Company’s systems and digital assets. The role supports the company’s Vulnerability Disclosure Program (VDP), Bug Bounty Program (BBP), and Attack Surface Management (ASM) operations — assessing incoming reports, confirming they are valid and in scope, assigning the right owners, and tracking each issue through to a verified fix. Working closely with researchers, asset owners, and remediation teams, the Vulnerability Analyst helps ensure vulnerabilities are prioritized, addressed within established SLAs, and resolved effectively.

Responsibilities

  • Review and validate incoming vulnerability reports across the VDP, BBP, and ASM programs, confirming scope and severity.
  • Coordinate remediation with asset owners and internal teams, and verify that fixes are effective before closing each report.
  • Track and prioritize vulnerabilities to ensure they are resolved within established SLAs.
  • Serve as the primary point of contact for external security researchers throughout the disclosure and resolution process.
  • Maintain accurate vulnerability records and reporting in the team’s tracking platforms.

Qualifications

  • 2+ years in vulnerability management, application security, SOC, or a related security operations role.
  • Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10) and the ability to read and reproduce a proof-of-concept.
  • Demonstrated ability to validate findings, judge scope, and assess severity accurately.
  • Familiarity with vulnerability tracking/disclosure platforms and ticketing workflows.
  • Strong written communication — able to correspond with external researchers and internal owners clearly and diplomatically.

Preferred qualifications

  • Experience running or supporting a VDP, bug bounty program, or ASM function.
  • Hands-on experience with platforms such as Intigriti, HackerOne, Bugcrowd, or an ASM vendor.
  • Understanding of enterprise remediation and risk-exception governance processes.

Pay

United States: $107,000 – $125,700 USD base pay (may vary by geography, job-related knowledge, skills, and experience). Annual incentive reference value: 7.5%.

Schedule

Location: United States of America (Atlanta). Travel required: 0% – 25%. Relocation provided: No.

Similar jobs

Vulnerability Analyst

Boston Government Services, LLC (BGS)Knoxville Metropolitan Area· 3 days ago
Business Developmentapply on workforcenow.adp.com

Vulnerability Analyst

Edgewater Federal Solutions, Inc.Bethesda, MD· 3 wk ago
Business Development$70k–$90k/yrapply on careers-edgewaterit.icims.com

Vulnerability Analyst

Y-12 National Security ComplexOak Ridge, TN· 1 mo ago
Salesapply on career-hcm03.ns2cloud.com