
Sr. Cybersecurity Analyst
Visa
Job description
About Us **Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.
At Visa, you'll have the opportunity to create impact at scale โ tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world.
Join Visa and do work that matters โ to you, to your community, and to the world. Progress starts with you.
Job Description**
Cybersecurity is at the beating heart of our culture. Our diligence and expertise are what make us the undisputed leader in electronic payments. We've made it our priority to create a top-tier Cyber Engineering & Operations team, poised to defend us against any potential cyber threats. We're looking for those of you who are inherently driven and fascinated by the art and science of Cybersecurity. We'll arm you with the very best tools and tech so that you can deliver top notch results.
We are seeking a Senior Cybersecurity Analyst with a strong development background to join our cybersecurity team. In this role, you will lead the identification, prioritization, and remediation of vulnerabilities across our cloud-native infrastructure, containerized workloads, and application environments. You will combine deep engineering expertise with security leadership to architect scalable automation, expand scanning coverage, mentor junior team members, and partner with engineering teams and senior stakeholders to drive risk reduction at scale.
Essential Functions:
-
Be a vulnerability management champion by leading the discovery, assessment, prioritization, and remediation of vulnerabilities across cloud, container, and host infrastructure at Visa.
-
Own the end-to-end lifecycle management of security scanning, including deployment, configuration, coverage expansion, policy tuning, upgrades, and ongoing optimization to ensure accurate and complete scanning across all environments.
-
Lead and facilitate vulnerability assessments, scan result analysis, and finding validation throughout the development and deployment lifecycle; eliminate false positives and provide clear, actionable remediation guidance to development and platform teams.
-
Architect the integration of vulnerability scanning into CI/CD pipelines in conjunction with engineering teams to enable shift-left security, establishing security gates, image policies, and automated checks that prevent vulnerable images from reaching production.
-
You'll be working on securing and assessing various platforms and technologies which protect Visa's environments from vulnerabilities and attacks like:
-
Cloud platforms like AWS, Azure, GCP, including cloud-native services, IAM, and CSPM practices
-
Container and orchestration technologies like Docker, Kubernetes, container registries, admission controllers, and runtime security
-
Vulnerability management tools like Qualys, Prisma Cloud, Tenable, Rapid7, Wiz, Trivy, Grype
-
CI/CD and DevOps tooling like Jenkins, GitHub Actions, GitLab CI, Artifactory
-
Programming and automation languages like Python, Bash, Go, and REST API integrations
-
AI/ML and LLM-based tools like AI coding assistants, automated triage engines, and security copilots
-
Threat and exploitability intelligence sources like EPSS, CISA KEV, CVE/CVSS, vendor advisories
-
Automate security tools and processes ensuring innovation and advancement strategies that keep pace in the areas of vulnerability triage, enrichment, ticketing, remediation orchestration, and metrics/reporting.
-
Apply risk-based prioritization leveraging threat intelligence, exploitability data, and asset criticality to provide recommended countermeasures or mitigating controls that reduce risk to an acceptable and manageable level.
-
Track and report on vulnerability metrics, SLAs, and remediation trends for engineering leadership, security management, and compliance stakeholders.
-
Mentor and provide technical guidance to junior security engineers and analysts across the team.
-
Help business and product teams achieve and maintain various compliance certifications like PCI DSS, SOC 2, ISO 27001, etc.
Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager.
Qualifications
Basic Qualifications:
- 5+ years of relevant work experience with a Bachelorโs degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD OR 8+ years of relevant work experience.
Preferred Qualifications:
-
6 or more years of work experience with a Bachelor's Degree or 4 or more years of work experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 3 years of relevant work experience with a PhD.
-
Have significant hands-on experience in vulnerability management, application security, or a related security engineering role, with a strong development background.
-
Have strong proficiency in Python for scripting, automation, and API integrations to streamline and scale security workflows.
-
Have deep experience with containers (Docker or similar), including image scanning, hardening, and registry security.
-
Strong working knowledge of Kubernetes, including architecture, workloads, security configurations, RBAC, and common misconfigurations.
-
Extensive experience securing and assessing cloud environments (AWS, Azure, or GCP), including cloud-native services and Identity and Access Management concepts.
-
A proven record of accomplishment operating and managing vulnerability scanning and management tools such as Prisma Cloud, Qualys, Tenable, Rapid7, Wiz, Trivy, Grype, etc., including tool lifecycle ownership.
-
Strong understanding of CVE/CVSS scoring, exploitability analysis, and risk-based prioritization.
-
Experience with CI/CD tooling (e.g. Jenkins, GitHub Actions, GitLab CI) and integrating security scanning into pipelines to drive shift-left practices across engineering teams.
-
Have experience applying AI/ML or LLM-based tools to security workflows, such as automated vulnerability triage, false-positive reduction, or remediation recommendations, and familiarity with securing AI/ML systems (e.g. OWASP Top 10 for LLMs).
-
Relevant certifications such as CKS, CKA, AWS/Azure/GCP security certifications, OSCP, GCSA, or CISSP.
-
Experience working in the payments industry or other regulated environments such as financial services, healthcare, or government.
-
Strong communication and stakeholder management skills, with the ability to explain technical risk to engineers, leadership, and non-technical audiences, and experience mentoring or guiding junior team members.
Visa is an EEO Employer
Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.