Vulnerability Analyst — External Attack Surface & VDP

Vanguard Malvern, PA

Company

Vanguard

Location

Malvern, PA

Type

Full Time

Job Description

We’re seeking a hands-on Vulnerability Analyst to validate, analyze, and prioritize vulnerabilities discovered across our External Attack Surface Management (EASM) platform and Vulnerability Disclosure Program (VDP). You’ll combine deep vulnerability analysis with adversarial testing skills to reproduce and triage issues, ensure accurate severity and ownership, and drive timely remediation with partner teams. The ideal candidate has strong diagnostic instincts, excellent written evidence construction, and practical penetration testing experience. *This Hybrid Role (in office Tues-Wed-Thurs) can be based in either Charlotte, NC, Dallas, TX, or Malvern, PA (HQ)** Whatyou’lldo • Validate & reproduce findingsfrom EASM (internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to confirm exploitability and business impact. • Right-sizeseverity & priorityusing exploitability signals (e.g., public exploit, EPSS/KEV), control context, asset criticality, and exposure window; document rationale and evidence that developers and risk owners can act on. • Deduplicate, enrich & routefindings to the correct owners; eliminate false positives; merge related signal (scanner output, logs, asset inventory, prior exceptions) and ensure single threaded tracking to closure. • Partner withsecure business enablement& productteamsto negotiate remediation paths and SLAs; propose compensating controls or layered fixes when “one-shot” remediation isn’t feasible. • Partner ongovernance workflowsfor risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in our dashboards. • Close the loop with researchers(for VDP) through clear, respectful communications and crisp proof-of-fix retesting. • Continuously improve signal qualityby tuning rules/policies, source inventories, and intake/playbooks; author repeatable runbooks for common vuln classes. • Contribute as an adversarywhen needed (mini-engagements) to validate edge case chains and confirm impact beyond tool output. Whatyou’llbring • 3–5yearsin vulnerability analysis, application/infrastructure security, red teaming, or penetration testing (internal or consulting). • Proven ability tovalidatecomplex issues(param tampering, authN/Z bypass, SSRF, injection, IDOR, misconfig, cloud/API exposures) and write concise, repeatable steps with screenshots/PoCs. • Experience withEASM(e.g., Censys, Defender EASM, Cortex Xpanse) andVDP/bug bountyplatforms (e.g., HackerOne, Bugcrowd) and their triage mechanics. • Familiarity withenterprise VM & tracking(ServiceNow VR/IRM, Jira, Archer/Risk Register), and with platform scanners (Qualys/Tenable/Nessus/Burp/ZAP). • Working knowledge ofcloud(AWS/Azure),web & APIsecurity, PKI/TLS hygiene, DNS, and internet exposed service hardening. • Scripting(Python/PowerShell/Bash) for repeatable validation and data wrangling; basic SQL helpful. • Exceptional written communication—capable of translating technical risk intoactionable guidanceand executive clarity. Nice-to-have exposure • EPSS/KEV driven prioritization, attack path/graph concepts, and risk quant inputs. • Cloud posture and SaaS posture signals (SSPM) that intersect with external exposure. • Building tuning logic for scanners and platform rules (e.g., policy libraries, discovery seeds, asset correlation). • Certifications such asOSCP,GWAPT,GPEN(or equivalent demonstrable skill) are a plus;CISSPnice-to-have. What’sin it for you • A front row seat reducing real-world external risk—turning noisy findings intodecisive action. • Growth pathways intopen testing,threat modeling/assurance, orVM program leadership. Special Factors SponsorshipVanguard is not offering visa sponsorship for this position. About Vanguard At Vanguard, we don't just have a mission—we're on a mission. To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best. How We Work Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Apply Now

Date Posted

09/08/2025

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Neutral
Subjectivity Score: 0

Similar Jobs

Associate Director, Customer Experience Transformation Project Management (Remote) - Jazz Pharmaceuticals

Views in the last 30 days - 0

Identify and implement project management best practices tools and templates Bachelors degree required advanced degree or PMP certification preferred

View Details

Janitor - Elwyn

Views in the last 30 days - 0

A current Real ID or valid US Passport is required for this position to obtain the necessary security clearances at designated federal job sites

View Details

Marketing Solutions Manager - Morgan Properties

Views in the last 30 days - 0

Bachelors degree in Marketing Business Administration or related field preferred The Marketing Solutions Manager plays a pivotal role in driving a gro...

View Details

Cloud Solutions Architect - Comcast Corporation

Views in the last 30 days - 0

Proven experience in operations andor engineering within complex technical environments Operational or engineering experience with Kubernetes familiar...

View Details

Data Governance Analyst - Philadelphia Gas Works

Views in the last 30 days - 0

Experience in Data Governance with preferred DGSP certification or equivalent certification and expertise in data quality and compliance The job is on...

View Details

Data Analytics Lead in Financial Crimes - Vanguard

Views in the last 30 days - 0

Modernize analytics platforms using AI tools to improve financial crime surveillance and risk forecasting We are seeking a strategic analytics leader ...

View Details