Talent.com
Vulnerability Analyst External Attack Surface & VDP
Vulnerability Analyst External Attack Surface & VDPVanguard • Malvern, PA, United States
Vulnerability Analyst External Attack Surface & VDP

Vulnerability Analyst External Attack Surface & VDP

Vanguard • Malvern, PA, United States
30+ days ago
Job type
  • Full-time
Job description

Were seeking a hands-on?Vulnerability Analyst?to validate, analyze, and prioritize vulnerabilities discovered across our?External Attack Surface Management (EASM)?platform and?Vulnerability Disclosure Program (VDP). Youll combine deep vulnerability analysis with adversarial testing skills to reproduce and triage issues, ensure accurate severity and ownership, and drive timely remediation with partner teams. The ideal candidate has strong diagnostic instincts, excellent written evidence construction, and practical penetration testing experience.

  • This Hybrid Role (in office Tues-Wed-Thurs) can be based in either Charlotte, NC, Dallas, TX, or Malvern, PA (HQ)

What youll do

Validate & reproduce findings ?from EASM (internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to confirm exploitability and business impact.

Right-size severity & priority ?using exploitability signals (e.g., public exploit, EPSS / KEV), control context, asset criticality, and exposure window; document rationale and evidence that developers and risk owners can act on.

Deduplicate, enrich & route ?findings to the correct owners; eliminate false positives; merge related signal (scanner output, logs, asset inventory, prior exceptions) and ensure single threaded tracking to closure.

Partner with secure business enablement & product teams ?to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when one-shot remediation isnt feasible.

Partner on governance workflows ?for risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in our dashboards.

Close the loop with researchers ?(for VDP) through clear, respectful communications and crisp proof-of-fix retesting.

Continuously improve signal quality ?by tuning rules / policies, source inventories, and intake / playbooks; author repeatable runbooks for common vuln classes.

Contribute as an adversary ?when needed (mini-engagements) to validate edge case chains and confirm impact beyond tool output.

What youll bring

35 years ?in vulnerability analysis, application / infrastructure security, red teaming, or penetration testing (internal or consulting).

Proven ability to? validate complex issues ?(param tampering, authN / Z bypass, SSRF, injection, IDOR, misconfig, cloud / API exposures) and write concise, repeatable steps with screenshots / PoCs.

Experience with? EASM ?(e.g., Censys, Defender EASM, Cortex Xpanse) and? VDP / bug bounty ?platforms (e.g., HackerOne, Bugcrowd) and their triage mechanics.

Familiarity with? enterprise VM & tracking ?(ServiceNow VR / IRM, Jira, Archer / Risk Register), and with platform scanners (Qualys / Tenable / Nessus / Burp / ZAP).

Working knowledge of? cloud ?(AWS / Azure),? web & API ?security, PKI / TLS hygiene, DNS, and internet exposed service hardening.

Scripting ?(Python / PowerShell / Bash) for repeatable validation and data wrangling; basic SQL helpful.

Exceptional written communicationcapable of translating technical risk into? actionable guidance ?and executive clarity.

Nice-to-have exposure

EPSS / KEV driven prioritization, attack path / graph concepts, and risk quant inputs.

Cloud posture and SaaS posture signals (SSPM) that intersect with external exposure.

Building tuning logic for scanners and platform rules (e.g., policy libraries, discovery seeds, asset correlation).

Certifications such as? OSCP ,? GWAPT ,? GPEN ?(or equivalent demonstrable skill) are a plus;? CISSP ?nice-to-have.

Whats in it for you

A front row seat reducing real-world external riskturning noisy findings into? decisive action .

Growth pathways into? pen testing ,? threat modeling / assurance , or? VM program leadership .

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a missionwe're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Create a job alert for this search

Vulnerability Analyst • Malvern, PA, United States

Related jobs
Vulnerability Analyst External Attack Surface & VDP

Vulnerability Analyst External Attack Surface & VDP

Vanguard Group • Malvern, PA, United States
Full-time
EASM ( internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to c...Show more
Last updated: 1 day ago • Promoted
Cyber Warfare Technician

Cyber Warfare Technician

US Navy • Willmington, Delaware, United States
Part-time
Languages are more than just communication-they're cultural codes that need to be analyzed and in some cases, broken.As a Cryptologic Technician Interpretive (CTI) you're more than a linguist-you'r...Show more
Last updated: 30+ days ago • Promoted
Field Data Analyst

Field Data Analyst

Brubacher Excavating Inc • Brecknock Township, Pennsylvania, United States
Full-time
The Field Data Analyst is primarily responsible to identify, implement, and provide training for technology-focused solutions that yield efficient flow of information and work process in the field ...Show more
Last updated: 30+ days ago • Promoted
Director, Distinguished AI Engineer (Remote-Eligible)

Director, Distinguished AI Engineer (Remote-Eligible)

Capital One • Wilmington, DE, US
Remote
Full-time +1
Director, Distinguished AI Engineer (Remote-Eligible).At Capital One, we are creating responsible and reliable AI systems, changing banking for good. For years, Capital One has been an industry lead...Show more
Last updated: 30+ days ago • Promoted
Engineer, Nuclear Fuels

Engineer, Nuclear Fuels

Constellation Energy • Oxford, PA, US
Full-time
As the nation's largest producer of clean, carbon-free energy, Constellation is focused on our purpose : accelerating the transition to a carbon-free future. We have been the leader in clean ener...Show more
Last updated: 21 days ago • Promoted
Travel CT Technologist

Travel CT Technologist

Vibra Travels • Gilbertsville, PA, US
Full-time
Vibra Travels is seeking a travel CT Technologist for a travel job in Gilbertsville, Pennsylvania.Job Description & Requirements. VIBRA TRAVELS is looking for a CORPORATE TRAVEL CT TECHNOLOGIST ...Show more
Last updated: 30+ days ago • Promoted
Senior Platform Engineer (Workday Integration)

Senior Platform Engineer (Workday Integration)

Capital One • Wilmington, DE, US
Full-time +1
Senior Platform Engineer (Workday Integration).Do you love building and pioneering in the technology space? Do you enjoy solving complex technical problems in a fast-paced, collaborative, inclusive...Show more
Last updated: 30+ days ago • Promoted
Director, AI Engineering ( Remote-Eligible)

Director, AI Engineering ( Remote-Eligible)

Capital One • Wilmington, DE, US
Remote
Full-time +1
Director, AI Engineering ( Remote-Eligible) At Capital One, we are creating responsible and reliable AI systems, changing banking for good. For years, Capital One has been an industry leader in usin...Show more
Last updated: 1 day ago • Promoted
Vulnerability Analyst Tester (VA Tester)

Vulnerability Analyst Tester (VA Tester)

Tech-X • Aberdeen, MD, United States
Full-time
Vulnerability Analyst Tester (VA Tester).Tech(x) is an energized company with experienced, specialized and progressive thought leaders progressing talented professionals in areas of technology, sec...Show more
Last updated: 1 day ago • Promoted
Vulnerability Analyst - External Attack Surface & VDP

Vulnerability Analyst - External Attack Surface & VDP

Vanguard Group, Inc. • Malvern, PA, United States
Full-time
EASM (internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to co...Show more
Last updated: 1 day ago • Promoted
Lead Cybersecurity Engineer - Vulnerability

Lead Cybersecurity Engineer - Vulnerability

M&T Bank • Wilmington, DE, United States
Full-time
This role offers a hybrid work schedule providing the opportunity for in-person collaboration at our Wilmington, DE location. Responsible for designing and implementing large scale-scale security sy...Show more
Last updated: 14 days ago • Promoted
Senior Platform Engineer, Workday Integration (Extend)

Senior Platform Engineer, Workday Integration (Extend)

Capital One • Wilmington, DE, US
Full-time +1
Senior Platform Engineer, Workday Integration (Extend).Do you love building and pioneering in the technology space? Do you enjoy solving complex technical problems in a fast-paced, collaborative, i...Show more
Last updated: 30+ days ago • Promoted
Tx Construction & Design Technology - Application Configuration Analyst

Tx Construction & Design Technology - Application Configuration Analyst

FirstEnergy • Reading, PA, United States
Full-time
We are a forward-thinking electric utility powered by a diverse team of employees committed to making customers’ lives brighter, the environment better and our communities stronger.FirstEnergy (NYS...Show more
Last updated: 1 day ago • Promoted
Construction Safety Specialist

Construction Safety Specialist

The H&K Group • Skippack, PA, United States
Full-time
We are always looking for the best, most qualified people to join our team.Pre-employment drug testing (EOE).Construction Safety Specialist. Safety Specialist to support heavy civil and highway cons...Show more
Last updated: 2 days ago • Promoted
Data Collection Leader

Data Collection Leader

Bowhead / UIC Technical Services • Aberdeen, Maryland, US
Full-time
Overview DATA COLLECTION LEADER (ATCDT) Bowhead seeks a Data Collection Leader to support the ATC Data Collection upcoming proposal effort at Aberdeen Proving Ground, MD. The ATC Data Collection con...Show more
Last updated: 30+ days ago • Promoted
Traffic Engineer

Traffic Engineer

Howell Engineering, Surveying and Environmental • West Chester, PA, United States
Full-time
At Howell Engineering, we thrive on pushing the boundaries of what's possible by leading the charge in innovative processes, utilizing best-in-class technology, and delivering unmatched results for...Show more
Last updated: 6 days ago • Promoted
Health Physics Sr. Specialist

Health Physics Sr. Specialist

Merck • West Point, PA, US
Full-time
Responsible for providing compliant environmental, health, and safety (EHS) programs to operating departments at the West Point site regarding laser safety and radiation safety.Integrates EHS progr...Show more
Last updated: 6 hours ago • Promoted • New!
Manager, Vulnerability Management Data Engineering

Manager, Vulnerability Management Data Engineering

Vanguard • Malvern, PA, United States
Full-time
We are seeking an experienced Manager, Vulnerability Management Data Engineering to build and lead a team focused on the design, development, and operation of enterprise-scale data solutions that e...Show more
Last updated: 3 days ago • Promoted