Talent.com
Vulnerability Analyst External Attack Surface & VDP

Vulnerability Analyst External Attack Surface & VDP

VanguardMalvern, PA, United States
4 days ago
Job type
  • Full-time
Job description

What you’ll do

Validate & reproduce findings  from EASM ( internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to confirm exploitability and business impact.

Right - size severity & priority  using exploitability signals (e.g., public exploit, EPSS / KEV), control context, asset criticality, and exposure window; document rationale and evidence that developers and risk owners can act on.

De duplicate, enrich & route  findings to the correct owners; eliminate false positives; merge related signal (scanner output, logs, asset inventory, prior exceptions) and ensure single threaded tracking to closure.

Partner with secure business enablement & product teams  to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when “ one-shot ” remediation isn’t feasible .

Partner on governance workflows  for risk acceptances, rating overrides, and re acceptance cycles; ensure issues aging and SLAs are visible in our dashboards.

Close the loop with researchers  (for VDP) through clear, respectful communications and crisp proof - of - fix retesting.

Continuously improve signal quality  by tuning rules / policies, source inventories, and intake / playbooks; author repeatable runbooks for common vuln classes.

Contribute as an adversary  when needed ( mini - engagements ) to validate edge case chains and confirm impact beyond tool output.

What you’ll bring

3 – 5 years  in vulnerability analysis, application / infrastructure security, red teaming, or penetration testing (internal or consulting).

Proven ability to  validate complex issues  (param tampering, authN / Z bypass, SSRF, injection, IDOR, misconfig , cloud / API exposures) and write concise, repeatable steps with screenshots / PoCs .

Experience with  EASM  (e.g., Censys , Defender EASM, Cortex Xpanse ) and  VDP / bug bounty  platforms (e.g., HackerOne , Bugcrowd ) and their triage mechanics.

Familiarity with  enterprise VM & tracking  (ServiceNow VR / IRM, Jira, Archer / Risk Register), and with platform scanners (Qualys / Tenable / Nessus / Burp / ZAP).

Working knowledge of  cloud  (AWS / Azure),  web & API  security, PKI / TLS hygiene, DNS, and internet e xposed service hardening.

Scripting  (Python / PowerShell / Bash) for repeatable validation and data wrangling; basic SQL helpful.

Exceptional written communication—capable of translating technical risk into  actionable guidance  and executive clarity.

Nice - to - have exposure

EPSS / KEV driven prioritization, attack path / graph concepts, and risk quant inputs.

Cloud posture and SaaS posture signals (SSPM) that intersect with external exposure.

Building tuning logic for scanners and platform rules (e.g., policy libraries, discovery seeds, asset correlation).

Certifications such as  OSCP ,  GWAPT ,  GPEN  (or equivalent demonstrable skill) are a plus;  CISSP  nice - to - have.

What’s in it for you

A front row seat reducing real-world external risk—turning noisy findings into  decisive action .

Growth pathways into  pen testing ,  threat modeling / assurance , or  VM program leadership .

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Create a job alert for this search

Vulnerability Analyst • Malvern, PA, United States

Related jobs
  • Promoted
Senior Security Analyst

Senior Security Analyst

EnvestnetBerwyn, PA, United States
Full-time
This is a hybrid role, with in-office work required at our Berwyn, PA office location.Envestnet is transforming the way financial advice is delivered through its connected technology, advanced insi...Show moreLast updated: 4 days ago
  • Promoted
Compliance Analyst

Compliance Analyst

Wilmington Savings Fund SocietyWilmington, DE, US
Full-time
Job Description At WSFS Bank, we empower our Associates to grow their careers, we guide our customers to secure their financial futures, and we actively support our Communities so they can fully th...Show moreLast updated: 19 days ago
  • Promoted
Cloud Identity Access Management Analyst I

Cloud Identity Access Management Analyst I

UHSKing of Prussia, PA, United States
Full-time
About Universal Health Services.One of the nation's largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. NYSE : UHS) has built an impressive recor...Show moreLast updated: 4 days ago
  • Promoted
Sr. Cloud Analyst

Sr. Cloud Analyst

Lincoln Financial ServicesRadnor Twp, PA, United States
Full-time
Alternate Locations : Radnor, PA (Pennsylvania); Charlotte, NC (North Carolina); Fort Wayne, IN (Indiana); Greensboro, NC (North Carolina) Work Arrangement : Hybrid : Employee will work 3 days a we...Show moreLast updated: 4 days ago
  • Promoted
Cybersecurity Lead w / PM

Cybersecurity Lead w / PM

Amtex EnterprisesWilmington, DE, United States
Full-time
Wilmington, DE (4 days on-site).We are seeking an experienced Cybersecurity Lead with a strong background in project management to oversee and deliver complex security initiatives.The ideal candida...Show moreLast updated: 1 day ago
  • Promoted
Principal Traffic Engineer

Principal Traffic Engineer

Howell Engineering, Surveying and EnvironmentalWest Chester, PA, US
Full-time
At Howell Engineering, we thrive on pushing the boundaries of what's possible by leading the charge in innovative processes, utilizing best-in-class technology, and delivering unmatched results...Show moreLast updated: 2 days ago
  • Promoted
Senior CyberArk Engineer - Remote

Senior CyberArk Engineer - Remote

EPAM Systems IncConshohocken, PA, United States
Remote
Full-time
Endpoint Privileged Management.Expertise in Endpoint Privileged Management tools is essential for this role.In this advanced position, you will work to elevate the organization's security posture w...Show moreLast updated: 4 days ago
  • Promoted
Border Patrol Agent

Border Patrol Agent

U.S. Customs and Border ProtectionBoyertown, PA, United States
Full-time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show moreLast updated: 30+ days ago
  • Promoted
Senior GRC Analyst

Senior GRC Analyst

Soni ResourcesKing of Prussia, PA, United States
Full-time
Hybrid role - King of Prussia, PA or Denver, PA.Minimum of 3 days (Tues, Wed & Thursday's).Information Security / Compliance / Risk Management. Global Cybersecurity GRC Manager.Reporting to the Glob...Show moreLast updated: 4 days ago
  • Promoted
Cyber Reverse Engineer

Cyber Reverse Engineer

Parra Consulting Group, Inc.Aberdeen, MD, United States
Full-time
Cyber Reverse Engineer, to contribute to a team that works hands on with state-of-the-art electronics.You'll perform advanced analysis and evaluation of applications and firmware and assist with th...Show moreLast updated: 30+ days ago
  • Promoted
Reimbursement Specialist-RTB

Reimbursement Specialist-RTB

Pentec HealthMarcus Hook, PA, US
Full-time
This position is responsible for the resolution of unbilled tickets with the Ready to Bill file, under AUTH, AUTH PART D, AUTHORIZATION PENDING PD, INS, TERMED PART D and MGMT etc.The role provides...Show moreLast updated: 11 days ago
  • Promoted
Vulnerability Management Application Security Lead

Vulnerability Management Application Security Lead

Insight GlobalWilmington, DE, United States
Full-time
A client of Insight Globals is seeking a Vulnerability Management Application Security Lead to enhance application security through penetration testing, static code reviews, and vulnerability analy...Show moreLast updated: 1 day ago
  • Promoted
Service Desk Analyst

Service Desk Analyst

TWO95 InternationalReading, PA, United States
Full-time
Job Title : Service Desk Analyst.Respond to incoming call and e-mail queues promptly and document incidents accurately and simultaneously in to the case management system. Create user accounts and ac...Show moreLast updated: 4 days ago
  • Promoted
Vulnerability Management Application Security Lead

Vulnerability Management Application Security Lead

BerkleyWilmington, DE, United States
Full-time
Company URL : .Berkley Technology Services (BTS) is the dynamic technology solution for W.Berkley Corporation, a Fortune 500 Commercial Lines Insurance Compan...Show moreLast updated: 4 days ago
  • Promoted
Compliance Analyst II

Compliance Analyst II

Wilmington Savings Fund SocietyWilmington, DE, US
Full-time
Job Description At WSFS Bank, we empower our Associates to grow their careers, guide our customers to secure their financial futures, and actively support our Communities so they can fully thrive.C...Show moreLast updated: 24 days ago
  • Promoted
Sr EH&S Specialist

Sr EH&S Specialist

Medline Industries - Transportation & OperationsPerryville, MD, US
Full-time
Job Summary Under minimal supervision, responsible for leading the implementation of Employee Health and Safety programs, policies, management systems and strategies in support of all Distribution ...Show moreLast updated: 30+ days ago
  • Promoted
Intune Security Analyst

Intune Security Analyst

MondoWilmington, DE, United States
Temporary
Hybrid (Onsite in Wilmington, DE - Mon-Wed onsite, office closed in February ).Help secure and manage enterprise Windows endpoints, ensuring device compliance, identity access, and vulnerability re...Show moreLast updated: 4 days ago
  • Promoted
Cybersecurity Sr. GRC Analyst

Cybersecurity Sr. GRC Analyst

RIT SolutionsKing of Prussia, PA, United States
Full-time
Location : 3-day Hybrid (TueThu) in King of Prussia, PA or Denver, PA Locals Only.Duration : 36 Months, Contract-to-Hire (CTH) Rate : Best Possible, But Keep At The Lower End (Oil & Gas Client Budget)...Show moreLast updated: 1 day ago