Vulnerability Analyst — External Attack Surface & VDP

Vanguard

Charlotte (NC)

On-site

USD 80,000 - 100,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

A leading financial services firm in Charlotte is seeking a Vulnerability Analyst to validate and reproduce security findings. The role requires 3-5 years in vulnerability analysis or application security, along with scripting skills. Collaboration with product teams and governance is essential. The ideal candidate will have experience with EASM and VDP platforms. This position offers a supportive work environment and is focused on continuous improvement.

Qualifications

  • 3-5 years in vulnerability analysis or application/infrastructure security.
  • Proven ability to validate complex issues and write concise steps.
  • Experience with EASM and VDP/bug bounty platforms.

Responsibilities

  • Validate and reproduce findings from EASM and VDP submissions.
  • Right-size severity and priority using exploitability signals.
  • Partner with teams to negotiate remediation paths and SLAs.

Skills

Vulnerability analysis
Application security
Exploitability validation
Scripting (Python/PowerShell/Bash)
Technical writing

Tools

EASM platforms
VDP platforms
Platform scanners

Job description

Vulnerability Analyst — External Attack Surface & VDP

Validate and reproduce findings from EASM (internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to confirm exploitability and business impact.

Responsibilities include:

  • Right-size severity and priority using exploitability signals, control context, asset criticality, and exposure window; document rationale and evidence that developers and risk owners can act on.
  • Deduplicate, enrich, and route findings to the correct owners; eliminate false positives; merge related signals and ensure single-threaded tracking to closure.
  • Partner with secure business enablement and product teams to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when one-shot remediation isn’t feasible.
  • Partner on governance workflows for risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in our dashboards.
  • Close the loop with researchers (for VDP) through clear, respectful communications and crisp proof-of-fix retesting.
  • Continuously improve signal quality by tuning rules/policies, source inventories, and intake/playbooks; author repeatable runbooks for common vulnerability classes.
  • Contribute as an adversary when needed (mini-engagements) to validate edge case chains and confirm impact beyond tool output.

Requirements include:

  • 3-5 years in vulnerability analysis, application/infrastructure security, red teaming, or penetration testing.
  • Proven ability to validate complex issues and write concise, repeatable steps with screenshots/PoCs.
  • Experience with EASM and VDP/bug bounty platforms and their triage mechanics.
  • Familiarity with enterprise VM and tracking, and with platform scanners.
  • Working knowledge of cloud, web, and API security, PKI/TLS hygiene, DNS, and internet exposed service hardening.
  • Scripting (Python/PowerShell/Bash) for repeatable validation and data wrangling; basic SQL helpful.
  • Exceptional written communication — capable of translating technical risk into actionable guidance and executive clarity.

Vanguard is an equal opportunities employer and welcomes applications from all qualified candidates. We are committed to providing a work environment that is free from discrimination and harassment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Malvern

On-site
USD 80,000 - 110,000
Growth pathways in security roles
Hybrid working model
Vulnerabilities Security Researcher
Vulnerabilities Security Researcher

Request Technology, LLC • United States

On-site
USD 120,000 - 150,000
Bonus eligibility
Vulnerability Scan Analyst
Vulnerability Scan Analyst

Xtreme Solutions Corporate • California (MO)

Remote
USD 90,000 - 120,000
External Attack Surface & Vulnerability Analyst (VDP)
External Attack Surface & Vulnerability Analyst (VDP)

Vanguard • Charlotte (NC)

On-site
USD 80,000 - 100,000
Vulnerability Engineer
Vulnerability Engineer

Vertex Computer Systems • New York (NY)

On-site
USD 110,000 - 160,000
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

Openloop-Health • Des Moines (IA)

On-site
USD 90,000 - 120,000
X-Day Offensive Research (XOR) Vulnerability Researcher
X-Day Offensive Research (XOR) Vulnerability Researcher

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 150,000 - 230,000
Vulnerability Management Analyst
Vulnerability Management Analyst

DANE, LLC • Chantilly (VA)

On-site
USD 75,000 - 95,000
Life/STD/LTD
FSA/DCA
401(k)
+7
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Security Engineer (Application Security)
Security Engineer (Application Security)

Trail of Bits • United States

Hybrid
USD 90,000 - 130,000
Health Insurance
Vision, Dental, Life & Disability
401k with company matching
+3