Vulnerability Analyst — External Attack Surface & VDP

Vanguard

Charlotte (NC)

On-site

USD 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading financial services firm in Charlotte is seeking a Vulnerability Analyst to validate and reproduce security findings. The role requires 3-5 years in vulnerability analysis or application security, along with scripting skills. Collaboration with product teams and governance is essential. The ideal candidate will have experience with EASM and VDP platforms. This position offers a supportive work environment and is focused on continuous improvement.

Qualifications

  • 3-5 years in vulnerability analysis or application/infrastructure security.
  • Proven ability to validate complex issues and write concise steps.
  • Experience with EASM and VDP/bug bounty platforms.

Responsibilities

  • Validate and reproduce findings from EASM and VDP submissions.
  • Right-size severity and priority using exploitability signals.
  • Partner with teams to negotiate remediation paths and SLAs.

Skills

Vulnerability analysis
Application security
Exploitability validation
Scripting (Python/PowerShell/Bash)
Technical writing

Tools

EASM platforms
VDP platforms
Platform scanners

Job description

Vulnerability Analyst — External Attack Surface & VDP

Validate and reproduce findings from EASM (internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to confirm exploitability and business impact.

Responsibilities include:

  • Right-size severity and priority using exploitability signals, control context, asset criticality, and exposure window; document rationale and evidence that developers and risk owners can act on.
  • Deduplicate, enrich, and route findings to the correct owners; eliminate false positives; merge related signals and ensure single-threaded tracking to closure.
  • Partner with secure business enablement and product teams to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when one-shot remediation isn’t feasible.
  • Partner on governance workflows for risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in our dashboards.
  • Close the loop with researchers (for VDP) through clear, respectful communications and crisp proof-of-fix retesting.
  • Continuously improve signal quality by tuning rules/policies, source inventories, and intake/playbooks; author repeatable runbooks for common vulnerability classes.
  • Contribute as an adversary when needed (mini-engagements) to validate edge case chains and confirm impact beyond tool output.

Requirements include:

  • 3-5 years in vulnerability analysis, application/infrastructure security, red teaming, or penetration testing.
  • Proven ability to validate complex issues and write concise, repeatable steps with screenshots/PoCs.
  • Experience with EASM and VDP/bug bounty platforms and their triage mechanics.
  • Familiarity with enterprise VM and tracking, and with platform scanners.
  • Working knowledge of cloud, web, and API security, PKI/TLS hygiene, DNS, and internet exposed service hardening.
  • Scripting (Python/PowerShell/Bash) for repeatable validation and data wrangling; basic SQL helpful.
  • Exceptional written communication — capable of translating technical risk into actionable guidance and executive clarity.

Vanguard is an equal opportunities employer and welcomes applications from all qualified candidates. We are committed to providing a work environment that is free from discrimination and harassment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Malvern

Hybrid
USD 80,000 - 110,000
Growth pathways in security roles
Hybrid working model
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Vulnerabilities Security Researcher
Vulnerabilities Security Researcher

Request Technology, LLC • United States

On-site
USD 120,000 - 150,000
Bonus eligibility
Vulnerability Management and Security Engineering
Vulnerability Management and Security Engineering

RennerBrown • New York (NY)

On-site
USD 140,000 - 190,000
External Attack Surface & Vulnerability Analyst (VDP)
External Attack Surface & Vulnerability Analyst (VDP)

Vanguard • Charlotte (NC)

On-site
USD 80,000 - 100,000
Senior Security Research Engineer
Senior Security Research Engineer

PlayStation • New York (NY)

On-site
USD 180,000 - 230,000
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

Peraton • Maryland

On-site
USD 90,000 - 150,000
VIPR & VMDR Expert
VIPR & VMDR Expert

Armis • Town of Poland (NY)

On-site
USD 140,000 - 200,000
VIPR & VMDR Expert
VIPR & VMDR Expert

Armis • Germany (OH)

Hybrid
USD 150,000 - 210,000
Security Operations Vice President - Vulnerability Management
Security Operations Vice President - Vulnerability Management

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 90,000 - 110,000