Vulnerability Analyst — External Attack Surface & VDP
Role overview and responsibilities for assessing and validating external attack surface findings and VDP submissions, prioritizing risk, and coordinating remediation with product and security teams.
What You’ll Do
- Validate and reproduce findings from EASM (internet-exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and penetration testing frameworks to confirm exploitability and business impact.
- Right-size severity and priority using exploitability signals (e.g., public exploit, EPSS/KEV), control context, asset criticality, and exposure window; document rationale and evidence for developers and risk owners to act on.
- Deduplicate, enrich, and route findings to the correct owners; eliminate false positives; merge related signals (scanner output, logs, asset inventory, prior exceptions) and ensure single-threaded tracking to closure.
- Partner with secure business enablement and product teams to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when a one-shot remediation isn’t feasible.
- Collaborate on governance workflows for risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in dashboards.
- Maintain clear, respectful communications with researchers (for VDP) and perform crisp proof-of-fix retesting.
- Continuously improve signal quality by tuning rules/policies, source inventories, and intake/runbooks; author repeatable runbooks for common vulnerability classes.
- Contribute as an adversary when needed (mini-engagements) to validate edge-case chains and confirm impact beyond tool output.
What You’ll Bring
- 3–5 years in vulnerability analysis, application/infrastructure security, red teaming, or penetration testing (internal or consulting).
- Proven ability to validate complex issues (param tampering, authN/Z bypass, SSRF, injection, IDOR, misconfig, cloud/API exposures) and write concise, repeatable steps with screenshots/PoCs.
- Experience with EASM (e.g., Censys, Defender EASM, Cortex Xpanse) and VDP/bug bounty platforms (e.g., HackerOne, Bugcrowd) and their triage mechanics.
- Familiarity with enterprise VM & tracking systems (ServiceNow VR/IRM, Jira, Archer/Risk Register) and platform scanners (Qualys/Tenable/Nessus/Burp/ZAP).
- Working knowledge of cloud (AWS/Azure), web & API security, PKI/TLS hygiene, DNS, and hardening of internet-exposed services.
- Scripting (Python/PowerShell/Bash) for repeatable validation and data wrangling; basic SQL helpful.
- Exceptional written communication—capable of translating technical risk into actionable guidance and executive clarity.
Nice-to-have
- EPSS/KEV-driven prioritization, attack-path concepts, and risk input experience.
- Cloud posture and SaaS posture signals (SSPM) related to external exposure.
- Experience building tuning logic for scanners and platform rules (policy libraries, discovery seeds, asset correlation).
- Certifications such as OSCP, GWAPT, GPEN (or equivalent); CISSP is a plus.
What’s In It For You
- A front-row seat reducing real-world external risk—turning noisy findings into decisive action.
- Growth pathways into open testing, threat modeling/assurance, or program leadership.
Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we’re on a mission to help the long-term financial wellbeing of our clients. We strive to transform our clients’ lives through our products and services, and to grow our skills as individuals and as a team.
How We Work
Vanguard has implemented a hybrid working model to balance flexibility with in-person collaboration and learning.
Note: This job description includes responsibilities, qualifications, and expectations relevant to the role. References to locations, seniority level, employment type, and job function reflect current postings and may be updated.