Vulnerability Analyst — External Attack Surface & VDP

Vanguard

Malvern (Chester County)

Hybrid

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Growth pathways in security roles
Hybrid working model

Job summary

A leading financial services company in Chester County is seeking a Vulnerability Analyst to assess external attack surface findings and manage submissions through detailed validation. This role offers a hybrid work model and opportunities for professional growth in security and risk management. Ideal candidates have 3–5 years in vulnerability analysis and strong communication skills.

Qualifications

  • 3–5 years in vulnerability analysis, application security, red teaming, or penetration testing.
  • Proven ability to validate complex issues and write concise steps with screenshots/PoCs.
  • Working knowledge of cloud (AWS/Azure) and web & API security.

Responsibilities

  • Validate and reproduce findings from external attack surface and VDP submissions.
  • Prioritize risk and coordinate remediation with product and security teams.
  • Maintain clear communications with researchers and perform proof-of-fix retesting.

Skills

Vulnerability analysis
Application security
Penetration testing
Scripting (Python/PowerShell/Bash)
Exceptional written communication

Tools

EASM tools (Censys, Defender EASM)
VDP platforms (HackerOne, Bugcrowd)
Jira
Qualys/Tenable/Nessus/Burp/ZAP

Job description

Vulnerability Analyst — External Attack Surface & VDP

Role overview and responsibilities for assessing and validating external attack surface findings and VDP submissions, prioritizing risk, and coordinating remediation with product and security teams.

What You’ll Do
  • Validate and reproduce findings from EASM (internet-exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and penetration testing frameworks to confirm exploitability and business impact.
  • Right-size severity and priority using exploitability signals (e.g., public exploit, EPSS/KEV), control context, asset criticality, and exposure window; document rationale and evidence for developers and risk owners to act on.
  • Deduplicate, enrich, and route findings to the correct owners; eliminate false positives; merge related signals (scanner output, logs, asset inventory, prior exceptions) and ensure single-threaded tracking to closure.
  • Partner with secure business enablement and product teams to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when a one-shot remediation isn’t feasible.
  • Collaborate on governance workflows for risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in dashboards.
  • Maintain clear, respectful communications with researchers (for VDP) and perform crisp proof-of-fix retesting.
  • Continuously improve signal quality by tuning rules/policies, source inventories, and intake/runbooks; author repeatable runbooks for common vulnerability classes.
  • Contribute as an adversary when needed (mini-engagements) to validate edge-case chains and confirm impact beyond tool output.
What You’ll Bring
  • 3–5 years in vulnerability analysis, application/infrastructure security, red teaming, or penetration testing (internal or consulting).
  • Proven ability to validate complex issues (param tampering, authN/Z bypass, SSRF, injection, IDOR, misconfig, cloud/API exposures) and write concise, repeatable steps with screenshots/PoCs.
  • Experience with EASM (e.g., Censys, Defender EASM, Cortex Xpanse) and VDP/bug bounty platforms (e.g., HackerOne, Bugcrowd) and their triage mechanics.
  • Familiarity with enterprise VM & tracking systems (ServiceNow VR/IRM, Jira, Archer/Risk Register) and platform scanners (Qualys/Tenable/Nessus/Burp/ZAP).
  • Working knowledge of cloud (AWS/Azure), web & API security, PKI/TLS hygiene, DNS, and hardening of internet-exposed services.
  • Scripting (Python/PowerShell/Bash) for repeatable validation and data wrangling; basic SQL helpful.
  • Exceptional written communication—capable of translating technical risk into actionable guidance and executive clarity.
Nice-to-have
  • EPSS/KEV-driven prioritization, attack-path concepts, and risk input experience.
  • Cloud posture and SaaS posture signals (SSPM) related to external exposure.
  • Experience building tuning logic for scanners and platform rules (policy libraries, discovery seeds, asset correlation).
  • Certifications such as OSCP, GWAPT, GPEN (or equivalent); CISSP is a plus.
What’s In It For You
  • A front-row seat reducing real-world external risk—turning noisy findings into decisive action.
  • Growth pathways into open testing, threat modeling/assurance, or program leadership.
Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we’re on a mission to help the long-term financial wellbeing of our clients. We strive to transform our clients’ lives through our products and services, and to grow our skills as individuals and as a team.

How We Work

Vanguard has implemented a hybrid working model to balance flexibility with in-person collaboration and learning.

Note: This job description includes responsibilities, qualifications, and expectations relevant to the role. References to locations, seniority level, employment type, and job function reflect current postings and may be updated.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Charlotte (NC)

On-site
USD 80,000 - 100,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Charlotte (NC)

Hybrid
USD 140,000 - 180,000
Hybrid work model
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Dallas (TX)

Hybrid
USD 180,000 - 240,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Threat Emulation and Exploit Engineer
Threat Emulation and Exploit Engineer

Vanguard • Dallas (TX)

Hybrid
USD 110,000 - 150,000
Vulnerability Management and Security Engineering
Vulnerability Management and Security Engineering

RennerBrown • New York (NY)

On-site
USD 140,000 - 190,000
Senior Manager, Offensive Security
Senior Manager, Offensive Security

Vanguard • Town of Charlotte (NY)

Hybrid
USD 180,000 - 240,000
Attack Surface and Exposure Validation Assistant Engineer
Attack Surface and Exposure Validation Assistant Engineer

EY • Secaucus (NJ)

On-site
USD 120,000 - 160,000
Attack Surface and Exposure Validation Assistant Engineer
Attack Surface and Exposure Validation Assistant Engineer

EY • Chicago (IL)

On-site
USD 150,000 - 210,000