Web Application and Fraud - Offensive Security Specialist

Vanguard

Dallas (TX)

Hybrid

USD 110,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Vanguard is seeking an Offensive Security Analyst for the Web Application & Fraud Testing team to conduct threat-driven security testing of our client-facing web apps. You will apply adversarial techniques to validate controls and help inform detection improvements across the enterprise.

You will design realistic stress tests for fraud detection, assess risks, and mentor junior team members while partnering with IT and business units to ensure timely remediation of findings.

Qualifications

  • OSCP, OSWA, OSWE, CWES, GWAPT, PWPP or equivalent professional level web application testing certification required
  • CISSP preferred
  • Minimum of five years related work experience, with three years' experience in threat analysis
  • Undergraduate degree in a related field or the equivalent combination of training and experience
  • Experience testing controls and fostering collaboration in an effort to remediate findings from assessments
  • Experience assessing production web applications

Responsibilities

  • Beyond traditional application testing, this operator will help design and execute realistic scenarios that stress-test cyber fraud detection and response, and partner with defensive teams in exercises to validate that our controls fire when they should.
  • Assesses the risk and business impact of identified findings, applying defensible severity ratings based on likelihood, exploitability, and exposure.
  • Fosters and supports junior talent through informal leadership and coaching. Mentors junior team members to improve their technical acumen.
  • Applies emerging adversarial tradecraft against client facing web application infrastructure through rigorous control validation to improve reactive and proactive threat driven operations.
  • Conducts penetration testing, vulnerability assessments and threat modeling. Evaluates risks and makes recommendations.
  • Provides written assessments focused on threats, vulnerabilities, and technologies relevant to Vanguard Infrastructure.
  • Leads with IT and business teams to ensure prompt and effective distribution of findings so incidents are effectively addressed. Provides department support to the business on enterprise-wide security initiatives and projects.
  • Participates in special projects and performs other duties as assigned.

Skills

Threat analysis
Mentoring
Security testing

Education

OSCP; OSWE; OSWA; CWES; GWAPT; PWPP certificates

Job description

The Offensive Security Analyst on the Web Application & Fraud Testing team conducts threat-driven security testing of Vanguard's critical client-facing web applications. This role applies nascent adversarial TTPs to validate whether existing controls detect and prevent the fraud tradecraft currently emerging in the threat landscape. Findings from this work directly inform detection improvements and control remediation across the enterprise.

Core Responsibilities
  • Beyond traditional application testing, this operator will help design and execute realistic scenarios that stress-test cyber fraud detection and response, and partner with defensive teams in exercises to validate that our controls fire when they should.
  • Assesses the risk and business impact of identified findings, applying defensible severity ratings based on likelihood, exploitability, and exposure. Thinks critically about remediation guidance so that recommendations to partner teams are practical, proportionate to the risk, and address root cause rather than symptom.
  • Fosters and supports junior talent through informal leadership and coaching. Mentors junior team members to improve their technical acumen.
  • Applies emerging adversarial tradecraft against client facing web application infrastructure through rigorous control validation to improve reactive and proactive threat driven operations.
  • Conducts penetration testing, vulnerability assessments and threat modeling. Evaluates risks and makes recommendations.
  • Provides written assessments focused on threats, vulnerabilities, and technologies relevant to Vanguard Infrastructure.
  • Leads with IT and business teams to ensure prompt and effective distribution of findings so incidents are effectively addressed. Provides department support to the business on enterprise-wide security initiatives and projects.
  • Participates in special projects and performs other duties as assigned.
Qualifications
  • OSCP, OSWA, OSWE, CWES, GWAPT, PWPP, or equivalent professional level web application testing certification required
  • CISSP preferred
  • Minimum of five years related work experience, with three years' experience in threat analysis.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • Experience testing controls and fostering collaboration in an effort to remediate findings from assessments.
  • Experience assessing production web applications.
Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Web Application and Fraud - Offensive Security Specialist
Web Application and Fraud - Offensive Security Specialist

Vanguard • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Hybrid Fraud-Focused Web App Offensive Security Analyst
Hybrid Fraud-Focused Web App Offensive Security Analyst

Vanguard • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Threat Emulation and Exploit Engineer
Threat Emulation and Exploit Engineer

Vanguard • Malvern

On-site
USD 140,000 - 190,000
Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

The Vanguard Group • Dallas (TX)

Hybrid
USD 110,000 - 170,000
Application Security, Specialist
Application Security, Specialist

Vanguard • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Health and wellness care
Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Senior Web App Security & Fraud Tester
Senior Web App Security & Fraud Tester

Vanguard • Dallas (TX)

Hybrid
USD 110,000 - 160,000
Application Security, Specialist
Application Security, Specialist

Vanguard • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Talentify • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Application Engineering Technical Lead - II
Application Engineering Technical Lead - II

Vanguard • Dallas (TX)

Hybrid
USD 140,000 - 170,000
Hybrid work model