Demo

Vulnerability Analyst — External Attack Surface & VDP

The Vanguard Group, Inc.
Malvern, PA Full Time
POSTED ON 1/2/2026
AVAILABLE BEFORE 2/2/2026
What you’ll do Validate & reproduce findings from EASM (internet exposed assets, misconfigurations, leaked services, weak crypto, open ports) and from VDP submissions (web, API, mobile, infrastructure). Use manual techniques and PT frameworks to confirm exploitability and business impact. Right-size severity & priority using exploitability signals (e.g., public exploit, EPSS/KEV), control context, asset criticality, and exposure window; document rationale and evidence that developers and risk owners can act on. Deduplicate, enrich & route findings to the correct owners; eliminate false positives; merge related signal (scanner output, logs, asset inventory, prior exceptions) and ensure single threaded tracking to closure. Partner with secure business enablement & product teams to negotiate remediation paths and SLAs; propose compensating controls or layered fixes when “one-shot” remediation isn’t feasible. Partner on governance workflows for risk acceptances, rating overrides, and reacceptance cycles; ensure issues aging and SLAs are visible in our dashboards. Close the loop with researchers (for VDP) through clear, respectful communications and crisp proof-of-fix retesting. Continuously improve signal quality by tuning rules/policies, source inventories, and intake/playbooks; author repeatable runbooks for common vuln classes. Contribute as an adversary when needed (mini-engagements) to validate edge case chains and confirm impact beyond tool output. What you’ll bring 3–5 years in vulnerability analysis, application/infrastructure security, red teaming, or penetration testing (internal or consulting). Proven ability to validate complex issues (param tampering, authN/Z bypass, SSRF, injection, IDOR, misconfig, cloud/API exposures) and write concise, repeatable steps with screenshots/PoCs. Experience with EASM (e.g., Censys, Defender EASM, Cortex Xpanse) and VDP/bug bounty platforms (e.g., HackerOne, Bugcrowd) and their triage mechanics. Familiarity with enterprise VM & tracking (ServiceNow VR/IRM, Jira, Archer/Risk Register), and with platform scanners (Qualys/Tenable/Nessus/Burp/ZAP). Working knowledge of cloud (AWS/Azure), web & API security, PKI/TLS hygiene, DNS, and internet exposed service hardening. Scripting (Python/PowerShell/Bash) for repeatable validation and data wrangling; basic SQL helpful. Exceptional written communication—capable of translating technical risk into actionable guidance and executive clarity. Nice-to-have exposure EPSS/KEV driven prioritization, attack path/graph concepts, and risk quant inputs. Cloud posture and SaaS posture signals (SSPM) that intersect with external exposure. Building tuning logic for scanners and platform rules (e.g., policy libraries, discovery seeds, asset correlation). Certifications such as OSCP, GWAPT, GPEN (or equivalent demonstrable skill) are a plus; CISSP nice-to-have. What’s in it for you A front row seat reducing real-world external risk—turning noisy findings into decisive action. Growth pathways into pen testing, threat modeling/assurance, or VM program leadership. Special Factors Sponsorship Vanguard is not offering visa sponsorship for this position. About Vanguard At Vanguard, we don't just have a mission—we're on a mission. To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best. How We Work Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience. Vanguard, one of the world's largest investment management companies, serves individual investors, institutions, employer-sponsored retirement plans, and financial professionals. We have a diverse and talented crew with a culture that promotes teamwork, along with an unwavering focus on serving our clients' best interests. This website uses "cookies" to distinguish you from other users. A cookie is a small file of letters and numbers placed on your computer or device. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site and services. The cookies are stored locally on your computer or mobile device. To accept cookies you can continue browsing as normal. Or you can go to our Privacy Policy to read more information and learn how to change your preferences.

Salary.com Estimation for Vulnerability Analyst — External Attack Surface & VDP in Malvern, PA
$87,245 to $110,355
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Vulnerability Analyst — External Attack Surface & VDP?

Sign up to receive alerts about other jobs on the Vulnerability Analyst — External Attack Surface & VDP career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$161,616 - $208,121
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$105,243 - $143,011
Income Estimation: 
$101,446 - $138,837
Income Estimation: 
$87,128 - $112,557
Income Estimation: 
$58,470 - $77,272
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$75,905 - $103,047
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$94,973 - $125,755
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$121,926 - $164,179
Income Estimation: 
$124,413 - $154,875
Income Estimation: 
$87,128 - $112,557
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at The Vanguard Group, Inc.

  • The Vanguard Group, Inc. Malvern, PA
  • Serves as a thought partner and senior analyst to develop innovative data solutions and frameworks to support AI ready data. Vanguard is looking for a seni... more
  • 13 Days Ago

  • The Vanguard Group, Inc. Scottsdale, AZ
  • About this Job: Work Model: This role will be remote once you complete our required hybrid licensing and training program. Location: This role is only open... more
  • 6 Days Ago

  • The Vanguard Group, Inc. Malvern, PA
  • Vanguard is a business that operates on trust – trust that we focus on the client, trust that assets are safe from fraud, and trust that we employ intellig... more
  • 6 Days Ago

  • The Vanguard Group, Inc. Malvern, PA
  • About this Job: Work Model: This role will be remote once you complete our required hybrid licensing and training program. Licensing: The SIE is a mandator... more
  • 6 Days Ago


Not the job you're looking for? Here are some other Vulnerability Analyst — External Attack Surface & VDP jobs in the Malvern, PA area that may be a better fit.

  • Vanguard and Careers Malvern, PA
  • We’re seeking a seasoned Senior Vulnerability Engineer to lead advanced attribution and engineering efforts across our External Attack Surface Management (... more
  • 8 Days Ago

  • EY Philadelphia, PA
  • At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career w... more
  • 18 Days Ago

AI Assistant is available now!

Feel free to start your new journey!