Lead EASM engineering and validation for vulnerability management at Vanguard. Shape strategies for external attack surface security in a leadership role while promoting risk reduction.
Responsibilities
Lead EASM validation and engineering: Investigate and reproduce findings from EASM platforms (e.g., exposed services, misconfigurations, weak crypto, DNS issues, leaked assets).
Engineer and maintain repeatable validation processes and automation to confirm exploitability and business impact.
Architect prioritization logic: Partner with VM stakeholder to apply exploitability signals (EPSS, KEV, public exploit availability), asset criticality, and exposure windows to drive risk-based prioritization.
Engineer attribution and routing workflows: Build logic to deduplicate, attribute, and route findings across inventories, scanner outputs, and historical exceptions.
Ensure single-threaded tracking and SLA visibility.
Partner on remediation strategy: Collaborate with stakeholders to design layered fixes, compensating controls, and sustainable hardening patterns for external assets.
Advance EASM capabilities: Develop tuning logic for discovery seeds and asset correlation. Continuously improve signal fidelity and automate common validation tasks.
Support VDP oversight: Provide governance for researcher communications, proof-of-fix validation, and SLA adherence.
Requirements
7+ years in vulnerability engineering or external attack surface security, with proven leadership in complex environments.
Hands-on experience with EASM platforms (e.g., Censys, Defender EASM, Cortex Xpanse, CyCognito, etc.) and strong understanding of internet-scale asset discovery.
Proficiency in scripting (Python, PowerShell, Bash) for automation and data wrangling; familiarity with SQL for enrichment tasks.
Strong knowledge of cloud security (AWS/Azure), PKI/TLS hygiene, DNS hardening, and external service posture.
Exceptional written and verbal communication—capable of translating technical risk into executive clarity and developer-ready guidance.
Nice-to-Have experience building prioritization models using EPSS/KEV and attack path concepts.
Familiarity with SaaS posture signals (SSPM) intersecting with external exposure.
Certifications such as OSCP, GWAPT, GPEN (or equivalent demonstrable skill); CISSP is a plus.
Deep expertise in validating advanced issues (authN/Z bypass, SSRF, injection, misconfigurations, cloud/API exposures) and producing actionable PoCs.
Benefits
Growth pathways into offensive security, vulnerability management, security architecture, or program ownership.
A technical leadership role helping to shape and influence EASM strategy, automation, and risk reduction across the enterprise.
Shift Maintenance Engineer troubleshooting and maintaining plant floor devices and ensuring optimal performance. Performing preventive and corrective maintenance with focus on mechanical and electrical systems, ensuring safety standards are met.
AV Multimedia Engineer in Swiss Re's Global Multimedia Operations Team. Responsible for daily AV services and implementing meeting room technologies in a dynamic environment.
Requirement Engineer working closely with Product Manager and Agile teams to manage requirements. Collaborate with stakeholders to gather, analyze, and document user stories.
Automation Factory Engineer responsible for high‑throughput automation delivery. Part of a collaborative team executing automation efforts in quality assurance at Ness Digital Engineering.
HPC Engineer designing, deploying, and maintaining high - performance computing environments at Honeywell. Collaborating with teams to optimize systems and enhance data processing capabilities.
Water Resources Engineer for Brisbane Water Team focusing on impactful projects in hydraulic and floodplain management. Collaborate with a supportive team to deliver sustainable water infrastructure.
Configuration Manager overseeing product configurations and modifications at Sogeclair in Toulouse. Collaborating with design, production, and clients to ensure product integrity and compliance.
Lead FAA certification strategy for complex in - flight entertainment systems at Thales. Ensure compliance and certification integrity across multiple aircraft communication projects.
Lead software architecture and engineering teams for fintech solutions at FIS. Drive innovation and mentor engineers in designing high‑availability software systems.
Global Steel Engineer designing and analyzing steel structures for international standards. Collaborating with global teams in construction and steel engineering projects.