Full-Time

Offensive Security Analyst

Confirmed live in the last 24 hours

Vanguard

Vanguard

10,001+ employees

Client-owned investment management firm offering low-cost funds

Fintech
Financial Services

Mid

No H1B Sponsorship

Dallas, TX, USA + 1 more

More locations: Malvern, PA, USA

Hybrid working model requires in-office presence.

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Bash
Python
JavaScript
HTML/CSS
Requirements
  • Proven experience in web application penetration testing, with a strong background in identifying vulnerabilities, performing manual testing, and using automated tools.
  • Deep understanding of web application security concepts, including OWASP Top 10, secure coding practices, authentication and authorization mechanisms, session management, and input validation.
  • Proficiency in using security tools such as Burp Suite, OWASP ZAP, Metasploit, and other custom scripts for penetration testing.
  • Strong knowledge of web technologies such as HTML, JavaScript, CSS, AJAX, and HTTP/HTTPS protocols.
  • Hands-on experience with exploiting common web vulnerabilities like SQL injection, XSS, CSRF, SSRF, RCE, XXE, and IDOR.
  • Familiarity with security testing methodologies, frameworks, and standards (e.g., OWASP, PTES, NIST, MITRE ATT&CK).
  • Strong scripting and programming skills (e.g., Python, JavaScript, Bash, PowerShell) to develop custom exploits and automate tasks.
  • Strong analytical and problem-solving skills, with the ability to think like an attacker and identify creative ways to exploit vulnerabilities.
  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Web Assessor (OSWA)
  • Offensive Security Web Expert (OSWE)
  • GIAC Web Application Penetration Tester (GWAPT)
Responsibilities
  • Perform comprehensive web application penetration testing and vulnerability assessments across internal and external web applications.
  • Identify, exploit, and document security vulnerabilities in web applications, APIs, and cloud environments, providing detailed risk assessments and recommendations for remediation.
  • Simulate real-world attacks to evaluate application security controls and detect potential threats.
  • Collaborate with development and security teams to offer actionable guidance on fixing vulnerabilities and strengthening security posture.
  • Prepare detailed penetration testing reports and clearly communicate findings to technical and non-technical stakeholders.
  • Continuously research and stay current on emerging vulnerabilities, security trends, and attack vectors in the web application landscape.
  • Assist in security incident response by identifying and analyzing vulnerabilities that may be exploited during an attack.
  • Conduct threat modeling and provide input on security requirements for application development.
  • Develop and maintain custom scripts and tools to enhance penetration testing efforts.
  • Mentor junior security team members and contribute to the overall knowledge base of the security team.

Vanguard provides financial services with a focus on investment management. The company offers a variety of products, including mutual funds, exchange-traded funds (ETFs), individual retirement accounts (IRAs), and 401k rollovers, aimed at individual investors, financial advisors, and institutional clients. Vanguard's unique ownership structure means it is owned by its funds, which are in turn owned by the clients, allowing it to prioritize the needs of its investors over external shareholders. This model enables Vanguard to offer low-cost investment options, as it primarily earns revenue through management fees that are generally lower than industry standards. Additionally, Vanguard provides personalized investment advisory services, charging fees based on the assets managed. The company aims to help clients grow their wealth and achieve their financial goals through effective investment strategies, with many of its funds performing competitively over time.

Company Stage

N/A

Total Funding

N/A

Headquarters

Kline Township, Pennsylvania

Founded

1975

Simplify Jobs

Simplify's Take

What believers are saying

  • Vanguard's expansion into active fixed income ETFs and international dividend growth funds demonstrates its commitment to offering diverse and innovative investment options.
  • The company's strong performance history, with many funds outperforming peer averages over a decade, provides a compelling reason for investors to trust Vanguard.
  • Strategic partnerships, such as the collaboration with American Express for financial advice services, enhance Vanguard's value proposition and market reach.

What critics are saying

  • The competitive landscape in financial services is intense, with major players like Schwab and Fidelity posing significant challenges.
  • Vanguard's reliance on low-cost fees may pressure profit margins, especially in volatile market conditions.

What makes Vanguard unique

  • Vanguard's unique client-owned structure ensures that the company operates solely in the best interest of its investors, unlike traditional firms driven by external shareholders.
  • The company's commitment to low-cost investment options, with fees generally lower than industry averages, sets it apart in the competitive financial services market.
  • Vanguard's broad range of investment products, including mutual funds, ETFs, and personalized advisory services, caters to a diverse clientele from individual investors to large institutions.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Best-in-class medical, dental & vision coverage

Onsite health clinic & fitness center

Health Smart Rewards program

Vanguard Retirement Savings Plan

Education Benefits

PTO

Family Planning Benefist

Parental leave

Personal development opportunities

Volunteer Time Off