Threat Emulation and Exploit Engineer

vanguard· The Vanguard Group, Inc.
Apply Now ↗
📍 Dallas/Ft. Worth, TX📍 Malvern, PAFull time

About this role

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.

Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.

Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.

Threat Emulation and Exploit Engineer:

  • Leads and responds to escalated cyber security alerts, cyber incidents, or related security investigations. Identifies real-time complex attack patterns and suggests mitigation strategies.
  • Leads the processes, tools and measures to monitor and detect compromises, risks, vulnerabilities, network security threats, tools and tactics used by modern and emerging threat actors. Facilitates security operations and incident response technologies and methodologies.
  • Develops, manages, maintains and enhances security controls (alerts, rules, policies, and signatures) for the security platforms.
  • Reviews the network environment for new and evolving cyber threats and providing preventive and remedial solutions. Identifies malicious activity by performing analysis on logs, traffic flows, and other investigative detective activities.
  • Conducts penetration testing, vulnerability assessments and threat modeling. Evaluates risks and makes recommendations.
  • Provides written assessments focused on threats, vulnerabilities, and technologies relevant to Vanguard Infrastructure.
  • Leads with IT and business teams to ensure prompt and effective distribution of findings so incidents are effectively addressed. Provides department support to the business on enterprise wide security initiatives and projects.
  • Mentors junior team members to improve their technical acumen
  • Participates in special projects and performs other duties as assigned.

What it takes:

  • Minimum of five years related work experience, with three years of experience in red teaming, adversary emulation, or penetration testing.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • Experience conducting in-depth technical analysis of vulnerabilities across diverse platforms and technologies, including replication of known exploits and development of proof-of-concept exploits to validate risk and impact.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • OSCP, CRTO, or an equivalent certification preferred.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Frequently Asked Questions

Is the salary disclosed for the Threat Emulation and Exploit Engineer position at vanguard?
The salary for this Threat Emulation and Exploit Engineer role at vanguard is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Threat Emulation and Exploit Engineer position at vanguard located?
This Threat Emulation and Exploit Engineer role at vanguard is based in Dallas/Ft. Worth, TX, Malvern, PA. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Threat Emulation and Exploit Engineer role at vanguard full-time or part-time?
This is listed as a Full time position. It is posted as a Threat Emulation and Exploit Engineer role in the The Vanguard Group, Inc. department at vanguard.
Which team or department does the Threat Emulation and Exploit Engineer at vanguard belong to?
This Threat Emulation and Exploit Engineer position is part of the The Vanguard Group, Inc. department at vanguard. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Threat Emulation and Exploit Engineer position at vanguard?
Click the "Apply Now" button on this page. You will be redirected to vanguard's official application portal hosted on workday where you can submit your application directly.
When was the Threat Emulation and Exploit Engineer job at vanguard posted?
This Threat Emulation and Exploit Engineer position at vanguard was posted on Sep 9, 2026. Apply as soon as possible — early applications are often reviewed first.
Threat Emulation and Exploit Engineer
vanguard
Apply for this role ↗

You'll be redirected to vanguard's official application page on Workday.