About The Position

We're seeking a seasoned Senior Vulnerability Engineer to lead advanced attribution and engineering efforts across our External Attack Surface Management (EASM) program. This role focuses on identifying and engineering solutions for vulnerabilities in internet-facing assets, ensuring robust external security posture at scale. While you'll maintain oversight of VDP workflows, your primary mission is to drive EASM maturity through automation, adversarial validation, and strategic remediation partnerships. This Hybrid Role (in office Tues-Wed-Thurs), can be based in Charlotte, NC, Dallas, TX, or Malvern, PA (HQ).

Requirements

  • 7+ years in vulnerability engineering or external attack surface security, with proven leadership in complex environments.
  • Hands-on experience with EASM platforms (e.g., Censys, Defender EASM, Cortex Xpanse, CyCognito, etc.) and strong understanding of internet-scale asset discovery.
  • Proficiency in scripting (Python, PowerShell, Bash) for automation and data wrangling; familiarity with SQL for enrichment tasks.
  • Strong knowledge of cloud security (AWS/Azure), PKI/TLS hygiene, DNS hardening, and external service posture.
  • Exceptional written and verbal communication-capable of translating technical risk into executive clarity and developer-ready guidance.

Nice To Haves

  • Experience building prioritization models using EPSS/KEV and attack path concepts.
  • Familiarity with SaaS posture signals (SSPM) intersecting with external exposure.
  • Certifications such as OSCP, GWAPT, GPEN (or equivalent demonstrable skill); CISSP is a plus.
  • Deep expertise in validating advanced issues (authN/Z bypass, SSRF, injection, misconfigurations, cloud/API exposures) and producing actionable PoCs.

Responsibilities

  • Lead EASM validation and engineering: Investigate and reproduce findings from EASM platforms (e.g., exposed services, misconfigurations, weak crypto, DNS issues, leaked assets). Engineer and maintain repeatable validation processes and automation to confirm exploitability and business impact.
  • Architect prioritization logic: Partner with VM stakeholder to apply exploitability signals (EPSS, KEV, public exploit availability), asset criticality, and exposure windows to drive risk-based prioritization.
  • Engineer attribution and routing workflows: Build logic to deduplicate, attribute, and route findings across inventories, scanner outputs, and historical exceptions. Ensure single-threaded tracking and SLA visibility.
  • Partner on remediation strategy: Collaborate with stakeholders to design layered fixes, compensating controls, and sustainable hardening patterns for external assets.
  • Advance EASM capabilities: Develop tuning logic for discovery seeds and asset correlation. Continuously improve signal fidelity and automate common validation tasks.
  • Support VDP oversight: Provide governance for researcher communications, proof-of-fix validation, and SLA adherence.

Benefits

  • A technical leadership role helping to shape and influence EASM strategy, automation, and risk reduction across the enterprise.
  • Growth pathways into offensive security, vulnerability management, security architecture, or program ownership.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Industry

Funds, Trusts, and Other Financial Vehicles

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service