> Markdown version of [/jobs/ext/191445-cyber-threat-management-analyst-specialist](https://www.wearedevelopers.com/jobs/ext/191445-cyber-threat-management-analyst-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Management Analyst, Specialist - **Company:** Vanguard - **Location:** Malvern, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Cloud Computing Security, Cyber Security, Query Languages, Intrusion Detection and Prevention, Python (Programming Language), Network Monitoring, Windows PowerShell, Kusto Query Language, Security Information and Event Management, SQL Databases, Mitre Att&ck, Cyber Threat Analysis, Cybercrime - **Published:** May 24, 2026 - **Apply:** https://www.juju.com/job/00000000g20mlt ## About the Role + Preferred3 - 5 years of experiencein threat hunting, detection engineering, incident response, or security operations. + Strong understanding ofthreat actor tactics, techniques, and procedures (TTPs)and modern attack methodologies. + Hands-on experience withenterprise telemetry and security platforms(EDR, SIEM, network monitoring, cloud security tools). + Proven application of theMITRE ATT&CK frameworkfor threat detection, gap analysis, and adversary mapping. + Proficiency inscripting and query languages(Python, PowerShell, KQL, SQL, or equivalent). + Experience withdata analysis and large-scale investigation workflows. + Strong written and verbal communication skills, with the ability to translate technical findings intobusiness-relevant risk. + Experience working incross-functional security teams(SOC, IR, Threat Intelligence, Detection Engineering). + Relevant certifications (e.g.,CISSP, GCFA, GCIH, GCDA, or equivalent) preferred. Special Factors ## Description Global Risk and Security(GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that Vanguard leaders and crew drive faster, stronger, risk-informed decisions. Within GR&S, theEnterprise Security and Fraud(ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource - by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core. Core Responsibilities + Lead proactive threat hunting operationsacross enterprise environments, including adversary emulations, live hunts, and investigative assessments. Identify anomalous behaviors and translate findings into actionable detections. + Apply hypothesis-driven hunting methodologies, leveraging threat intelligence, behavioral analytics, and the MITRE ATT&CK framework to identify gaps in detection and control coverage. + Analyze telemetry across the enterprise security stack(endpoint, network, identity, cloud, email, SIEM/XDR) and pivot across datasets to identify advanced threats and hidden attacker activity. + Identify and validate adversary techniques, mapping observed activity to ATT&CK and informing improvements to detection logic, alerting, and response workflows. + Enhance detection engineering effortsby developing, tuning, and validating rules, analytics, and behavioral detections based on hunt findings and adversary simulations. + Leverage scripting and automation(e.g., Python, PowerShell, KQL, SQL) to scale threat hunting activities, enrich data, and improve investigative efficiency. + Utilize advanced analytics and AI-assisted techniquesto accelerate the identification of suspicious or malicious activity. + Collaborate across CSOC and engineering teamsto validate findings, operationalize detections, and strengthen defensive capabilities. + Produce clear and actionable reporting, including hunt reports, detection gap analyses, and executive summaries that translate technical findings into business risk and recommended actions. + Support incident response when required, providing deep investigative expertise, threat context, and rapid escalation of critical findings. + Mentor and guide team members, sharing threat hunting methodologies, tooling expertise, and investigative techniques to improve overall team capability and maturity. + Continuously evaluate and improve hunt processes, tooling, and methodologies to advance threat hunting maturity and operational effectiveness. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)