> Markdown version of [/jobs/ext/2965327-web-application-and-fraud-offensive-security-specialist](https://www.wearedevelopers.com/jobs/ext/2965327-web-application-and-fraud-offensive-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Application and Fraud - Offensive Security Specialist - **Company:** Vanguard - **Location:** Malvern, PA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Application Testing, Fraud Prevention and Detection, Web Applications, Web Testing, GWAPT, Vulnerability Analysis - **Published:** September 17, 2026 - **Apply:** http://www.vanguardjobs.com/job/23878715/web-application-and-fraud-offensive-security-specialist-pennsylvania-statewide/?utm_medium=%22mcloud%2Djobads%22&utm_campaign=Technology&utm_content=Web%20Application%20and%20Fraud%20%2D%20Offensive%20Security%20Specialist&utm_term=182215 ## About the Role * OSCP, OSWA, OSWE, CWES, GWAPT, PWPP, or equivalent professional level web application testing certification required * CISSP preferred * Minimum of five years related work experience, with three years' experience in threat analysis. * Undergraduate degree in a related field or the equivalent combination of training and experience. * Experience testing controls and fostering collaboration in an effort to remediate findings from assessments. * Experience assessing production web applications. ## Description The Offensive Security Analyst on the Web Application & Fraud Testing team conducts threat-driven security testing of Vanguard's critical client-facing web applications. This role applies nascent adversarial TTPs to validate whether existing controls detect and prevent the fraud tradecraft currently emerging in the threat landscape. Findings from this work directly inform detection improvements and control remediation across the enterprise. Core Responsibilities * Beyond traditional application testing, this operator will help design and execute realistic scenarios that stress-test cyber fraud detection and response, and partner with defensive teams in exercises to validate that our controls fire when they should. * Assesses the risk and business impact of identified findings, applying defensible severity ratings based on likelihood, exploitability, and exposure. Thinks critically about remediation guidance so that recommendations to partner teams are practical, proportionate to the risk, and address root cause rather than symptom. * Fosters and supports junior talent through informal leadership and coaching. Mentors junior team members to improve their technical acumen. * Applies emerging adversarial tradecraft against client facing web application infrastructure through rigorous control validation to improve reactive and proactive threat driven operations. * Conducts penetration testing, vulnerability assessments and threat modeling. Evaluates risks and makes recommendations. * Provides written assessments focused on threats, vulnerabilities, and technologies relevant to Vanguard Infrastructure. * Leads with IT and business teams to ensure prompt and effective distribution of findings so incidents are effectively addressed. Provides department support to the business on enterprise-wide security initiatives and projects. * Participates in special projects and performs other duties as assigned. ## Related Videos - [Plants vs. Thieves: Automated Tests in the World of Web Security](https://www.wearedevelopers.com/videos/1282-plants-vs-thieves-automated-tests-in-the-world-of-web-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Is Flutter ready for the web yet? - A live coding comparison between Flutter and React](https://www.wearedevelopers.com/videos/401-is-flutter-ready-for-the-web-yet-a-live-coding-comparison-between-flutter-and-react) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)