Built because the prioritization problem is unsolved

Vendrsec was founded in 2023 by a security engineer who spent years running manual triage processes and building internal tooling to replicate what every scanner was missing.

Why we built this

Ethan Park spent six years in application security and infrastructure vulnerability management at two Bay Area fintech companies. In both roles, the same pattern repeated: export Qualys or Tenable findings to a spreadsheet, manually cross-reference against an asset criticality doc someone built in 2021, then spend two hours in a sprint planning meeting arguing about what to fix first. The output was usually wrong — driven by whoever argued loudest, not by which findings had active exploits targeting internet-facing production assets.

By 2023 Q1, Ethan had written a Python script that answered those questions automatically: pull Qualys findings, query the CISA KEV API, cross-reference against an asset inventory with business function tags, output a ranked list. The script took 90 seconds. The meeting it replaced took two hours. Three other teams within his company asked to use it. That conversation became Vendrsec.

Vendrsec is not a scanner. We don't compete with Qualys, Tenable, or Wiz — we read their output and add the context they deliberately leave out: your asset topology, your business function tags, and whether an exploit kit actually exists for this CVE in the wild right now. The prioritization reasoning that every security team was doing manually is what we automate.

The team

Ethan Park, CEO and Co-Founder of Vendrsec

Ethan Park

CEO & Co-Founder

Six years in application security and vulnerability management at Bay Area fintech companies. Built the internal CVE prioritization script that became Vendrsec. Focused on the product and customer-facing work.

Mara Osei, CTO and Co-Founder of Vendrsec

Mara Osei

CTO & Co-Founder

Backend infrastructure and distributed systems background. Designed and built the network reachability graph engine at Vendrsec's core — the component that maps lateral movement paths and blast radius across asset topologies.

James Calvo, Head of Security Research at Vendrsec

James Calvo

Head of Security Research

Five years in threat intelligence, tracking CVE exploitation timelines and exploit-kit activity. Owns Vendrsec's CISA KEV correlation pipeline, NVD ingestion, and threat-intel feed connectors that drive real-time exploit scoring.

How we work

  • Practitioner-first: we build for security engineers, not security theater. Every feature ships with a specific use case from a real vulnerability management workflow.

  • Specific over vague: every feature does one thing precisely. We don’t use language models to rewrite CVE descriptions or generate security summaries — that’s not what moves a finding from open to closed. We add logic to rank findings correctly and generate the ticket that gets it fixed.

  • Transparent about limitations: we show what Vendrsec doesn’t know as clearly as what it does. If a finding can’t be enriched due to missing asset data, we say so — we don’t silently omit it from the queue.

We’re a small team with a specific problem

We don’t have open roles listed publicly. When we hire, it’s for a specific gap from our own network. If you have hands-on experience in vulnerability management, security engineering, or backend graph systems — and understand why scanner output alone is not a prioritization strategy — reach out directly.

Contact Ethan

Talk to us directly

Questions about Vendrsec, your specific scanner environment, or how we built the scoring model — we’re engineers, we like detailed questions.

Contact Ethan Request Access