Application Security, Senior Analyst

Vanguard

Malvern (Chester County)

Hybrid

USD 130,000 - 180,000

Full time

46 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Vanguard is seeking an experienced application security engineer to lead manual and AI-assisted code reviews across modern stacks. You will develop prompts and workflows to improve the accuracy and efficiency of security reviews.

The role requires deep OWASP knowledge, SAST tool experience, and the ability to communicate findings to developers and leadership. A hybrid work model in the United States is offered, with collaboration across security teams.

Qualifications

  • Minimum of 5 years of work experience in application security or secure code review.
  • Strong understanding of secure coding principles, OWASP Top 10 and secure SDLC.
  • Experience with modern software architectures, APIs, cloud-native apps, and CI/CD.
  • Experience reviewing Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Experience using SAST tools (Checkmarx, Fortify, Veracode, Semgrep, SonarQube).
  • Hands-on experience with AI-assisted developer/security tools in engineering workflows.
  • Ability to communicate security findings to developers and leadership.
  • Undergraduate degree in a related field or equivalent.

Responsibilities

  • Performs manual and AI-assisted secure code reviews across modern application stacks.
  • Develops and optimises prompts, workflows, and review methodologies for AI-assisted reviews.
  • Validates and refines vulnerability findings, reducing false positives.
  • Produces clear technical reports and risk-based recommendations.
  • Partners with development teams to explain findings and remediation guidance.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Contributes to team processes, methodologies, and automation initiatives.

Skills

Secure coding principles
OWASP Top 10 knowledge
Languages: Java
Languages: C#
Languages: Python
Languages: JavaScript/TypeScript
Languages: Go
AI-assisted review experience
Communication to developers

Education

Bachelor's degree in a related field

Tools

Checkmarx
Fortify
Veracode
Semgrep
SonarQube

Job description

Core Responsibilities


  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.

  • Develops and optimises prompts, workflows, and review methodologies that improve the effectiveness and repeatability of AI-assisted code review activities.

  • Validates and refines vulnerability findings, reducing false positives and identifying overlooked risks.

  • Produces clear technical reports and risk-based recommendations.

  • Partners with development teams to explain findings, assess risk, and provide actionable remediation guidance.

  • Collaborates with penetration testers, threat modelers, and application security teams.

  • Contributes to team processes, methodologies, and automation initiatives.


Required Qualifications


  • Minimum of 5 years of related work experience in application security, secure code review, or software engineering with a security focus.

  • Strong understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.

  • Understanding of modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.

  • Experience reviewing Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.

  • Experience using SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices

  • Hands‑on experience using generative AI or AI-assisted developer/security tools as part of engineering, code review, security testing, or DevSecOps workflows.

  • Ability to communicate security findings and remediation guidance to developers and technical leadership

  • Undergraduate degree in a related field or an equivalent combination of training and experience.


Preferred Qualifications


  • Experience creating prompts, workflows, agents, or automations.

  • Experience leveraging large language models (LLMs) to improve security analysis, code review efficiency, vulnerability triage, or secure development workflows.

  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.

  • Experience reviewing applications that utilise machine learning, generative AI, agentic AI, or AI‑enabled business processes.


Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.


About Vanguard

At Vanguard, we don't just have a mission-we're on a mission.


To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.


How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security, Senior Analyst
Application Security, Senior Analyst

The Vanguard Group • Malvern

Hybrid
USD 120,000 - 190,000
Application Security, Senior Analyst
Application Security, Senior Analyst

Vanguard • Town of Charlotte (NY)

Hybrid
USD 140,000 - 190,000
Application Security, Specialist
Application Security, Specialist

The Vanguard Group • Malvern

Hybrid
USD 120,000 - 190,000
Application Security, Specialist
Application Security, Specialist

The Vanguard Group • Lees (PA)

Hybrid
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Charlotte (NC)

Hybrid
USD 110,000 - 160,000
Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Malvern

Hybrid
USD 120,000 - 160,000
Application Engineering Technical Lead - II
Application Engineering Technical Lead - II

Vanguard • Dallas (TX)

Hybrid
USD 140,000 - 170,000
Hybrid work model
Application Security, Specialist
Application Security, Specialist

Vanguard • Town of Charlotte (NY)

Hybrid
USD 140,000 - 180,000
Health and wellness benefits
Hybrid work model
Pioneer/long-term investment in your未来
Application Engineering Technical Lead - II
Application Engineering Technical Lead - II

The Vanguard Group • United States

Hybrid
USD 160,000 - 230,000
Senior Specialist, Control Assurance
Senior Specialist, Control Assurance

Vanguard • Malvern

Hybrid
USD 140,000 - 190,000