Senior Application Security Engineer

Vanguard

Malvern (Chester County)

Hybrid

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vanguard is seeking an Application Security Specialist to help secure the SDLC, drive API/container/application security testing, and implement guardrails for secure development across projects. You will collaborate with developers to enable secure and continuous delivery of applications, contributing to risk reduction and improved security visibility.

The role requires expertise in CICD, secure software development, and best practices, with the ability to mentor teams on secure development and

Qualifications

  • Undergraduate degree in a related field or equivalent combination of training and experience.
  • Strong experience deploying and operating DAST tools to include managing team onboarding, authentication setup, and CI/CD integration.
  • Experience with other well-known application security tools (SAST, SCA, IAST, RASP, etc.)
  • Strong knowledge of application development, build, and deployment processes (development, IDEs, repositories, branching, pipelines, cloud, containers, serverless, etc.).
  • Familiarity with industry standards such as NIST, OWASP, and MITRE.
  • Relevant certifications in application development, security, application security, DevSecOps, or cloud are a plus.

Responsibilities

  • Utilize application development, deployment, and security experience to help guide Application Security strategy and secure the software development lifecycle (SDLC)
  • Drive API, Container, and Application Security testing initiatives, including DAST and other security validation capabilities, to improve security coverage, identify vulnerabilities, and support timely remediation.
  • Develop strategies to secure current and emerging technologies (containers, serverless, API, AI/ML).
  • Provide hands-on engineering support for security incidents, threat events, vulnerability management, and control improvements to strengthen Enterprise application security posture.
  • Gather and report metrics from Application Security solutions and processes to provide meaningful insights into security coverage, risk reduction, and program maturity.
  • Create and maintain technical standards, operational procedures, and supporting documentation for Application Security services by leveraging guidance from organizations such as NIST, OWASP, and SANS.
  • Provide technical mentorship and training to development and cloud engineering teams on secure development practices for API, Container security, and vulnerability remediation.
  • Implement, optimize, and operationalize Application Security solutions to improve risk visibility, security coverage, and developer adoption.
  • Drive automation and security capabilities that improve developer experience, streamline security processes, and align Application Security solutions with enterprise security and technology goals.
  • Stay informed on emerging Application Security trends, technologies, attack techniques, and industry best practices to continuously enhance Vanguard's security posture.

Skills

CI/CD integration
Secure development
Threat modeling

Education

Bachelor's degree in related field

Tools

DAST tools
SAST
SCA
IAST
RASP

Job description

The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application Security Specialist, you will play a pivotal role in ensuring the security and compliance of the Vanguard software development lifecycle (SDLC). You will help develop strategy, implement new technology, maintain technical controls, assess vulnerabilities, and collaborate with developers to ensure that the proper guardrails are in place to enable the continuous and secure delivery of applications.


This role requires expertise in CICD, Secure software development, and application security best practices to improve developer experience and delivery of our end users


Key Responsibilities


  • Utilize application development, deployment, and security experience to help guide Application Security strategy and secure the software development lifecycle (SDLC)

  • Drive API, Container, and Application Security testing initiatives, including DAST and other security validation capabilities, to improve security coverage, identify vulnerabilities, and support timely remediation.

  • Develop strategies to secure current and emerging technologies (containers, serverless, API, AI/ML).

  • Provide hands-on engineering support for security incidents, threat events, vulnerability management, and control improvements to strengthen Enterprise application security posture.

  • Gather and report metrics from Application Security solutions and processes to provide meaningful insights into security coverage, risk reduction, and program maturity.

  • Create and maintain technical standards, operational procedures, and supporting documentation for Application Security services by leveraging guidance from organizations such as NIST, OWASP, and SANS.

  • Provide technical mentorship and training to development and cloud engineering teams on secure development practices for API, Container security, and vulnerability remediation.

  • Implement, optimize, and operationalize Application Security solutions to improve risk visibility, security coverage, and developer adoption.

  • Drive automation and security capabilities that improve developer experience, streamline security processes, and align Application Security solutions with enterprise security and technology goals.

  • Stay informed on emerging Application Security trends, technologies, attack techniques, and industry best practices to continuously enhance Vanguard's security posture.


Qualifications


  • Undergraduate degree in a related field or equivalent combination of training and experience.

  • Strong experience deploying and operating DAST tools to include managing team onboarding, authentication setup, and CI/CD integration.

  • Experience with other well-known application security tools (SAST, SCA, IAST, RASP, etc.)

  • Strong knowledge of application development, build, and deployment processes (development, IDEs, repositories, branching, pipelines, cloud, containers, serverless, etc.).

  • Familiarity with industry standards such as NIST, OWASP, and MITRE.

  • Relevant certifications in application development, security, application security, DevSecOps, or cloud are a plus.


Special Factor(s)

Sponsorship

Vanguard is not offering visa sponsorship for this position.


Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.


About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.


To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.


How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Charlotte (NC)

Hybrid
USD 110,000 - 150,000
Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Town of Charlotte (NY)

Hybrid
USD 120,000 - 180,000
Application Engineer - II
Application Engineer - II

Worky • Dallas (TX)

Hybrid
USD 110,000 - 140,000
Application Engineer - III
Application Engineer - III

Vanguard • Malvern

Hybrid
USD 140,000 - 190,000
Full-Stack Application Engineer (AWS)
Full-Stack Application Engineer (AWS)

The Vanguard Group • Dallas (TX)

Hybrid
USD 110,000 - 150,000
Technology Leadership Program - Risk & Security Engineer (PA)
Technology Leadership Program - Risk & Security Engineer (PA)

The Vanguard Group • Malvern

Hybrid
USD 85,000 - 105,000
Performance bonuses
401(k) matching above average
Paid time off
+2
Application Engineer - III
Application Engineer - III

The Vanguard Group • Malvern

Hybrid
USD 120,000 - 150,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Dallas (TX)

Hybrid
USD 180,000 - 240,000
Manager, Offensive Security Operations & Engineering
Manager, Offensive Security Operations & Engineering

Vanguard • Town of Charlotte (NY)

Hybrid
USD 180,000 - 260,000