Application Security, Analyst

@ The Vanguard Group, Inc.
The Vanguard Group, Inc.thevanguardgroup,inc..com

Application Security, Analyst

Malvern, PA
Posted 1 day ago

About the job

Vanguard focuses on long-term financial wellbeing and innovative solutions. This role emphasizes application security, secure coding, and AI tools to protect and enhance software systems.

Requirements

  • 3+ years in application security
  • Secure coding principles knowledge
  • Experience with APIs and cloud-native apps
  • Proficiency in Java, Python, etc
  • Familiar with SAST tools

Qualifications

  • Bachelor's degree or equivalent
  • Strong communication skills
  • Understanding of SDLC and DevSecOps
  • Experience with AI or code review tools
  • Analytical and team-oriented

Full job description


Core Responsibilities

  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
  • Utilizes established prompts, workflows, and review methodologies to support AI-assisted code review activities.
  • Reviews and validates vulnerability findings identified through automated and AI-assisted analysis.
  • Produces clear technical reports and risk-based recommendations.
  • Works with development teams to communicate findings and support remediation efforts.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Supports team processes, methodologies, and automation initiatives.

Required Qualifications

  • Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus.
  • Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
  • Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
  • Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
  • Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities.
  • Ability to communicate security findings and remediation guidance to developers and technical teams.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.


Preferred Qualifications

  • Experience creating prompts, workflows, agents, or automations
  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
  • Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Show full description