Application Security, Analyst

Vanguard Group, Inc.

• $95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 3 years experience in application security or secure coding
  • Knowledge of secure coding and vulnerabilities (OWASP Top 10)
  • Familiarity with modern software architectures and CI/CD
  • Proficient in programming languages like Java, Python, or Go
  • Experience with SAST tools (Checkmarx, Fortify, etc.)
  • Understanding of DevSecOps practices and secure SDLC
  • Strong communication skills for technical findings

Responsibilities

  • Conduct manual and AI-assisted secure code reviews
  • Implement established prompts and workflows for code analysis
  • Validate automated vulnerability findings
  • Create detailed technical reports with risk recommendations
  • Collaborate with development teams on findings and remediation
  • Work alongside penetration testers and application security teams
  • Support automation and team processes in security initiatives

Benefits

  • Opportunity to work with innovative AI-assisted technologies
  • Collaboration with cross-functional teams to enhance security practices
  • Open environment for professional development
  • Engagement with modern application stacks and architectures
  • Exposure to cutting-edge tools and methodologies in security
Full Job Description

Core Responsibilities

  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
  • Utilizes established prompts, workflows, and review methodologies to support AI-assisted code review activities.
  • Reviews and validates vulnerability findings identified through automated and AI-assisted analysis.
  • Produces clear technical reports and risk-based recommendations.
  • Works with development teams to communicate findings and support remediation efforts.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Supports team processes, methodologies, and automation initiatives.

Required Qualifications

  • Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus.
  • Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
  • Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
  • Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
  • Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities.
  • Ability to communicate security findings and remediation guidance to developers and technical teams.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.


Preferred Qualifications

  • Experience creating prompts, workflows, agents, or automations
  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
  • Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

Similar Jobs

More Jobs at Vanguard Group, Inc.

More Information Technology Jobs

Find similar Application Security, Analyst jobs: