Application Security, Senior Analyst

Vanguard Group, Inc.

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in application security, secure code reviews, or security-focused software engineering.
  • Strong grasp of secure coding principles and OWASP Top 10 vulnerabilities.
  • Familiarity with modern software architectures, APIs, and CI/CD frameworks.
  • Experience with code review in languages like Java, C#, Python, and JavaScript/TypeScript.
  • Proficient with SAST tools such as Checkmarx and Veracode, and understanding of DevSecOps practices.
  • Hands-on experience with AI-assisted security tools in development workflows.
  • Excellent communication skills to convey security findings to technical teams.

Responsibilities

  • Conduct secure code reviews using both manual and AI tools to identify vulnerabilities.
  • Develop and refine AI-assisted review methodologies to enhance efficiency.
  • Validate vulnerability findings to minimize false positives and uncover hidden risks.
  • Create detailed technical reports with risk-based recommendations.
  • Work with development teams to interpret findings and suggest remediation steps.
  • Collaborate with security professionals across penetration testing and threat modeling.
  • Contribute to the enhancement of team methodologies and automation processes.

Benefits

  • Health, dental, and vision insurance options.
  • 401(k) plan with company match.
  • Flexible work schedule and remote work opportunities.
  • Professional development and training programs.
  • Wellness initiatives and employee assistance programs.
Full Job Description
Core Responsibilities
  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
  • Develops and optimizes prompts, workflows, and review methodologies that improve the effectiveness and repeatability of AI-assisted code review activities.
  • Validates and refines vulnerability findings, reducing false positives and identifying overlooked risks.
  • Produces clear technical reports and risk-based recommendations.
  • Partners with development teams to explain findings, assess risk, and provide actionable remediation guidance.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Contributes to team processes, methodologies, and automation initiatives.


Required Qualifications
  • Minimum of 5 years of related work experience in application security, secure code review, or software engineering with a security focus.
  • Strong understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
  • Understanding of modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
  • Experience reviewing Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Experience using SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
  • Hands-on experience using generative AI or AI-assisted developer/security tools as part of engineering, code review, security testing, or DevSecOps workflows.
  • Ability to communicate security findings and remediation guidance to developers and technical leadership
  • Undergraduate degree in a related field or an equivalent combination of training and experience.


Preferred Qualifications
  • Experience creating prompts, workflows, agents, or automations.
  • Experience leveraging large language models (LLMs) to improve security analysis, code review efficiency, vulnerability triage, or secure development workflows.
  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
  • Experience reviewing applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

Special Factors

Sponsorship
Vanguard is not offering visa sponsorship for this position.

Similar Jobs

More Jobs at Vanguard Group, Inc.

More Information Technology Jobs

Find similar Application Security, Senior Analyst jobs: