Application Security, Senior Analyst

Vanguard Group, Inc.

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in application security, secure code review, or software engineering with a security focus.
  • Strong grasp of secure coding principles and vulnerabilities (OWASP Top 10).
  • Familiarity with modern software architectures, APIs, and CI/CD pipelines.
  • Proficient in reviewing languages like Java, C#, Python, JavaScript/TypeScript, or Go.
  • Experience with SAST tools like Checkmarx or Veracode and knowledge of DevSecOps practices.
  • Hands-on experience with AI-assisted tools in security workflows.
  • Effective communication of security issues to technical teams.

Responsibilities

  • Conduct manual and AI-assisted secure code reviews of application code.
  • Enhance and automate workflows to boost AI code review effectiveness.
  • Assess and refine vulnerability findings to minimize false positives.
  • Create detailed reports with risk assessments and recommendations.
  • Work closely with development teams to provide remediation guidance.
  • Collaborate with security teams including penetration testers and modelers.
  • Drive contributions to team methodologies and automation projects.

Benefits

  • Hybrid working model promoting flexibility and collaboration.
  • Supportive, mission-driven culture focused on client outcomes.
  • Opportunities for in-person learning and team building.
Full Job Description

Core Responsibilities

  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
  • Develops and optimizes prompts, workflows, and review methodologies that improve the effectiveness and repeatability of AI-assisted code review activities.
  • Validates and refines vulnerability findings, reducing false positives and identifying overlooked risks.
  • Produces clear technical reports and risk-based recommendations.
  • Partners with development teams to explain findings, assess risk, and provide actionable remediation guidance.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Contributes to team processes, methodologies, and automation initiatives.

Required Qualifications

  • Minimum of 5 years of related work experience in application security, secure code review, or software engineering with a security focus.
  • Strong understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
  • Understanding of modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
  • Experience reviewing Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Experience using SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
  • Hands-on experience using generative AI or AI-assisted developer/security tools as part of engineering, code review, security testing, or DevSecOps workflows.
  • Ability to communicate security findings and remediation guidance to developers and technical leadership
  • Undergraduate degree in a related field or an equivalent combination of training and experience.

Preferred Qualifications

  • Experience creating prompts, workflows, agents, or automations.
  • Experience leveraging large language models (LLMs) to improve security analysis, code review efficiency, vulnerability triage, or secure development workflows.
  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
  • Experience reviewing applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Similar Jobs

More Jobs at Vanguard Group, Inc.

More Information Technology Jobs

Find similar Application Security, Senior Analyst jobs: