Core Responsibilities
- Help define and implement Application Security strategy and secure SDLC practices across the organization.
- Partner with development teams to establish security requirements early in the software development lifecycle.
- Design and implement security controls and guardrails that support continuous and secure application delivery.
- Develop and maintain security standards and architecture patterns for APIs, cloud-native applications, containers, serverless platforms, and emerging technologies.
- Assess, prioritize, and drive remediation of application and infrastructure vulnerabilities identified through SAST, SCA, IAST, DAST, container, and cloud security solutions.
- Configure, integrate, and onboard teams to application security tools across CI/CD environments.
- Automate security processes and controls to improve efficiency, scalability, and developer adoption.
- Conduct security reviews, threat analysis, and risk assessments for new and existing applications.
- Partner with developers to identify root causes of vulnerabilities and provide remediation guidance.
- Ensure application security solutions are properly implemented, integrated, and delivering expected coverage.
- Develop security metrics, reporting, and dashboards to measure program effectiveness and maturity.
- Provide secure coding guidance, technical consultation, and training to development and cloud engineering teams.
- Maintain documentation for security controls, processes, standards, and operational procedures.
- Stay current with industry trends, emerging threats, and guidance from organizations such as OWASP, NIST, and SANS.
- Support enterprise application security standards, policies, and governance initiatives.
Qualifications
- Minimum of five years related work experience.
- Undergraduate degree in a related field or the equivalent combination of training and experience.
- Strong experience in Application Security, Secure SDLC, DevSecOps, or Software Engineering.
- Hands-on experience securing CI/CD pipelines and modern application development environments.
- Experience with application security technologies including SAST, SCA, IAST, DAST, API Security, and Container Security.
- Experience working with cloud platforms and cloud-native technologies.
- Strong understanding of secure coding principles, vulnerability management, and application risk assessment.
- Experience partnering with development teams to remediate security findings.
- Experience designing and implementing security automation solutions.
- Strong communication, collaboration, and problem-solving skills.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.