Senior Application Security Engineer

Vanguard Group, Inc.

$120K — $140K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Undergraduate degree in a related field or equivalent experience.
  • Strong experience with DAST tools, including onboarding and CI/CD integration.
  • Experience with additional application security tools like SAST and IAST.
  • Solid understanding of development and deployment processes including cloud and containers.
  • Familiarity with NIST, OWASP, and MITRE standards.
  • Relevant security or DevSecOps certifications are a plus.

Responsibilities

  • Guide Application Security strategy and secure the SDLC using development experience.
  • Drive API, Container, and Application Security testing initiatives to identify and remediate vulnerabilities.
  • Develop strategies for securing emerging technologies such as AI/ML and serverless.
  • Provide engineering support for security incidents and strengthen security controls.
  • Report metrics to offer insights into security coverage and program maturity.
  • Create and maintain technical standards and documentation for Application Security.
  • Mentor development teams on secure development practices and vulnerability remediation.
  • Implement and optimize Application Security solutions to enhance risk visibility and developer adoption.
  • Stay updated on Application Security trends and best practices to enhance security posture.

Benefits

  • Comprehensive health, dental, and vision insurance.
  • Retirement savings plan with company match.
  • Generous paid time off policy.
  • Professional development opportunities including training and certifications.
  • Flexible work arrangements to support work-life balance.
Full Job Description
The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application Security Specialist, you will play a pivotal role in ensuring the security and compliance of the Vanguard software development lifecycle (SDLC). You will help develop strategy, implement new technology, maintain technical controls, assess vulnerabilities, and collaborate with developers to ensure that the proper guardrails are in place to enable the continuous and secure delivery of applications.

This role requires expertise in CICD, Secure software development, and application security best practices to improve developer experience and delivery of our security services to our end users

Key Responsibilities
  • Utilize application development, deployment, and security experience to help guide Application Security strategy and secure the software development lifecycle (SDLC)
  • Drive API, Container, and Application Security testing initiatives, including DAST and other security validation capabilities, to improve security coverage, identify vulnerabilities, and support timely remediation.
  • Develop strategies to secure current and emerging technologies (containers, serverless, API, AI/ML).
  • Provide hands-on engineering support for security incidents, threat events, vulnerability management, and control improvements to strengthen Enterprise application security posture.
  • Gather and report metrics from Application Security solutions and processes to provide meaningful insights into security coverage, risk reduction, and program maturity.
  • Create and maintain technical standards, operational procedures, and supporting documentation for Application Security services by leveraging guidance from organizations such as NIST, OWASP, and SANS.
  • Provide technical mentorship and training to development and cloud engineering teams on secure development practices for API, Container security, and vulnerability remediation.
  • Implement, optimize, and operationalize Application Security solutions to improve risk visibility, security coverage, and developer adoption.
  • Drive automation and security capabilities that improve developer experience, streamline security processes, and align Application Security solutions with enterprise security and technology goals.
  • Stay informed on emerging Application Security trends, technologies, attack techniques, and industry best practices to continuously enhance Vanguard's security posture.


Qualifications
  • Undergraduate degree in a related field or equivalent combination of training and experience.
  • Strong experience deploying and operating DAST tools to include managing team onboarding, authentication setup, and CI/CD integration.
  • Experience with other well-known application security tools (SAST, SCA, IAST, RASP, etc.)
  • Strong knowledge of application development, build, and deployment processes (development, IDEs, repositories, branching, pipelines, cloud, containers, serverless, etc.).
  • Familiarity with industry standards such as NIST, OWASP, and MITRE.
  • Relevant certifications in application development, security, application security, DevSecOps, or cloud are a plus.


Special Factor(s)

Sponsorship

Vanguard is not offering visa sponsorship for this position.

Special Factors

Sponsorship
Vanguard is not offering visa sponsorship for this position.

Similar Jobs

More Jobs at Vanguard Group, Inc.

More Information Technology Jobs

Find similar Senior Application Security Engineer jobs: