Application Security, Senior Analyst

The Vanguard Group
  • Charlotte, Pennsylvania
    3 days ago

    Job Description

    Core Responsibilities

    • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
    • Develops and optimizes prompts, workflows, and review methodologies that improve the effectiveness and repeatability of AI-assisted code review activities.
    • Validates and refines vulnerability findings, reducing false positives and identifying overlooked risks.
    • Produces clear technical reports and risk-based recommendations.
    • Partners with development teams to explain findings, assess risk, and provide actionable remediation guidance.
    • Collaborates with penetration testers, threat modelers, and application security teams.
    • Contributes to team processes, methodologies, and automation initiatives.

    Required Qualifications

    • Minimum of 5 years of related work experience in application security, secure code review, or software engineering with a security focus.
    • Strong understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
    • Understanding of modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
    • Experience reviewing Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
    • Experience using SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
    • Hands-on experience using generative AI or AI-assisted developer/security tools as part of engineering, code review, security testing, or DevSecOps workflows.
    • Ability to communicate security findings and remediation guidance to developers and technical leadership
    • Undergraduate degree in a related field or an equivalent combination of training and experience.

    Preferred Qualifications

    • Experience creating prompts, workflows, agents, or automations.
    • Experience leveraging large language models (LLMs) to improve security analysis, code review efficiency, vulnerability triage, or secure development workflows.
    • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
    • Experience reviewing applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

    Special Factors

    Sponsorship

    Vanguard is not offering visa sponsorship for this position.

    About Vanguard

    At Vanguard, we don't just have a mission—we're on a mission.

    To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

    How We Work

    Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

    Numbers & Facts

    LocationCharlotte, Pennsylvania

    Skills

    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • Cloud Applicationsunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Go Programming Language (Golang)unmatched
    • Injectionsunmatched
    • Javaunmatched
    • JavaScriptunmatched
    • Microsoft C# (C Sharp)unmatched
    • Modeling Languagesunmatched
    • Penetration Testingunmatched
    • Python Programming/Scripting Languageunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Security Analysisunmatched
    • Software Architectureunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Team Playerunmatched
    • Technical Leadershipunmatched
    • Testingunmatched
    • Threat Modelingunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder