LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Application Security, Analyst

ExperiencedVisa sponsorship available
Vanguard logo

at Vanguard

Asset Management

Posted 5 days ago

No clicks

**Secure Code Reviewer | Application Security Analyst** Join the Threat Modeling & Validation team as our new Secure Code Reviewer. This role, responsible for performing manual and AI-assisted secure code reviews of internally developed applications and services, drives early identification of security vulnerabilities. Key responsibilities include: - Analyzing source code to spot vulnerabilities, logic flaws, and insecure coding practices across modern application stacks. - Utilizing established workflows and AI-assisted code review techniques. - Reviewing and validating vulnerability findings, and producing risk-based recommendations. - Collaborating with development teams, penetration testers, and application security teams to communicate findings and support remediation. Candidates with minimum 3 years of related work experience in application security or software engineering with a security focus are welcome. Essential qualifications include understanding of secure coding principles, familiarity with modern software architectures, Java, C#, Python, JavaScript/TypeScript, Go or similar languages, and SAST tools such as Checkmarx, Fortify. Experience with generative AI and prompt engineering is a plus. Ability to communicate security findings clearly to technical teams is crucial. Undergraduate degree in a related field is required.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
United States

Full Job Description

We are seeking a Secure Code Reviewer to join the Threat Modeling & Validation team. This role is responsible for performing secure code reviews of internally developed applications and services, identifying security vulnerabilities, validating findings, and supporting developers with remediation recommendations. You'll combine manual review techniques with AI analysis to help identify vulnerabilities early in the software development lifecycle.

Core Responsibilities

  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
  • Utilizes established prompts, workflows, and review methodologies to support AI-assisted code review activities.
  • Reviews and validates vulnerability findings identified through automated and AI-assisted analysis.
  • Produces clear technical reports and risk-based recommendations.
  • Works with development teams to communicate findings and support remediation efforts.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Supports team processes, methodologies, and automation initiatives.

Required Qualifications

  • Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus.
  • Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
  • Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
  • Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
  • Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities.
  • Ability to communicate security findings and remediation guidance to developers and technical teams.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.


Preferred Qualifications

  • Experience creating prompts, workflows, agents, or automations
  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
  • Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a missionwe're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Application Security, Analyst

Compensation

Not specified

City: Not specified

Country: United States

Vanguard logo
Asset Management

5 days ago

No clicks

at Vanguard

ExperiencedVisa sponsorship available

**Secure Code Reviewer | Application Security Analyst** Join the Threat Modeling & Validation team as our new Secure Code Reviewer. This role, responsible for performing manual and AI-assisted secure code reviews of internally developed applications and services, drives early identification of security vulnerabilities. Key responsibilities include: - Analyzing source code to spot vulnerabilities, logic flaws, and insecure coding practices across modern application stacks. - Utilizing established workflows and AI-assisted code review techniques. - Reviewing and validating vulnerability findings, and producing risk-based recommendations. - Collaborating with development teams, penetration testers, and application security teams to communicate findings and support remediation. Candidates with minimum 3 years of related work experience in application security or software engineering with a security focus are welcome. Essential qualifications include understanding of secure coding principles, familiarity with modern software architectures, Java, C#, Python, JavaScript/TypeScript, Go or similar languages, and SAST tools such as Checkmarx, Fortify. Experience with generative AI and prompt engineering is a plus. Ability to communicate security findings clearly to technical teams is crucial. Undergraduate degree in a related field is required.

Full Job Description

We are seeking a Secure Code Reviewer to join the Threat Modeling & Validation team. This role is responsible for performing secure code reviews of internally developed applications and services, identifying security vulnerabilities, validating findings, and supporting developers with remediation recommendations. You'll combine manual review techniques with AI analysis to help identify vulnerabilities early in the software development lifecycle.

Core Responsibilities

  • Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
  • Utilizes established prompts, workflows, and review methodologies to support AI-assisted code review activities.
  • Reviews and validates vulnerability findings identified through automated and AI-assisted analysis.
  • Produces clear technical reports and risk-based recommendations.
  • Works with development teams to communicate findings and support remediation efforts.
  • Collaborates with penetration testers, threat modelers, and application security teams.
  • Supports team processes, methodologies, and automation initiatives.

Required Qualifications

  • Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus.
  • Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
  • Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
  • Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
  • Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
  • Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities.
  • Ability to communicate security findings and remediation guidance to developers and technical teams.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.


Preferred Qualifications

  • Experience creating prompts, workflows, agents, or automations
  • Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors.
  • Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a missionwe're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.