LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Create an account
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Application Security Pentester, Specialist

ExperiencedVisa sponsorship available
Vanguard logo

at Vanguard

Asset Management

Posted 3 days ago

No clicks

**Application Security Pentester, Specialist** leads and conducts meticulous security assessments to identify, validate, and communicate risks across diverse technologies, such as web applications, APIs, and AI systems. This experienced (5+ years) professional performs manual and automated penetration testing, employs Secure Code Reviews and DAST, and produces actionable reports for technical teams and leadership. They collaborate with IT and business stakeholders to assess risk, support remediation, and boost organizational security. Key skills include experience in penetration testing, proficiency in scripting/programming languages, and familiarity with common vulnerabilities (e.g., OWASP Top 10) and security frameworks like MITRE ATT&CK. Preferred certifications include OSCP, OSWA, OSWE, GPEN, or GWAPT.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
United States

Full Job Description

Leads and executes security assessments to identify, validate, and communicate security risks. Performs manual and automated penetration testing, conducts additional security assessments such as Secure Code Reviews and Dynamic Application Security Testing (DAST), and produces clear, actional reports for technical teams and leadership. Partners with IT and business stakeholders to assess risk, support remediation, and improve the organizations overall security posture.

Core Responsibilities

  • Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and validate vulnerabilities.

  • Conducts other security assessments as needed, including Secure Code Reviews and/or Dynamic Application Security Testing (DAST).

  • Develops detailed assessment reports and presents findings to technical teams and leadership. Coordinates security risk reporting and collaborates with IT sub-divisions, third-party partners, and business units to identify the impact of technology implementations on IT and business operations.

  • Contributes to the evolution of team processes, testing methodologies, standards, and best practices.

  • Maintains subject-matter expertise in common vulnerability classes and attack techniques (e.g., OWASP Top 10, OWASP Top 10 API, SANS Top 25), and remains familiar with relevant security frameworks (e.g., MITRE ATT&CK). Stays current on emerging threats, tools, and offensive security techniques.

  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Minimum five years related work experience with three years experience in IT security or application development.

  • Undergraduate degree in related field or equivalent combination of training and experience.

  • Hands-on experience performing web application, API, and network penetration testing.

  • Preferred experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tooling.

  • Experience in on or more of the following a plus: cloud penetration testing, mobile penetration testing, AI red teaming

  • Proficiency in at least one programming or scripting language (e.g., Python, Java).

  • Preferred security certifications such as OffSec Certified Professional (OSCP), OffSec Web Assessor (OSWA), OffSec Web Expert (OSWE), GIAC Penetration Tester (GPEN), or GIAC Web Application Penetration Tester (GWAPT).

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a missionwe're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Application Security Pentester, Specialist

Compensation

Not specified

City: Not specified

Country: United States

Vanguard logo
Asset Management

3 days ago

No clicks

at Vanguard

ExperiencedVisa sponsorship available

**Application Security Pentester, Specialist** leads and conducts meticulous security assessments to identify, validate, and communicate risks across diverse technologies, such as web applications, APIs, and AI systems. This experienced (5+ years) professional performs manual and automated penetration testing, employs Secure Code Reviews and DAST, and produces actionable reports for technical teams and leadership. They collaborate with IT and business stakeholders to assess risk, support remediation, and boost organizational security. Key skills include experience in penetration testing, proficiency in scripting/programming languages, and familiarity with common vulnerabilities (e.g., OWASP Top 10) and security frameworks like MITRE ATT&CK. Preferred certifications include OSCP, OSWA, OSWE, GPEN, or GWAPT.

Full Job Description

Leads and executes security assessments to identify, validate, and communicate security risks. Performs manual and automated penetration testing, conducts additional security assessments such as Secure Code Reviews and Dynamic Application Security Testing (DAST), and produces clear, actional reports for technical teams and leadership. Partners with IT and business stakeholders to assess risk, support remediation, and improve the organizations overall security posture.

Core Responsibilities

  • Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and validate vulnerabilities.

  • Conducts other security assessments as needed, including Secure Code Reviews and/or Dynamic Application Security Testing (DAST).

  • Develops detailed assessment reports and presents findings to technical teams and leadership. Coordinates security risk reporting and collaborates with IT sub-divisions, third-party partners, and business units to identify the impact of technology implementations on IT and business operations.

  • Contributes to the evolution of team processes, testing methodologies, standards, and best practices.

  • Maintains subject-matter expertise in common vulnerability classes and attack techniques (e.g., OWASP Top 10, OWASP Top 10 API, SANS Top 25), and remains familiar with relevant security frameworks (e.g., MITRE ATT&CK). Stays current on emerging threats, tools, and offensive security techniques.

  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Minimum five years related work experience with three years experience in IT security or application development.

  • Undergraduate degree in related field or equivalent combination of training and experience.

  • Hands-on experience performing web application, API, and network penetration testing.

  • Preferred experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tooling.

  • Experience in on or more of the following a plus: cloud penetration testing, mobile penetration testing, AI red teaming

  • Proficiency in at least one programming or scripting language (e.g., Python, Java).

  • Preferred security certifications such as OffSec Certified Professional (OSCP), OffSec Web Assessor (OSWA), OffSec Web Expert (OSWE), GIAC Penetration Tester (GPEN), or GIAC Web Application Penetration Tester (GWAPT).

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a missionwe're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.