Application Security Specialist securing Vanguard's investment-management software; implement SAST/DAST, API and CI/CD security, and train developers.
Responsibilities
Utilize application development, deployment, and security experience to guide Application Security strategy and secure the SDLC
Utilize current and emerging security technologies to identify, assess, and remediate application vulnerabilities (SAST, SCA, IAST, DAST, Containers, etc.)
Configure and onboard teams to dynamic scanning tools across CI/CD environments, including authentication and integration of DAST scanners
Design, implement, and continuously refine API security requirements and architecture patterns
Ensure proper implementation, coverage, and function of application security solutions
Develop and implement strategies to secure cloud, containers, serverless, mobile, and AI/ML technologies
Conduct in-depth analysis of vulnerabilities in software and application deployment processes and implement remediation measures
Identify and execute opportunities to automate Application Security processes
Gather and report metrics from application security solutions to inform program maturity
Collaborate with developer community to enhance remediation experience and provide secure coding guidance
Provide guidance and training to development and cloud engineering teams on secure coding and deployment best practices
Stay up to date on application security practices and maintain documentation
Participate in special projects and other duties as assigned
Requirements
Undergraduate degree in a related field or equivalent combination of training and experience
Strong experience deploying and operating DAST tools, including managing team onboarding, authentication setup, and CI/CD integration
Experience with other application security tools (SAST, SCA, IAST, RASP, etc.)
Strong knowledge of application development, build, and deployment processes (IDEs, repositories, branching, pipelines, cloud, containers, serverless, etc.)
Familiarity with industry standards such as NIST, OWASP, and MITRE
Relevant certifications in application development, security, application security, DevSecOps, or cloud are a plus
Experience designing and implementing API security requirements and architecture patterns
Experience securing cloud, containers, serverless, mobile, and AI/ML technologies
Ability to analyze vulnerabilities and propose/implement remediation measures
Ability to automate Application Security processes and gather/report metrics
Ability to provide guidance and training to development and cloud engineering teams
Authorization to work without visa sponsorship (Vanguard is not offering visa sponsorship for this position)
Benefits
Hybrid working model for the majority of crew members (enhanced flexibility and in-person collaboration)
Opportunities for in-person learning and collaboration
Professional development and educational opportunities
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.
Principal Systems Engineer - Cybersecurity role in protecting our nation's products as part of Integrated Platform Solutions team. Develop solutions utilizing RMF, Anti - Tamper, Software Assurance, and more.
Agent de Sécurité assurant la sécurité des usagers du réseau de transport TBM. Rattaché au Manager de Proximité Sûreté, garantissant la qualité de service public de transport en commun.