- Location
- Malvern, PA, United States of America · Charlotte, NC · Dallas/Ft. Worth, TX
- Type
- Full-time
- Department
- Security
- Education
- Bachelor
- Visa
- Not sponsored
- Source
- Workday
Description
Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.
Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.
Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.
Core Responsibilities
- Help define and implement Application Security strategy and secure SDLC practices across the organization.
- Partner with development teams to establish security requirements early in the software development lifecycle.
- Design and implement security controls and guardrails that support continuous and secure application delivery.
- Develop and maintain security standards and architecture patterns for APIs, cloud-native applications, containers, serverless platforms, and emerging technologies.
- Assess, prioritize, and drive remediation of application and infrastructure vulnerabilities identified through SAST, SCA, IAST, DAST, container, and cloud security solutions.
- Configure, integrate, and onboard teams to application security tools across CI/CD environments.
- Automate security processes and controls to improve efficiency, scalability, and developer adoption.
- Conduct security reviews, threat analysis, and risk assessments for new and existing applications.
- Partner with developers to identify root causes of vulnerabilities and provide remediation guidance.
- Ensure application security solutions are properly implemented, integrated, and delivering expected coverage.
- Develop security metrics, reporting, and dashboards to measure program effectiveness and maturity.
- Provide secure coding guidance, technical consultation, and training to development and cloud engineering teams.
- Maintain documentation for security controls, processes, standards, and operational procedures.
- Stay current with industry trends, emerging threats, and guidance from organizations such as OWASP, NIST, and SANS.
- Support enterprise application security standards, policies, and governance initiatives.
Qualifications
- Minimum of five years related work experience.
- Undergraduate degree in a related field or the equivalent combination of training and experience.
- Strong experience in Application Security, Secure SDLC, DevSecOps, or Software Engineering.
- Hands-on experience securing CI/CD pipelines and modern application development environments.
- Experience with application security technologies including SAST, SCA, IAST, DAST, API Security, and Container Security.
- Experience working with cloud platforms and cloud-native technologies.
- Strong understanding of secure coding principles, vulnerability management, and application risk assessment.
- Experience partnering with development teams to remediate security findings.
- Experience designing and implementing security automation solutions.
- Strong communication, collaboration, and problem-solving skills.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.