{"id":1184677,"url":"https://alion.io/job/the-vanguard-group-application-security-specialist","title":"Application Security, Specialist","company":{"id":253,"name":"The Vanguard Group","domain":"vanguard.com","url":"https://alion.io/company/vanguard","size_band":"1001-5000","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":82,"open_postings":53,"ghost_share":0.038,"stale_share":0.585,"repost_share":0.075,"time_to_fill_p50_days":22,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Malvern, United States","Charlotte, United States","Dallas, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":117000,"max_usd":233000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":659},"experience_years_min":5,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"OWASP","optional":false}],"status":"live","first_seen_at":"2026-09-24T14:35:21Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-24T17:32:42Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.\nWithin GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.\nOur crew are our greatest resource - by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.\nCore Responsibilities\nHelp define and implement Application Security strategy and secure SDLC practices across the organization.\nPartner with development teams to establish security requirements early in the software development lifecycle.\nDesign and implement security controls and guardrails that support continuous and secure application delivery.\nDevelop and maintain security standards and architecture patterns for APIs, cloud-native applications, containers, serverless platforms, and emerging technologies.\nAssess, prioritize, and drive remediation of application and infrastructure vulnerabilities identified through SAST, SCA, IAST, DAST, container, and cloud security solutions.\nConfigure, integrate, and onboard teams to application security tools across CI/CD environments.\nAutomate security processes and controls to improve efficiency, scalability, and developer adoption.\nConduct security reviews, threat analysis, and risk assessments for new and existing applications.\nPartner with developers to identify root causes of vulnerabilities and provide remediation guidance.\nEnsure application security solutions are properly implemented, integrated, and delivering expected coverage.\nDevelop security metrics, reporting, and dashboards to measure program effectiveness and maturity.\nProvide secure coding guidance, technical consultation, and training to development and cloud engineering teams.\nMaintain documentation for security controls, processes, standards, and operational procedures.\nStay current with industry trends, emerging threats, and guidance from organizations such as OWASP, NIST, and SANS.\nSupport enterprise application security standards, policies, and governance initiatives.\nQualifications\nMinimum of five years related work experience.\nUndergraduate degree in a related field or the equivalent combination of training and experience.\nStrong experience in Application Security, Secure SDLC, DevSecOps, or Software Engineering.\nHands-on experience securing CI/CD pipelines and modern application development environments.\nExperience with application security technologies including SAST, SCA, IAST, DAST, API Security, and Container Security.\nExperience working with cloud platforms and cloud-native technologies.\nStrong understanding of secure coding principles, vulnerability management, and application risk assessment.\nExperience partnering with development teams to remediate security findings.\nExperience designing and implementing security automation solutions.\nStrong communication, collaboration, and problem-solving skills.\nSpecial Factors\nSponsorship\nVanguard is not offering visa sponsorship for this position.About Vanguard\nAt Vanguard, we don't just have a mission-we're on a mission.\nTo work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.\nHow We Work\nVanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.","description_format":"text","description_chars":4442,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Hybrid work"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Financial Services"],"lifecycle":[{"event":"open","at":"2026-09-24T14:35:21Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":22,"reasons":["conf:0","win:early","comp:brand"],"computed_at":"2026-09-24T18:14:42Z"},"pay":null,"html_url":"https://alion.io/job/the-vanguard-group-application-security-specialist","json_url":"https://alion.io/job/the-vanguard-group-application-security-specialist.json","meta":{"generated_at":"2026-09-24T18:14:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}