> Markdown version of [/jobs/ext/1737517-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1737517-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Vanguard - **Location:** Malvern, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Cloud Engineering, Continuous Integration, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Enterprise Software Applications, Software Security, Devsecops, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 31, 2026 - **Apply:** http://www.vanguardjobs.com/job/23651713/senior-application-security-engineer-malvern-pa/?utm_medium=%22mcloud%2Djobads%22&utm_campaign=Technology&utm_content=Senior%20Application%20Security%20Engineer&utm_term=180827 ## About the Role * Undergraduate degree in a related field or equivalent combination of training and experience. * Strong experience deploying and operating DAST tools to include managing team onboarding, authentication setup, and CI/CD integration. * Experience with other well-known application security tools (SAST, SCA, IAST, RASP, etc.) * Strong knowledge of application development, build, and deployment processes (development, IDEs, repositories, branching, pipelines, cloud, containers, serverless, etc.). * Familiarity with industry standards such as NIST, OWASP, and MITRE. * Relevant certifications in application development, security, application security, DevSecOps, or cloud are a plus. ## Description The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application Security Specialist, you will play a pivotal role in ensuring the security and compliance of the Vanguard software development lifecycle (SDLC). You will help develop strategy, implement new technology, maintain technical controls, assess vulnerabilities, and collaborate with developers to ensure that the proper guardrails are in place to enable the continuous and secure delivery of applications. This role requires expertise in CICD, Secure software development, and application security best practices to improve developer experience and delivery of our security services to our end users, * Utilize application development, deployment, and security experience to help guide Application Security strategy and secure the software development lifecycle (SDLC) * Drive API, Container, and Application Security testing initiatives, including DAST and other security validation capabilities, to improve security coverage, identify vulnerabilities, and support timely remediation. * Develop strategies to secure current and emerging technologies (containers, serverless, API, AI/ML). * Provide hands-on engineering support for security incidents, threat events, vulnerability management, and control improvements to strengthen Enterprise application security posture. * Gather and report metrics from Application Security solutions and processes to provide meaningful insights into security coverage, risk reduction, and program maturity. * Create and maintain technical standards, operational procedures, and supporting documentation for Application Security services by leveraging guidance from organizations such as NIST, OWASP, and SANS. * Provide technical mentorship and training to development and cloud engineering teams on secure development practices for API, Container security, and vulnerability remediation. * Implement, optimize, and operationalize Application Security solutions to improve risk visibility, security coverage, and developer adoption. * Drive automation and security capabilities that improve developer experience, streamline security processes, and align Application Security solutions with enterprise security and technology goals. * Stay informed on emerging Application Security trends, technologies, attack techniques, and industry best practices to continuously enhance Vanguard's security posture. ## Related Videos - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)