> Markdown version of [/jobs/ext/3048666-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/3048666-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security, Analyst - **Company:** Vanguard - **Location:** Malvern, PA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, C Sharp (Programming Language), Code Generation, Code Review, Continuous Integration, Python (Programming Language), Machine Learning, Open Web Application Security, Software Architecture, Systems Development Life Cycle, Fortify (Software), Secure Coding, Software Engineering, SonarQube, TypeScript, Spring Cloud, Large Language Models, Software Security, Veracode, Generative AI, Checkmarx, Virtual Agents, Devsecops, Static Application Security Testing - **Published:** September 24, 2026 - **Apply:** http://www.vanguardjobs.com/job/23911414/application-security-analyst-malvern-pa/?utm_medium=%22mcloud%2Djobads%22&utm_campaign=Technology&utm_content=Application%20Security%2C%20Analyst&utm_term=182415 ## About the Role * Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus. * Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices. * Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines. * Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages. * Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices * Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities. * Ability to communicate security findings and remediation guidance to developers and technical teams. * Undergraduate degree in a related field or the equivalent combination of training and experience., * Experience creating prompts, workflows, agents, or automations * Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors. * Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes. ## Description We are seeking a Secure Code Reviewer to join the Threat Modeling & Validation team. This role is responsible for performing secure code reviews of internally developed applications and services, identifying security vulnerabilities, validating findings, and supporting developers with remediation recommendations. You'll combine manual review techniques with AI analysis to help identify vulnerabilities early in the software development lifecycle. Core Responsibilities * Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices. * Utilizes established prompts, workflows, and review methodologies to support AI-assisted code review activities. * Reviews and validates vulnerability findings identified through automated and AI-assisted analysis. * Produces clear technical reports and risk-based recommendations. * Works with development teams to communicate findings and support remediation efforts. * Collaborates with penetration testers, threat modelers, and application security teams. * Supports team processes, methodologies, and automation initiatives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)