> Markdown version of [/jobs/ext/3053320-application-security-senior-analyst](https://www.wearedevelopers.com/jobs/ext/3053320-application-security-senior-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security, Senior Analyst - **Company:** Vanguard - **Location:** Malvern, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, C Sharp (Programming Language), Code Generation, Code Review, Continuous Integration, Python (Programming Language), Machine Learning, Open Web Application Security, Software Architecture, Systems Development Life Cycle, Fortify (Software), Secure Coding, Software Engineering, SonarQube, TypeScript, Spring Cloud, Large Language Models, Software Security, Veracode, Generative AI, Checkmarx, Virtual Agents, Devsecops, Static Application Security Testing, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** http://www.vanguardjobs.com/job/23911415/application-security-senior-analyst-malvern-pa/?utm_medium=%22mcloud%2Djobads%22&utm_campaign=Technology&utm_content=Application%20Security%2C%20Senior%20Analyst&utm_term=182417 ## About the Role We are seeking a (Senior) Secure Code Reviewer to join the Threat Modeling & Validation team. This role is responsible for performing secure code reviews of internally developed applications and services, identifying security vulnerabilities, validating findings, and providing developers with practical remediation guidance. You'll combine manual expertise with AI analysis to catch vulnerabilities before they ship. The ideal candidate combines application security expertise with hands-on software development experience and a demonstrated ability to leverage AI tooling., * Minimum of 5 years of related work experience in application security, secure code review, or software engineering with a security focus. * Strong understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices. * Understanding of modern software architectures, APIs, cloud-native applications, and CI/CD pipelines. * Experience reviewing Java, C#, Python, JavaScript/TypeScript, Go, or similar languages. * Experience using SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices * Hands-on experience using generative AI or AI-assisted developer/security tools as part of engineering, code review, security testing, or DevSecOps workflows. * Ability to communicate security findings and remediation guidance to developers and technical leadership * Undergraduate degree in a related field or an equivalent combination of training and experience., * Experience creating prompts, workflows, agents, or automations. * Experience leveraging large language models (LLMs) to improve security analysis, code review efficiency, vulnerability triage, or secure development workflows. * Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors. * Experience reviewing applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes. ## Description * Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices. * Develops and optimizes prompts, workflows, and review methodologies that improve the effectiveness and repeatability of AI-assisted code review activities. * Validates and refines vulnerability findings, reducing false positives and identifying overlooked risks. * Produces clear technical reports and risk-based recommendations. * Partners with development teams to explain findings, assess risk, and provide actionable remediation guidance. * Collaborates with penetration testers, threat modelers, and application security teams. * Contributes to team processes, methodologies, and automation initiatives. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)