Senior Application Security Engineer
Vanguard · Charlotte, NC · Yesterday
HybridFull-time
Key Responsibilities
- Utilize application development, deployment, and security experience to help guide Application Security strategy and secure the software development lifecycle (SDLC)
- Drive API, Container, and Application Security testing initiatives, including DAST and other security validation capabilities, to improve security coverage, identify vulnerabilities, and support timely remediation
- Develop strategies to secure current and emerging technologies (containers, serverless, API, AI/ML)
- Provide hands-on engineering support for security incidents, threat events, vulnerability management, and control improvements to strengthen Enterprise application security posture
- Gather and report metrics from Application Security solutions and processes to provide meaningful insights into security coverage, risk reduction, and program maturity
- Create and maintain technical standards, operational procedures, and supporting documentation for Application Security services by leveraging guidance from organizations such as NIST, OWASP, and SANS
- Provide technical mentorship and training to development and cloud engineering teams on secure development practices for API, Container security, and vulnerability remediation
- Implement, optimize, and operationalize Application Security solutions to improve risk visibility, security coverage, and developer adoption
- Drive automation and security capabilities that improve developer experience, streamline security processes, and align Application Security solutions with enterprise security and technology goals
- Stay informed on emerging Application Security trends, technologies, attack techniques, and industry best practices to continuously enhance Vanguard's security posture
Qualifications
- Undergraduate degree in a related field or equivalent combination of training and experience
- Strong experience deploying and operating DAST tools to include managing team onboarding, authentication setup, and CI/CD integration
- Experience with other well-known application security tools (SAST, SCA, IAST, RASP, etc.)
- Strong knowledge of application development, build, and deployment processes (development, IDEs, repositories, branching, pipelines, cloud, containers, serverless, etc.)
- Familiarity with industry standards such as NIST, OWASP, and MITRE
- Relevant certifications in application development, security, application security, DevSecOps, or cloud are a plus