At a glanceSummarised by Seekless from the posting.
Must have8
Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus
Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices
Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines
Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages
Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities
Ability to communicate security findings and remediation guidance to developers and technical teams
Undergraduate degree in a related field or the equivalent combination of training and experience
Nice to have3
Experience creating prompts, workflows, agents, or automations preferred
Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors preferred
Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes preferred
Eligibility1
Vanguard is not offering visa sponsorship for this position
Skills
Java
C#
Python
JavaScript
TypeScript
Go
Checkmarx
Fortify
Veracode
Semgrep
SonarQube
Responsibilities:
•
Performs manual and AI-assisted secure code reviews across modern application stacks, analyzing source code to identify vulnerabilities, logic flaws, and insecure coding practices.
•
Utilizes established prompts, workflows, and review methodologies to support AI-assisted code review activities.
•
Reviews and validates vulnerability findings identified through automated and AI-assisted analysis.
•
Produces clear technical reports and risk-based recommendations.
•
Works with development teams to communicate findings and support remediation efforts.
•
Collaborates with penetration testers, threat modelers, and application security teams.
•
Supports team processes, methodologies, and automation initiatives.
Qualifications:
•
Minimum of 3 years of related work experience in application security, secure code review, or software engineering with a security focus.
•
Understanding of secure coding principles, application security vulnerabilities (OWASP Top 10 and common application vulnerabilities), and secure software development practices.
•
Familiarity with modern software architectures, APIs, cloud-native applications, and CI/CD pipelines.
•
Familiarity with Java, C#, Python, JavaScript/TypeScript, Go, or similar languages.
•
Familiarity with SAST tools such as Checkmarx, Fortify, Veracode, Semgrep, or SonarQube as well as familiarity with secure SDLC and DevSecOps practices
•
Familiarity with generative AI or AI-assisted developer/security tools used in software development, code review, or security testing activities.
•
Ability to communicate security findings and remediation guidance to developers and technical teams.
•
Undergraduate degree in a related field or the equivalent combination of training and experience.
•
Experience creating prompts, workflows, agents, or automations preferred
•
Familiarity with LLM security risks, prompt injection, insecure code generation, model misuse, and AI application attack vectors preferred
•
Familiarity with applications that utilize machine learning, generative AI, agentic AI, or AI-enabled business processes preferred
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don’t just have a mission—we’re on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients’ lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.