Application Security Engineer - Cloud Engineering - Vanguard Careers - Malvern, PA
Vanguard Careers
Responsibilities:
Design, implement, test, and maintain application security tooling and integrations across the software development lifecycle, with a focus on reliability, scalability, and performance.Build, enhance, and operate CI/CD pipeline integrations for application security scanning, ensuring consistent execution and minimal impact to developer workflows.Develop and maintain monitoring, alerting, and operational controls for application security platforms to ensure availability and rapid detection of failures.Participate in an on-call rotation, troubleshoot and resolve production issues related to application security tooling, perform root cause analysis, and implement preventative improvements.Collaborate closely with other Application Security engineers, platform teams, and the CTO organization to integrate new and existing security tools into enterprise development platforms.Partner with Security Specialists to implement and maintain application security tool integrations and workflows, translating program requirements into reliable engineering solutions (e.g., pipeline steps, configurations, connectors, automation, and operational runbooks).Continuously improve application security engineering standards, tooling architecture, and technical patterns, identifying opportunities to modernize or simplify implementations.Identify and implement automation opportunities to reduce manual effort, improve consistency, and scale application security capabilities.Maintain a strong working knowledge of software development practices, application architectures, and infrastructure patterns, applying that knowledge to improve security tooling effectiveness.Contribute code, scripts, configurations, and infrastructure-as-code to support application security platforms and workflows.Support and mentor junior engineers through technical guidance, code reviews, and knowledge sharing.Create and maintain technical documentation for application security systems, integrations, a