招聘
Core Responsibilities
-
Serve as the technical lead and subject matter expert for Software Composition Analysis (SCA), partnering closely with the App Sec team lead and manager to execute strategy and roadmap for open-source and dependency security across the SDLC.
-
Lead the design, configuration, and continuous optimization of SCA tooling, including policy definition, risk and reachability tuning, and CI/CD integration at scale.
-
Drive risk-based vulnerability management for open-source dependencies, providing guidance on prioritization, remediation approaches, and risk acceptance decisions.
-
Define and maintain standards, guardrails, and best practices for open-source usage, including approved dependency policies, vulnerability thresholds, and exception workflows.
-
Act as the primary point of contact for SCA, collaborating with application teams, platform teams, App Sec peers, and other security stakeholders to ensure alignment and effective execution.
-
Participate in an on-call rotation to support application security tooling, assist developers, and respond to security threat events when required.
-
Champion a developer-first experience by improving signal quality, reducing noise, and delivering clear, actionable remediation guidance aligned with engineering workflows.
-
Identify, design, and implement automation and process improvements to enhance dependency visibility, response times, and program scalability.
-
Define, track, and communicate key metrics and insights related to open-source risk, remediation effectiveness, and SCA program maturity to stakeholders and leadership.
-
Provide technical leadership and mentorship to App Sec engineers and development teams on secure dependency management and emerging open-source risks.
-
Maintain comprehensive documentation for SCA technologies, processes, and standards; stay current on industry trends, tooling, and open-source security threats.
-
Participate in strategic initiatives and cross-functional efforts to advance the broader Application Security program.
Qualifications
-
Bachelor’s degree in a related field or equivalent experience
-
Hands-on experience deploying and operating SCA/SAST tools, including onboarding, auth setup, and CI/CD integration
-
Experience with additional App Sec tools (Secret Scanning, IAST, DAST, etc.)
-
Strong understanding of modern application development and delivery (IDEs, repos, CI/CD, cloud, containers, serverless)
-
Working knowledge of NIST, OWASP, and MITRE frameworks
-
App Sec, Dev Sec Ops, cloud, or development certifications a plus
Special Factors Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
总浏览量
0
申请点击数
0
模拟申请者数
0
收藏
0
相似职位

Vice President, Site Reliability Engineer
BNY Mellon · Pune, MH, India

CISO Governance Manager L2
Wipro ·

Senior Lead Software Engineer - VMware/OpenShift
JPMorgan Chase · Plano, TX, United States, US

DEVOPS LEAD L2
Wipro · Bengaluru, India

Senior Manager of Software Engineering - Java, AWS
JPMorgan Chase · New York, NY, United States, US
关于Vanguard

Vanguard
PublicA client-owned investment company that offers low-cost mutual funds, ETFs, advice, and related services to institutional and individual investors, and financial professionals.
10,001+
员工数
Kelayres
总部位置
评价
3.0
3条评价
工作生活平衡
3.8
薪酬
2.8
企业文化
2.5
职业发展
2.3
管理层
2.5
45%
推荐给朋友
优点
Better work/life balance
Higher pay compared to current positions
Interesting rotational programs
缺点
Lower pay than industry average
Perceived as dead end career path
Mixed employer reputation at entry level
薪资范围
887个数据点
Junior/L3
Junior/L3 · Business Development Specialist
3份报告
$82,893
年薪总额
基本工资
$72,072
股票
-
奖金
-
$82,893
$82,893
面试经验
3次面试
难度
3.0
/ 5
时长
14-28周
面试流程
1
Application Review
2
Online Assessment/Case Study
3
Phone Interview
4
Technical Interview
5
Final Round Interview
6
Offer
常见问题
Technical Knowledge
Behavioral/STAR
Past Experience
Case Study
Coding/Algorithm
新闻动态
Which Is the Better ETF, Vanguard's Mega-Cap MGK or iShares' Small-Cap IWO? - The Motley Fool
The Motley Fool
News
·
5d ago
Vanguard Releases New Index Equity ETFs - 401k Specialist
401k Specialist
News
·
5d ago
Just In: Iran military command closes Strait of Hormuz again - Vanguard News
Vanguard News
News
·
5d ago
Two candidates, parent arrested for falsifying UTME scores with AI — JAMB - Vanguard News
Vanguard News
News
·
5d ago