
Largest company.
Application Security Pentester, Specialist at Vanguard
About the role
Leads and executes security assessments to identify, validate, and communicate security risks. Performs manual and automated penetration testing, conducts additional security assessments such as Secure Code Reviews and Dynamic Application Security Testing (DAST), and produces clear, actional reports for technical teams and leadership. Partners with IT and business stakeholders to assess risk, support remediation, and improve the organization’s overall security posture.
Core Responsibilities
-
Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and validate vulnerabilities.
-
Conducts other security assessments as needed, including Secure Code Reviews and/or Dynamic Application Security Testing (DAST).
-
Develops detailed assessment reports and presents findings to technical teams and leadership. Coordinates security risk reporting and collaborates with IT sub-divisions, third-party partners, and business units to identify the impact of technology implementations on IT and business operations.
-
Contributes to the evolution of team processes, testing methodologies, standards, and best practices.
-
Maintains subject-matter expertise in common vulnerability classes and attack techniques (e.g., OWASP Top 10, OWASP Top 10 API, SANS Top 25), and remains familiar with relevant security frameworks (e.g., MITRE ATT&CK). Stays current on emerging threats, tools, and offensive security techniques.
-
Participates in special projects and performs other duties as assigned.
Qualifications
-
Minimum five years related work experience with three years experience in IT security or application development.
-
Undergraduate degree in related field or equivalent combination of training and experience.
-
Hands-on experience performing web application, API, and network penetration testing.
-
Preferred experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tooling.
-
Experience in on or more of the following a plus: cloud penetration testing, mobile penetration testing, AI red teaming
-
Proficiency in at least one programming or scripting language (e.g., Python, Java).
-
Preferred security certifications such as Off Sec Certified Professional (OSCP), Off Sec Web Assessor (OSWA), Off Sec Web Expert (OSWE), GIAC Penetration Tester (GPEN), or GIAC Web Application Penetration Tester (GWAPT).
Special Factors Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Required skills
Penetration testing
Application security
Secure code review
DAST
Vulnerability assessment
Risk communication
Total Views
0
Total Apply Clicks
0
Total Mock Apply
0
Total Bookmarks
0
More open roles at Vanguard

Data Engineer, Specialist
Vanguard · Malvern; Dallas/Ft. Worth

Senior Data Product Manager
Vanguard · Malvern; North Carolina

Controls and Enablement Senior Specialist - Personal Wealth – Brokerage and Investments
Vanguard · Malvern; Scottsdale; Charlotte

Business Controls Oversight Analyst, Specialist
Vanguard · Malvern; Scottsdale; Charlotte

Controls Management, Specialist
Vanguard · Malvern; Scottsdale
Similar jobs

Staff Tech, Security, T4
Collins Aerospace (RTX) · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site)

Principal Systems Security Engineer (Cyber) - P4 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Senior Principal Systems Security Engineer (Cyber) - P5 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Principal Systems Security Engineer (Cyber) - P4 (Onsite)
Collins Aerospace (RTX) · US-AL-HUNTSVILLE-401 ~ 401 Jan Davis Dr NW ~ JAN DAVIS 401

Network/Security Analyst- Onsite
Collins Aerospace (RTX) · US-MT-GREAT FALLS-6932-CUST ~ 6932 Goddard Dr ~ GODDARD (External Site)
About Vanguard

Vanguard
PublicA client-owned investment company that offers low-cost mutual funds, ETFs, advice, and related services to institutional and individual investors, and financial professionals.
10,001+
Employees
Kelayres
Headquarters
Reviews
10 reviews
4.1
10 reviews
Work-life balance
3.8
Compensation
2.5
Culture
4.2
Career
3.2
Management
4.3
75%
Recommend to a friend
Pros
Supportive management and leadership
Great work-life balance and flexibility
Strong team collaboration and culture
Cons
Low or non-competitive compensation
Limited career advancement and promotions
Heavy workload and long hours
Salary Ranges
756 data points
Junior/L3
Junior/L3 · Business Development Specialist
3 reports
$82,893
total per year
Base
$72,072
Stock
-
Bonus
-
$82,893
$82,893
Interview experience
3 interviews
Difficulty
3.0
/ 5
Duration
14-28 weeks
Interview process
1
Application Review
2
Online Assessment/Case Study
3
Phone Interview
4
Technical Interview
5
Final Round Interview
6
Offer
Common questions
Technical Knowledge
Behavioral/STAR
Past Experience
Case Study
Coding/Algorithm
Latest updates
Vanguard to Update Names of U.S. Equity Index Funds Tracking Morningstar Indexes - PR Newswire
PR Newswire
News
·
1w ago
VOO vs. VGT: Which Vanguard ETF Has More Room to Run in 2026? - TipRanks
TipRanks
News
·
1w ago
FHSAA flag football highlights from Deltona vs. Vanguard playoff game - Daytona Beach News-Journal
Daytona Beach News-Journal
News
·
1w ago
Vanguard Bundles Bond ETFs Into Ready-Made Income Portfolios - Vanguard Target Maturity 2027 Corporate Bo - Benzinga
Benzinga
News
·
1w ago