Jobs

Secure Developer Experience Specialist
Chandler, AZ; Charlotte, NC; Dallas, TX; Malvern, PA
·
On-site
·
Full-time
·
2w ago
Benefits & Perks
•Healthcare
•401(k)
•Flexible Hours
•Remote Work
•Healthcare
•401k
•Flexible Hours
•Remote Work
Required Skills
Secure coding practices
SDLC knowledge
Python or Java or C#
Security awareness
Global Risk and Secu rity (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard l eaders and crew drive faster, stronger, risk-informed decisions.
Within GR&S, the Enterprise Security and Fraud(ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.
Our crew are our greatest resource - by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.
-
Core Responsibilities
-
Design and Maintain the Secure Developer Scorecard: Lead the creation, evolution, and ongoing management of a secure developer scorecard that measures developer successes and failures in secure coding practices. Ensure the scorecard reflects key metrics such as vulnerability prevention, SDLC adherence, time spent on secure coding, and alignment with Vanguard-specific expectations.
-
Discover and Address Developer Community Bottlenecks: Proactively engage with the developer community to identify bottlenecks, frustrations, and barriers that delay code merges to production or lead to the dismissal of secure coding governance. Analyze feedback and data to pinpoint areas for improvement.
-
Lead Developer Engagement and Feedback Loops: Facilitate regular sessions with developers to listen, gather insights, and foster open dialogue about secure development challenges. Serve as a trusted advocate for developers, ensuring their voices are heard in enterprise security initiatives.
-
Build Business Cases for Secure Development Process Improvements: Translate developer feedback and scorecard insights into actionable business cases for process, tooling, or cultural changes. Present recommendations to leadership with a focus on business value, profitability, and measurable outcomes.
-
Conduct Learning and Awareness Activities: Develop and deliver targeted learning sessions, workshops, and awareness campaigns to promote secure coding practices and SDLC governance within the developer community.
-
Education & Experience Requirements
-
Minimum 8 years of related work experience, with at least 3 years in IT security or application development.
-
Undergraduate degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or related field.
-
Alternatively, candidates with a non-technical degree or no degree but substantial relevant experience will be considered.
-
Minimum of 2+ years of professional experience in secure software development, application security, or developer enablement roles.
-
Alternatively, 5+ years of experience in cybersecurity, security awareness, or enterprise application risk management may substitute for direct developer experience.
-
Direct developer experience is not strictly required. However, candidates must demonstrate:
-
Rudimentary coding capability (e.g., able to read, write, and understand code in at least one major programming language such as Python, Java, or C#).
-
High-level understanding of the Software Development Life Cycle (SDLC), secure coding principles, and the challenges faced in enterprise application development.
-
Familiarity with common developer workflows, tools, and bottlenecks.
-
Highly respected certifications: CISSP, CSSLP. Desired: Security+ or equivalent foundational security certification. Considered: SSAP or similar credentials, especially for candidates with a background in security awareness and developer enablement.
-
Candidates lacking direct developer experience but possessing a strong background in cybersecurity awareness, secure development advocacy, or enterprise change management will be strongly considered.
-
Preferred Technical Skills & Tools
-
Experience with any of the following is a plus:
-
Using Wiz dashboards or similar tools for extracting insights and informing project decisions
-
Qualys, Cloud Fleet, or other vulnerability management platforms
-
AWS, Azure, GCP, or OCI cloud environments
-
Secure code training platforms
-
Familiarity with secure development frameworks (e.g., NIST SSDF, OWASP SAMM, SLSA)
-
Developer productivity platforms, code analysis tools, or IDE security controls
Special Factors
Sponsorship Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don't just have a mission-we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work:
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Consulting Director, Cloud Security, Proactive Services (Unit 42) - Remote San Francisco, CA 01/26/2026
Palo Alto Networks · san francisco

Level 3 Digital Forensics and Incident Response Analyst
Allstate · Flexible / Remote

Senior Security Monitoring and Response Analyst
Mastercard · Pune, India

Lead, GCS Strategy & Ops
Palo Alto Networks · Santa Clara, CA

Sr. Consultant, Cyber Engineering & Tech Ops - Endpoint Security
Cargill · Bangalore, India
About Vanguard
Reviews
3.4
3 reviews
Work Life Balance
2.5
Compensation
3.2
Culture
2.8
Career
3.5
Management
3.0
45%
Recommend to a Friend
Pros
Competitive compensation package with bonuses
Good foundation for career development
Interesting programs aligned with education
Cons
Long commute requirements (2.5 hours)
Mandatory on-site presence multiple days
Pay below industry standards
Salary Ranges
1,532 data points
Junior/L3
Mid/L4
Senior/L5
Junior/L3 · Processing Associate
135 reports
$57,471
total / year
Base
$53,433
Stock
-
Bonus
$4,038
$45,260
$73,912
Interview Experience
3 interviews
Difficulty
3.0
/ 5
Duration
14-28 weeks
Interview Process
1
Application Review
2
Recruiter/HR Phone Screen
3
Technical/Case Study Round
4
Final Round Interview
5
Offer
Common Questions
Behavioral/STAR
Technical Knowledge
Case Study
Past Experience
Culture Fit
News & Buzz
Vanguard Personalized Indexing Management LLC Sells 10,432 Shares of Owens Corning Inc $OC - MarketBeat
Source: MarketBeat
News
·
5w ago
Vanguard Mining Reports Re-Assay Program for Redonda Copper-Molybdenum Project - TheNewswire
Source: TheNewswire
News
·
5w ago
Why Vanguard says investors should flip the traditional 60/40 portfolio in favor of bonds - Business Insider
Source: Business Insider
News
·
5w ago
3 Vanguard Mutual Funds to Buy for Spectacular Returns - TradingView
Source: TradingView
News
·
5w ago