<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>5c7e46c8-c5c</externalid>
      <Title>Application Security Intern</Title>
      <Description><![CDATA[<p>We&#39;re looking for a curious and motivated Application Security Intern to help us build secure products and development practices at VGS. As an Application Security Intern, you will partner with security and engineering teams to evaluate application risk, improve secure software development workflows, and help developers ship software safely in an environment that handles highly sensitive payment and identity data.</p>
<p>Your responsibilities will include:</p>
<ul>
<li>Supporting application security reviews for services, APIs, and new product features across the VGS platform.</li>
<li>Helping identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.</li>
<li>Participating in threat modeling and secure design discussions with engineering teams during feature development.</li>
<li>Evaluating the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC.</li>
<li>Assisting with manual testing and validation of web application and API security issues.</li>
<li>Helping improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.</li>
<li>Working with engineers to understand remediation options and clearly document security risks and recommendations.</li>
<li>Contributing to improving security tooling and guardrails in CI/CD and development workflows.</li>
</ul>
<p>We&#39;re looking for someone with a strong interest in secure software design, cloud-native architectures, and automation. You should have a foundational understanding of application security concepts, such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.</p>
<p>At VGS, we have a remote-first philosophy, and we&#39;re looking for someone who is comfortable working independently and collaboratively as part of a team.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>internship</Jobtype>
      <Experiencelevel>entry</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>application security, secure software development, cloud-native architectures, automation, OWASP Top 10, API security, authentication and authorization, secure coding, common software vulnerabilities, LMMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, cloud environments</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>VGS</Employername>
      <Employerlogo>https://logos.yubhub.co/vgs.com.png</Employerlogo>
      <Employerdescription>VGS is the world&apos;s leader in payment tokenization, providing processor-agnostic tokenization solutions to large banks, fintechs, and merchants.</Employerdescription>
      <Employerwebsite>https://www.vgs.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
  </jobs>
</source>