AppSec - Secrets Management Specialist

The Vanguard Group

United States

Hybrid

USD 110,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Vanguard Group is seeking a security professional to strengthen secrets management and software supply chain security within Global Risk and Security. The role emphasizes risk-based triage, remediation coordination, and governance across the enterprise.

You will partner with engineering, IAM, and platform teams to implement GHAS protections, drive credential lifecycle improvements, and build analytics dashboards that track exposure trends and program maturity.

Qualifications

  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.
  • Familiarity with GitHub and GHAS, Secrets Scanning, and CI/CD platforms.
  • Understanding of cloud credentials, API tokens, certificates, and privileged access concepts.
  • Knowledge of secure SDLC practices and software supply chain security principles.
  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar.
  • Strong analytical, communication, and stakeholder management skills.

Responsibilities

  • Investigate, validate, and triage exposed credentials and other secrets using risk-based prioritization.
  • Partner with application teams to drive remediation and secure replacement of exposed secrets.
  • Support GHAS Secret Protection, push protection, and enterprise scanning controls.
  • Define and maintain secrets classification standards, severity models, and governance processes.
  • Collaborate with IAM and platform teams to improve credential lifecycle management.
  • Develop dashboards and reports to measure exposure trends and program maturity.
  • Support exception management workflows and audit readiness for secrets controls.
  • Work with engineering and security teams to identify recurring exposure patterns and preventive controls.
  • Create developer-facing guidance and best practices for secure secrets handling in SDLC.
  • Identify automation opportunities via APIs, workflows, and AI-assisted capabilities to streamline processes.
  • Participate in on-call support and incident response involving exposed credentials and software supply chain security events.

Skills

Application Security
DevSecOps
IAM
Cloud Security
Security Operations
GitHub/GHAS
Secrets Scanning
CI/CD Platforms
Python
PowerShell
JavaScript
Scripting & Automation
Analytical Skills
Stakeholder Management
Cross-functional Collaboration

Tools

GitHub/GHAS

Job description

Core Responsibilities
  • Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization.
  • Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets.
  • Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls.
  • Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes.
  • Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration.
  • Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity.
  • Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls.
  • Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls.
  • Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC.
  • Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes.
  • Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events.
Preferred Qualifications
  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.
  • Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.
  • Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.
  • Knowledge of secure SDLC practices and software supply chain security principles.
  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to work cross-functionally with engineering, IAM, platform, and security teams.
Special Factors Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions. Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience. Vanguard, one of the world's leading investment management companies, serves individual investors, institutions, employer-sponsored retirement plans, and financial professionals. We have a diverse and talented crew with a culture that promotes teamwork, along with an unwavering focus on serving our clients' best interests. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AppSec - Secrets Management Specialist
AppSec - Secrets Management Specialist

Vanguard • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Comprehensive health and wellness care
Work-life balance
Investment in your future
AppSec - Secrets Management Specialist
AppSec - Secrets Management Specialist

Socket.dev • College Township (PA)

Hybrid
USD 120,000 - 190,000
Hybrid work model
Health benefits
Work-life balance
AppSec - Secrets Management Specialist
AppSec - Secrets Management Specialist

Vanguard • Malvern

Hybrid
USD 130,000 - 180,000
Health and wellness benefits
Work‑life balance
Investment in your future
+1
AppSec - Secrets Management Specialist
AppSec - Secrets Management Specialist

Vanguard • Dallas (TX)

Hybrid
USD 140,000 - 210,000
Hybrid work model
Health and wellness benefits
Work-life balance
Cloud Engineering, Senior Specialist
Cloud Engineering, Senior Specialist

The Vanguard Group • Dallas (TX)

Hybrid
USD 120,000 - 170,000
Senior Specialist, Control Assurance
Senior Specialist, Control Assurance

The Vanguard Group • Malvern

Hybrid
USD 120,000 - 170,000
Comprehensive health and wellness care
Work-life balance
Hybrid work model
Senior Specialist, Control Assurance
Senior Specialist, Control Assurance

Vanguard • Malvern

Hybrid
USD 140,000 - 190,000
Application Engineering Technical Lead - II
Application Engineering Technical Lead - II

The Vanguard Group • Lees (PA)

Hybrid
USD 170,000 - 230,000
Application Engineering Technical Lead - II
Application Engineering Technical Lead - II

Vanguard • Charlotte (NC)

Hybrid
USD 140,000 - 210,000
Identity Security MultiCloud Analyst
Identity Security MultiCloud Analyst

The Vanguard Group • Malvern

Hybrid
USD 90,000 - 130,000