AppSec - Secrets Management Specialist

Vanguard Group, Inc.

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in application security, DevSecOps, or related fields
  • Proficient in GitHub Advanced Security (GHAS) and secrets management
  • Strong understanding of API tokens, certificates, and privileged access management
  • Experience with secure software development lifecycle (SDLC) practices
  • Skilled in scripting and automation tools such as Python or PowerShell
  • Excellent analytical and communication abilities
  • Proven capacity to collaborate across multiple teams in a tech environment

Responsibilities

  • Investigate and prioritize exposed credentials and sensitive secrets
  • Drive remediation efforts alongside application teams for secure secret management
  • Support implementation of GitHub Advanced Security features and enterprise security controls
  • Document and maintain governance processes for secrets classification
  • Enhance credential lifecycle management with IAM and platform teams
  • Develop metrics and dashboards for monitoring secrets exposure and remediation
  • Facilitate exception management and audit readiness for secrets controls
  • Identify exposure patterns and improve preventive measures with engineering and AppSec teams
  • Create training materials and best practices for secure secrets handling
  • Explore automation to optimize detection and remediation processes
  • Engage in incident response related to credential issues and software supply chain security

Benefits

  • Opportunity to work with cutting-edge security tools and technologies
  • Emphasis on collaboration with cross-functional teams
  • Focus on a proactive security posture through education and training
  • Engagement in continuous improvement of security policies and practices
  • Access to professional growth and learning opportunities within a leading financial institution
  • A dynamic work environment where innovation is encouraged
  • Participation in incident response for real-world security challenges
Full Job Description
Core Responsibilities

  • Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization.
  • Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets.
  • Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls.
  • Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes.
  • Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration.
  • Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity.
  • Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls.
  • Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls.
  • Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC.
  • Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes.
  • Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events.


Preferred Qualifications

  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.
  • Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.
  • Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.
  • Knowledge of secure SDLC practices and software supply chain security principles.
  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to work cross-functionally with engineering, IAM, platform, and security teams.

Special Factors

Sponsorship
Vanguard is not offering visa sponsorship for this position.

Similar Jobs

More Jobs at Vanguard Group, Inc.

More Information Technology Jobs

Find similar AppSec - Secrets Management Specialist jobs: