Core Responsibilities- Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization.
- Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets.
- Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls.
- Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes.
- Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration.
- Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity.
- Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls.
- Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls.
- Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC.
- Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes.
- Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events.
Preferred Qualifications- Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.
- Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.
- Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.
- Knowledge of secure SDLC practices and software supply chain security principles.
- Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.
- Strong analytical, communication, and stakeholder management skills.
- Ability to work cross-functionally with engineering, IAM, platform, and security teams.
Special FactorsSponsorshipVanguard is not offering visa sponsorship for this position.