Hiring.Camp

AppSec - Secrets Management Specialist

Vanguard

·

Yesterday

Location
USA - Horizon, United States of America · Dallas/Ft. Worth, TX · Malvern, PA
Type
Full-time
Department
Management
Visa
Not sponsored
Source
Workday

Description

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.

 

Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.

Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.

Core Responsibilities

  • Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization. 

  • Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets. 

  • Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls. 

  • Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes. 

  • Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration. 

  • Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity. 

  • Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls. 

  • Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls. 

  • Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC. 

  • Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes. 

  • Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events. 

Preferred Qualifications

  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.

  • Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.

  • Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.

  • Knowledge of secure SDLC practices and software supply chain security principles.

  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.

  • Strong analytical, communication, and stakeholder management skills.

  • Ability to work cross-functionally with engineering, IAM, platform, and security teams. 

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Skills

PythonJavaScriptCI/CDGitHub