AppSec - Secrets Management Specialist

Vanguard•Malvern, PA
•Hybrid

About The Position

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions. Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.

Requirements

  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.
  • Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.
  • Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.
  • Knowledge of secure SDLC practices and software supply chain security principles.
  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to work cross-functionally with engineering, IAM, platform, and security teams.

Responsibilities

  • Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization.
  • Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets.
  • Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls.
  • Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes.
  • Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration.
  • Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity.
  • Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls.
  • Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls.
  • Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC.
  • Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes.
  • Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events.

Benefits

  • comprehensive health and wellness care
  • work-life balance
  • investment in your future
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service