Vanguard
AppSec - Secrets Management Specialist
Charlotte, NC · Dallas/Ft. Worth, TX · Malvern, PA
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 20 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.
Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.
Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.
Core Responsibilities
Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization.
Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets.
Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls.
Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes.
Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration.
Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity.
Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls.
Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls.
Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC.
Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes.
Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events.
Preferred Qualifications
Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.
Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.
Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.
Knowledge of secure SDLC practices and software supply chain security principles.
Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.
Strong analytical, communication, and stakeholder management skills.
Ability to work cross-functionally with engineering, IAM, platform, and security teams.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Similar jobs
- AppSec EngineerDigital Asset · New York CityFirst seen 4d ago
- AppSec EngineerTheori · United StatesFirst seen 5d agoremote
- DevOps Engineer (FortiAppSec)for interns · Sunnyvale, CA, United StatesFirst seen 6d ago
- Security Engineer II, Stores Application Security, SDO AppSec, Stores SecurityAmazon · New York, New York, USAFirst seen 6d ago
- Security Engineer II, Stores AppSecAmazon · New York, New York, USAFirst seen 6d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job