Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Vanguard

AppSec – Secrets Management Specialist

Vanguard

. Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization .

Posted 9/18/2026full-timeCharlotte • North Carolina • United StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Application Security, DevSecOps, and IAM, with a strong focus on credential management, secure SDLC practices, and automation. Proficient in utilizing GitHub Advanced Security for secrets protection and implementing governance processes for sensitive information.

Highest-signal resume keywords
Application SecurityGitHub Advanced Security (GHAS)Credential Lifecycle ManagementScripting and Automation (Python, PowerShell, JavaScript)Secure SDLC Practices

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Secrets ScanningAPI TokensCertificatesService AccountsPrivileged Access ManagementRisk-Based PrioritizationRemediationMetrics DevelopmentIncident ResponseAutomation Opportunities
Soft Skills
Analytical SkillsCommunication SkillsStakeholder ManagementCross-Functional Collaboration
Tools & Technologies
GitHubCI/CD PlatformsDashboardsEnterprise Scanning Controls
Industry Keywords
Cloud SecuritySecurity OperationsSecrets Classification StandardsGovernance ProcessesSoftware Supply Chain Security

Tech Stack

Tools & technologies
CloudJavaScriptPythonSDLCVault

About the role

Key responsibilities & impact
  • Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization
  • Partner with application teams to drive remediation, credential rotation, revocation, and secure replacement of exposed secrets
  • Support implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls
  • Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes
  • Collaborate with IAM and platform teams to improve credential lifecycle management, vault adoption, rotation controls, and privileged access management integration
  • Develop dashboards, metrics, and reporting for secrets exposure trends, remediation effectiveness, SLA performance, and program maturity
  • Support exception management workflows, bypass approvals, evidence collection, and audit readiness for secrets-related controls
  • Identify recurring exposure patterns and improve preventive controls with engineering, AppSec, and security advisor teams
  • Create developer-facing guidance, training materials, and best practices for secure secrets handling throughout the SDLC
  • Identify automation opportunities through APIs, workflows, and AI-assisted capabilities
  • Participate in on-call support and incident response involving exposed credentials, credential abuse, and software supply chain security events

Requirements

What you’ll need
  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations
  • Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms
  • Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts
  • Knowledge of secure SDLC practices and software supply chain security principles
  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies
  • Strong analytical, communication, and stakeholder management skills
  • Ability to work cross-functionally with engineering, IAM, platform, and security teams
  • No visa sponsorship is offered for this position

Benefits

Comp & perks
  • Comprehensive health and wellness care
  • Work-life balance
  • Investment in your future
  • Hybrid working model with enhanced flexibility
  • In-person learning, collaboration, and connection