Back to jobs
Vanguard

AppSec - Secrets Management Specialist

Charlotte, NCSalary not listedPosted 8 days ago

Immigration summary

Visa sponsorship

LikelyLow confidence

This employer sponsors, but not for roles like this one.

222 recent H-1B filings

View visa evidence

Green card sponsorship

Strong historyMedium confidence

This employer has recently sponsored green cards at scale.

63 recent certified PERM filings

View green card evidence

Job description

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.

Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.

Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.

Core Responsibilities

  • Investigate, validate, and triage exposed credentials, API keys, tokens, certificates, and other sensitive secrets using risk-based prioritization. 

  • Partner with application teams to drive timely remediation, credential rotation, revocation, and secure replacement of exposed secrets. 

  • Support the implementation and administration of GitHub Advanced Security (GHAS) Secret Protection, push protection, custom detection patterns, and enterprise scanning controls. 

  • Define, document, and maintain secrets classification standards, severity models, response procedures, and governance processes. 

  • Collaborate with IAM and platform teams to improve credential lifecycle management practices, including vault adoption, rotation controls, and privileged access management integration. 

  • Develop dashboards, metrics, and reporting to measure secrets exposure trends, remediation effectiveness, SLA performance, and program maturity. 

  • Support exception management workflows, bypass approvals, evidence collection, and audit readiness activities for secrets-related controls. 

  • Work with engineering, AppSec, and security advisor teams to identify recurring exposure patterns and improve preventive controls. 

  • Create developer-facing guidance, training materials, and best practices to promote secure secrets handling throughout the SDLC. 

  • Identify automation opportunities through APIs, workflows, and AI-assisted capabilities to streamline detection, triage, ownership mapping, and remediation processes. 

  • Participate in on-call support and incident response activities involving exposed credentials, credential abuse, and software supply chain security events. 

Preferred Qualifications

  • Experience in Application Security, DevSecOps, IAM, Cloud Security, or Security Operations.

  • Familiarity with GitHub, GitHub Advanced Security (GHAS), Secrets Scanning, and CI/CD platforms.

  • Understanding of cloud credentials, API tokens, certificates, service accounts, and privileged access concepts.

  • Knowledge of secure SDLC practices and software supply chain security principles.

  • Experience with scripting and automation using Python, PowerShell, JavaScript, or similar technologies.

  • Strong analytical, communication, and stakeholder management skills.

  • Ability to work cross-functionally with engineering, IAM, platform, and security teams. 

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Sponsorship evidence

Why Openbound reached the conclusions above.

Visa sponsorship evidence

Current posting

Silent on sponsorship

Other openings

3 of 290 recent openings at this employer state a sponsorship restriction.

Employer H-1B history

222
recent certified H-1B filings
54
new-hire petitions
0
filings for similar roles
176
so far in FY2026
More evidence details
  • 222 recent certified H-1B filings across the employer
  • Still filing this year — 176 filings in FY2026
  • 38 USCIS H-1B new-employment approvals, counted separately from LCA filings
  • Strong filing activity in NC
  • 475 further USCIS approvals for extensions or transfers
  • We checked 142 filing titles for this employer and none describe work like this role
  • 3 other recent postings at this company state a sponsorship restriction
  • The posting says nothing about sponsorship either way

Strong filing activity in NC.

Green card sponsorship evidence

Employer PERM history

63
recent certified PERM filings
0
filings for similar roles
9
filings in this location
Certified PERM filings by fiscal year
202313
202431
2025102
2026119YTD

Filing history reflects past employer behavior; it isn't a promise for this opening.

All open roles at Vanguard
How Openbound evaluates sponsorship

Visa history uses official U.S. Department of Labor H-1B LCA disclosure data and USCIS H-1B petition history. Green card history uses DOL PERM disclosure data. Each is read for the employer as a whole, for roles like this one, and for this location, weighted toward the most recent fiscal years.

An employer is matched to its filing entities by verified legal name and reviewed aliases; a match is never made on a name resemblance alone. Where no verified entity can be matched, the page says so and draws no conclusion from the absence. 142 filing titles were examined for this employer.

What this posting states outranks history in both directions, and an employer's published policy outranks past filings. Filing history reflects past behavior; it is not a promise of sponsorship for this opening, and none of this is legal advice.