The Secrets Management Technical Analyst is responsible for discovering, compiling, researching, analyzing, and documenting data, requirements, workflows, controls, and business processes within Enterprise Security Product & Services. This role serves as a subject matter expert and liaison across technical and business teams, supporting cybersecurity compliance and secure credential handling practices. The analyst will support the Enterprise Secrets Management program by facilitating governance, discovery, analysis, remediation tracking, and compliance activities, including findings identified through automated scanning and discovery tools such as TruffleHog and Clutch.
Key Responsibilities:
Discover, review, validate, and analyze findings generated by secret-scanning and discovery platforms, including TruffleHog and Clutch, to identify exposed secrets, stale identities, and other credential-related security risks.
Support Non-Human Identity (NHI) management, including governance, lifecycle oversight, and alignment of system/service accounts with enterprise security policies.
Monitor and enforce secret rotation compliance, ensuring credentials are rotated according to policy and assisting teams in meeting regulatory and internal rotation requirements.
Coordinate with application teams, business owners, system owners, and engineering partners to remediate compromised credentials and enforce secure rotation workflows.
Collaborate with security engineers to validate findings, confirm ownership, and assess the impact of policy or process changes.
Track findings end to end, ensuring timely resolution and accurate attribution of ownership.
Assist in improving scanning accuracy and optimizing discovery and remediation pipelines in partnership with engineering teams.
Serve as liaison between IAM and business partners to ensure cohesive remediation and secure credential usage practices.
Prepare and deliver metrics and dashboards related to exposed secrets, mean time to detect/remediate, repeat offenders, and security posture trends.
Maintain procedural documentation and create automation runbooks.
Qualifications:
Bachelor's Degree in Information Technology, Cybersecurity, or other related field, or the equivalent combination of education, training or experience
Knowledge of IT policies, security procedures, and identity governance frameworks.
Understanding of foundational security concepts (AAA, authentication fundamentals, Zero Trust).
Experience with secret-scanning and automated discovery technologies, preferably including TruffleHog and Clutch, and familiarity with credential discovery and remediation workflow
Familiarity with IAM concepts, incident response processes, and secure access management for Enterprise Security Product & Services.
Desired Qualifications
Experience generating security metrics, supporting risk mitigation, or assembling audit evidence.
Exposure to Privileged Access Management (PAM) tools such as CyberArk.
Ability to translate technical findings into clear, actionable business recommendations.
Process improvement mindset with a focus on security, quality, and operational efficiency.
Ability to serve as a trusted advisor to development, infrastructure, and business teams.
Experience with secret management on the Multicloud (AWS, OCI, Azure)
Experience with secret-scanning and discovery platforms, including TruffleHog and Clutch, to identify exposed secrets, stale identities, and other credential-related security risks
| Enable Skills-Based Hiring | No | |
Additional Details
| ||
|---|---|---|
| Location | Merrifield, VA |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder