1. Limiting access for crutials secrets: to access an vault you need credentials, but if you encrypt it you need another and so on, so the absolutly lowest should be stored securly with the least possible access.
2. An secret you don't have is save. So removing an secret from ram if you don't need it. Useful for an pool of persistent database connections.
3. If you need it at multiple places or you don't know were its accessed, store it at an central location(for example a cluster) that stores the secrets at rest.
a hashicorp vault you change your secret there and every supporting application can retrieve it from there and use it. once they are done they delete it from the ram.
If you can/want use specific kernel apis i would propose keyctl( https://www.man7.org/linux/man-pages/man2/keyctl.2.html ) this apis can store secrets limited to an specific range(threat, process, user, ...) outside of the process.