Jobs · Pennsylvania

Governance, Risk & Compliance Analyst, Specialist

Vanguard · Malvern, PA · 3 days ago
HybridFull-time

About the role

Lead the modernization, rewriting, and ongoing management of cybersecurity policies and standards. Develop clear, actionable, and audit-ready requirements that align to enterprise risk, regulatory, and control expectations while helping teams understand and comply with security governance requirements. Join Vanguard’s Global Enterprise Security GRC and Strategic Operations team to modernize the way we manage information security policies, standards, and governance practices.

Develop and maintain enterprise security requirements, strengthen alignment between policies, controls, risks, and regulatory obligations, and partner with stakeholders to deliver practical, audit-ready solutions. This role is ideal for a detail-oriented GRC professional who is excited to use data, automation, and strong stakeholder engagement to improve security governance at scale.

Responsibilities

  • Work with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities to evaluate their effectiveness at meeting defined requirements, determining integration requirements, and identifying operational ramifications.
  • Support the development and maintenance of a portfolio of global security and fraud policies and standards. Monitor and maintain the lifecycle of the portfolio.
  • Oversee management and decisions related to methodology and policy for all Security and Fraud functions.
  • Advise key stakeholders and security policy owners during policy and standards discussions. Interface with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Work with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interface with external regulators for Information and IT Security and Fraud.
  • Review and analyze current and proposed policy and standards directives and IT technical issues that may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommend, develop, implement, and coordinate new security policies, standards, controls, and operating doctrine at all levels across the company. Interpret policy relating to Vanguard information security and fraud functions and provide guidance as required.
  • Define and implement automations to accelerate delivery and improve effectiveness.
  • Define and implement data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Design, implement, and support modernized GRC process and tool capabilities.
  • Participate in special projects and perform other duties as assigned.

Requirements

  • Seven years of related work experience in Information Security or fraud.
  • Undergraduate degree or equivalent combination of training and experience.
  • In-depth knowledge of relevant frameworks and standards (e.g., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines. Considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills to engage key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don’t just have a mission—we’re on a mission: to work for the long-term financial wellbeing of our clients, lead through products and services that transform our clients' lives, and learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Similar jobs