Government Jobs
  • Governance, Risk & Compliance Analyst, Specialist

  • Vanguard
  • Malvern, 19355 US View Map

Summary

hackajob is collaborating with Vanguard to connect them with exceptional professionals for this role. In this role, you will be responsible for redesigning, maintaining, and managing cybersecurity policies and standards that support our GRC modernization efforts. You will translate regulatory, risk, control, and business requirements into clear, actionable, and audit-ready policy language; ensure standards remain current, consistent, and aligned to enterprise governance expectations; and partner with stakeholders to strengthen compliance, reduce ambiguity, and enable teams to operate efficiently within defined risk and control requirements. The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard’s Global Enterprise Security’s Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise-wide information security policies, standards, and operational guidelines. It assesses the end-to-end integrated GRC framework of information security policies, standards, and operational control linkages to manage cyber security risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data-driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness. Responsibilities Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation. Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards. Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions. Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities. Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud. Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise. Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required. Defines and implements automations to accelerate delivery and improve effectiveness. Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders. Designs, implements and supports modernized GRC process and tool capabilities. Participates in special projects and performs other duties as assigned. Qualifications Five years related work experience, Information Security or fraud experience required. Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred. In-depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain. Demonstrated experience with GRC solutions platform and automation capabilities. Excellent communication and influencing skills. Influence key stakeholders and security policy and control owners. Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred. Special Factors Sponsorship Vanguard is not offering visa sponsorship for this position. About Vanguard At Vanguard, we don't just have a mission—we're on a mission. To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best. How We Work Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Job Description

hackajob is collaborating with Vanguard to connect them with exceptional professionals for this role. In this role, you will be responsible for redesigning, maintaining, and managing cybersecurity policies and standards that support our GRC modernization efforts. You will translate regulatory, risk, control, and business requirements into clear, actionable, and audit-ready policy language; ensure standards remain current, consistent, and aligned to enterprise governance expectations; and partner with stakeholders to strengthen compliance, reduce ambiguity, and enable teams to operate efficiently within defined risk and control requirements. The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard’s Global Enterprise Security’s Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise-wide information security policies, standards, and operational guidelines. It assesses the end-to-end integrated GRC framework of information security policies, standards, and operational control linkages to manage cyber security risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data-driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness. Responsibilities Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation. Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards. Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions. Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities. Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud. Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise. Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required. Defines and implements automations to accelerate delivery and improve effectiveness. Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders. Designs, implements and supports modernized GRC process and tool capabilities. Participates in special projects and performs other duties as assigned. Qualifications Five years related work experience, Information Security or fraud experience required. Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred. In-depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain. Demonstrated experience with GRC solutions platform and automation capabilities. Excellent communication and influencing skills. Influence key stakeholders and security policy and control owners. Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred. Special Factors Sponsorship Vanguard is not offering visa sponsorship for this position. About Vanguard At Vanguard, we don't just have a mission—we're on a mission. To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best. How We Work Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Government Jobs

Government Jobs

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS

  • Lead Statistical Assistant (Administrative Specialist 1)

    • Trenton, New Jersey
    • New Jersey Judiciary
    • Sep 30, 2026
    New Jersey Judiciary
  • PKI Engineer

    • Fort George G. Meade, Maryland
    • Take2 Consulting, LLC
    • Oct 10, 2026
    Take2 Consulting, LLC
    $124532.468750
  • Principal Azure Security Architect

    • Jersey City, New Jersey
    • The Depository Trust & Clearing Corporation
    • Oct 10, 2026
    The Depository Trust & Clearing Corporation
    $225991.093750
  • Principal Security Architect

    • New Brunswick, New Jersey
    • Johnson & Johnson
    • Oct 10, 2026
    Johnson & Johnson
    $210436.234375
  • Senior MQ Engineer

    • Annapolis Junction, Maryland
    • HRUCKUS
    • Oct 10, 2026
    HRUCKUS
    $110635.843750
  • Principal Java Engineer (Client Facing)

    • Jersey City, New Jersey
    • Luxoft
    • Oct 10, 2026
    Luxoft
    $152328.109375