PitchMeAI
Vanguard

Governance, Risk & Compliance Analyst, Specialist

Vanguard · Dallas, TX

This listing has closed — view similar roles below.

  • On site
  • Full-time
  • $110,000 / year
  • Dallas, TX

Job highlights

  • Lead GRC modernization and risk assessments.
  • Develop and scale compliance programs.
  • Advise on information security policies.
  • Utilize data and automation for risk prediction.
  • Collaborate with security, fraud, and compliance teams.

About the role

About The Job

In this role, you will help deliver on our investment in GRC modernization. You will lead risk assessments, design and scale forward-looking governance, risk, and compliance programs, and serve as a trusted advisor who helps teams move faster and smarter while staying audit-ready and compliant.

The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard’s Global Enterprise Security’s Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise-wide information security policies, standards, and operational guidelines. It assesses the end-to-end integrated GRC framework of information security policies, standards, and operational control linkages to manage cyber security risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data-driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness.

Responsibilities

  • Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation.
  • Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards.
  • Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions.
  • Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud.
  • Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required.
  • Defines and implements automations to accelerate delivery and improve effectiveness.
  • Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Designs, implements and supports modernized GRC process and tool capabilities.
  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Seven years related work experience, Information Security or fraud experience required.
  • Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred.
  • In-depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Key skills/competency

  • Governance Risk and Compliance Analyst Specialist
  • Information Security
  • Risk Assessment
  • Policy Development
  • Compliance Programs
  • NIST CSF
  • NIST 800-53
  • ISO 27002
  • GRC Solutions
  • Automation

Skills & topics

  • Governance Risk and Compliance Analyst Specialist
  • GRC
  • Risk Management
  • Information Security
  • Compliance
  • Policy Development
  • NIST
  • ISO 27002
  • Cybersecurity
  • Financial Services

How to get hired

  • Tailor your resume: Highlight 7+ years of information security or fraud experience, aligning with GRC frameworks like NIST CSF and ISO 27002.
  • Showcase GRC expertise: Emphasize experience with GRC solutions platforms and automation capabilities in your application.
  • Demonstrate communication skills: Prepare to discuss how you influence stakeholders and policy owners effectively.
  • Highlight relevant certifications: Mention preferred certifications like CISSP, CISM, or CompTIA for stronger candidacy.

Technical preparation

Master NIST CSF, NIST 800-53, ISO 27002.,Familiarize with GRC platforms.,Understand financial services regulations.,Practice implementing automation.

Behavioral questions

Describe a complex risk assessment you led.,How do you influence stakeholders on compliance?,Share an automation success in GRC.,How do you balance speed and compliance?

Frequently asked questions

What are the key responsibilities of a Governance, Risk & Compliance Analyst, Specialist at Vanguard?
The Governance, Risk & Compliance Analyst, Specialist at Vanguard is responsible for leading GRC modernization, conducting risk assessments, developing and implementing enterprise-wide information security policies and standards, and advising stakeholders. They utilize data-driven approaches and automation to manage cyber risks and ensure regulatory compliance.
What qualifications are essential for the Governance, Risk & Compliance Analyst, Specialist role at Vanguard?
Essential qualifications include seven years of related work experience in Information Security or fraud, an undergraduate degree (preferably in Computer Science), in-depth knowledge of GRC frameworks (NIST CSF, NIST 800-53, ISO 27002), experience with GRC solutions platforms and automation, and excellent communication and influencing skills.
Does Vanguard offer visa sponsorship for the Governance, Risk & Compliance Analyst, Specialist position?
No, Vanguard is not offering visa sponsorship for this particular Governance, Risk & Compliance Analyst, Specialist position.
What is Vanguard's approach to work-life balance for this role?
Vanguard employs a hybrid working model, balancing flexibility with in-person collaboration. This approach aims to support long-term client outcomes and enrich the employee experience for roles like the Governance, Risk & Compliance Analyst, Specialist.
What GRC frameworks and standards are important for this role at Vanguard?
Knowledge of frameworks and standards such as NIST CSF, NIST 800-53, CIS Controls, and ISO 27002 is crucial for the Governance, Risk & Compliance Analyst, Specialist role, particularly within the financial services industry's cyber regulations.
How does Vanguard use data and automation in its GRC function?
Vanguard utilizes data-driven approaches to predict risk issues and develops automation to accelerate GRC delivery and improve effectiveness. This role actively contributes to defining and implementing these data and automation strategies.
What type of experience is required for the Governance, Risk & Compliance Analyst, Specialist position?
A minimum of seven years of related work experience is required, specifically in Information Security or fraud. A Computer Science degree is preferred but not mandatory; an equivalent combination of training and experience is also considered.