Governance, Risk & Compliance Analyst, Specialist

Vanguard

Dallas (TX)

On-site

USD 90,000 - 125,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Vanguard is seeking a Governance, Risk & Compliance Analyst, Specialist to lead enterprise‑wide information security policies and standards. You will translate regulatory and business needs into audit‑ready policy language, ensure standards stay current, and collaborate with stakeholders to reduce ambiguity and enable teams to operate within defined risk controls.

You will assess the end‑to‑end GRC framework, monitor policy lifecycles, and use data‑driven methods to predict risk issues and craft

Qualifications

  • Five years related work experience in Information Security or fraud.
  • Undergraduate degree or equivalent; Computer Science preferred.
  • In-depth knowledge of NIST CSF, NIST 800-53, CIS Controls, ISO 27002 and financial services cyber regulations.
  • Experience with GRC solutions platforms and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Responsibilities

  • Serve as the technical authority on security of applications and systems.
  • Conduct security and fraud assessments and risk analyses.
  • Develop and maintain policies and standards portfolio; monitor lifecycle.
  • Advise stakeholders during policy discussions; interface with regulators.
  • Define automations to accelerate delivery and improve effectiveness.
  • Design data-driven dashboards to predict risk issues and partner with owners.
  • Support modernized GRC process and tooling across the company.

Skills

GRC
InfoSec
Policy development
Automation
Stakeholder mgmt

Education

Undergraduate degree
Computer Science degree preferred

Tools

GRC platform
Automation tools

Job description

In this role, you will be responsible for redesigning, maintaining, and managing cybersecurity policies and standards that support our GRC modernization efforts. You will translate regulatory, risk, control, and business requirements into clear, actionable, and audit‑ready policy language; ensure standards remain current, consistent, and aligned to enterprise governance expectations; and partner with stakeholders to strengthen compliance, reduce ambiguity, and enable teams to operate efficiently within defined risk and control requirements.

The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard’s Global Enterprise Security’s Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise‑wide information security policies, standards, and operational guidelines. It assesses the end‑to‑end integrated GRC framework of information security policies, standards, and operational control linkages to manage cybersecurity risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data‑driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness.

Responsibilities
  • Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation.
  • Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards.
  • Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions.
  • Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud.
  • Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required.
  • Defines and implements automations to accelerate delivery and improve effectiveness.
  • Defines and implements data‑driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Designs, implements and supports modernized GRC process and tool capabilities.
  • Participates in special projects and performs other duties as assigned.
Qualifications
  • Five years related work experience, Information Security or fraud experience required.
  • Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred.
  • In‑depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800‑53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.
Sponsorship

Vanguard is not offering visa sponsorship for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

Vanguard • Malvern

On-site
USD 110,000 - 160,000
Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

Vanguard • Malvern (AR)

Hybrid
USD 110,000 - 160,000
Hybrid work model
Competitive benefits
GRC Policy Architect — Cybersecurity & Compliance
GRC Policy Architect — Cybersecurity & Compliance

Vanguard • Malvern

On-site
USD 110,000 - 160,000
GRC Cybersecurity Policy & Risk Analyst
GRC Cybersecurity Policy & Risk Analyst

Vanguard • Dallas (TX)

On-site
USD 90,000 - 125,000
Senior Specialist, Control Assurance
Senior Specialist, Control Assurance

The Vanguard Group • Lees (PA)

Hybrid
USD 140,000 - 190,000
Health and wellness benefits
Hybrid work model
Senior Specialist, Control Assurance
Senior Specialist, Control Assurance

The Vanguard Group • Malvern

Hybrid
USD 120,000 - 170,000
Comprehensive health and wellness care
Work-life balance
Hybrid work model
Security Engineering Governance & Data Analyst
Security Engineering Governance & Data Analyst

Vanguard • United States

Hybrid
CAD 90,000 - 140,000
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Staffing • Hartford (CT)

On-site
USD 130,000 - 180,000
Senior Cybersecurity Risk & Controls Specialist
Senior Cybersecurity Risk & Controls Specialist

The Vanguard Group • Lees (PA)

Hybrid
USD 140,000 - 190,000
Health and wellness benefits
Hybrid work model
Threat Emulation and Exploit Engineer
Threat Emulation and Exploit Engineer

Vanguard • Charlotte (NC)

Hybrid
USD 120,000 - 150,000