Governance, Risk & Compliance Analyst, Specialist

Vanguard

Malvern (Chester County)

On-site

USD 110,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Vanguard is seeking a Governance, Risk & Compliance Analyst, Specialist to redesign and manage cybersecurity policies and standards that support GRC modernization. You’ll translate regulatory and business requirements into clear policy language, ensure alignment with enterprise governance, and partner with stakeholders to strengthen compliance.

As a key member of Vanguard’s Global Enterprise Security’s GRC and Strategic Operations team, you will develop, monitor, and automate enterprise-wide

Qualifications

  • Five years of information security or fraud experience required.
  • Undergraduate degree or equivalent experience; Computer Science preferred.
  • Strong knowledge of NIST CSF/800-53, CIS Controls, ISO 27002.
  • Experience with GRC solutions and automation capabilities.
  • Excellent communication and influencing skills.

Responsibilities

  • Redesign, maintain and manage cybersecurity policies and standards.
  • Translate regulatory and business requirements into plain policy language.
  • Assess global regulatory requirements and coordinate policy implementations.
  • Advise stakeholders on policy ownership and controls.
  • Define automations to accelerate policy delivery and improve effectiveness.
  • Develop data-driven dashboards to predict risk and drive solutions.

Skills

InfoSec experience
GRC platforms
Policy communication
Stakeholder influence
Framework knowledge
Certification preferred

Education

Undergraduate degree

Tools

GRC software

Job description

In this role, you will be responsible for redesigning, maintaining, and managing cybersecurity policies and standards that support our GRC modernization efforts. You will translate regulatory, risk, control, and business requirements into clear, actionable, and audit‑ready policy language; ensure standards remain current, consistent, and aligned to enterprise governance expectations; and partner with stakeholders to strengthen compliance, reduce ambiguity, and enable teams to operate efficiently within defined risk and control requirements.

The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard’s Global Enterprise Security’s Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise‑wide information security policies, standards, and operational guidelines. It assesses the end‑to‑end integrated GRC framework of information security policies, standards, and operational control linkages to manage cybersecurity risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data‑driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness.

Responsibilities
  • Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation.
  • Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards.
  • Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions.
  • Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud.
  • Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required.
  • Defines and implements automations to accelerate delivery and improve effectiveness.
  • Defines and implements data‑driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Designs, implements and supports modernized GRC process and tool capabilities.
  • Participates in special projects and performs other duties as assigned.
Qualifications
  • Five years related work experience, Information Security or fraud experience required.
  • Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred.
  • In‑depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800‑53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.
Sponsorship

Vanguard is not offering visa sponsorship for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

Vanguard • Dallas (TX)

On-site
USD 90,000 - 125,000
Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

Vanguard • Malvern (AR)

Hybrid
USD 110,000 - 160,000
Hybrid work model
Competitive benefits
GRC Policy Architect — Cybersecurity & Compliance
GRC Policy Architect — Cybersecurity & Compliance

Vanguard • Malvern

On-site
USD 110,000 - 160,000
GRC Cybersecurity Policy & Risk Analyst
GRC Cybersecurity Policy & Risk Analyst

Vanguard • Dallas (TX)

On-site
USD 90,000 - 125,000
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Staffing • Hartford (CT)

On-site
USD 130,000 - 180,000
Security Engineering Governance & Data Analyst
Security Engineering Governance & Data Analyst

Vanguard • United States

Hybrid
CAD 90,000 - 140,000
Threat Emulation and Exploit Engineer
Threat Emulation and Exploit Engineer

Vanguard • Charlotte (NC)

Hybrid
USD 120,000 - 150,000
Threat Emulation and Exploit Engineer
Threat Emulation and Exploit Engineer

Vanguard • Dallas (TX)

Hybrid
USD 110,000 - 150,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000