Governance Risk Compliance Specialist, Senior Security Controls Tester

Malvern, PA, United States

Apply now Apply later

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.

Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.

Key Responsibilities:


•    Design, plan and execute control testing for key processes including Cash Management.
•    Collaborate with stakeholders and control owners to build, validate, and enhance security and privacy controls.
•    Develops automations and data driven insights from automations, measurement, and appropriate scoring algorithms.
•    Assess the design and operational effectiveness of internal controls to ensure alignment with internal policies and external regulatory requirements 
•    Identify control gaps and provide actionable recommendations.
•    Maintain documentation of controls, test procedures, and findings.
•    Align security controls testing with frameworks such as NIST CSF, ISO 27002, and COBIT.

Additional Responsibilities:


•    Delivers the cybersecurity continuous controls monitoring and assurance roadmap and capabilities to enable cybersecurity and fraud risk objectives and priorities.
•    Builds and implements solutions to reduce time to risk discovery and testing cycle time.
•    Modernizes the internal control framework and leads complex control identification, design, implementation, testing, and reporting.
•    Works with IT subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined security requirements, determining integration requirements and identifying ramifications on IT and business unit operations of their implementation.
•    Participates in special projects and performs other duties as assigned.

What it takes:


•    Four - six years related work experience planning and executing control testing.   Information Security experience preferred.
•    Demonstrated experience building and running automation and monitoring of cybersecurity controls for high volume transaction processing such as in the Banking industry.
•    In-depth knowledge of relevant frameworks and control standards (i.e. NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
•    One or more of CISSP, CISM, CISA, CIA, CPA, or other relevant certifications required is preferred.
•    Undergraduate degree or equivalent combination of training and experience. Cyber Security or Computer Science degree preferred.
 

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  3  1  0
Category: Compliance Jobs

Tags: Automation Banking CIA CISA CISM CISSP COBIT Compliance Computer Science Governance ISO 27002 Monitoring NIST NIST 800-53 Privacy Strategy

Perks/benefits: Career development Health care Wellness

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.