What are the responsibilities and job description for the Third Party Cybersecurity Risk Analyst position at Vanguard?
Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.
Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.
This is a great opportunity to have a significant positive impact by helping Vanguard manage its supplier risk and play a leadership role in establishing a new capability for the Enterprise Security & Fraud (ES&F) Vendor Management Office (VMO).
You will be responsible for establishing a Systems and Organizations Controls 2 (SOC2) reporting center of excellence (CoE) for ES&F vendors in scope. You will partner closely with the Third-Party Oversight Modernization (TPOM) program and our Enterprise Supplier Management (ESM) partners. You will establish sustainable and repeatable processes to allow the ES&F VMO to take on an enhanced role in vendor oversight, performance management and monitoring of value delivered. This role has become essential due to an increase in the scope of the VMO roles and responsibilities.
You will have an opportunity to increase your cyber security skills and partner with the business relationship managers and product owners across all E&SF departments both domestically and internationally.
The ideal candidate will have:
- Foundational cybersecurity and IT technical acumen with a desire to build on this acumen
- Comprehensive understanding and experience working with and/or assessing industry leading cybersecurity solutions, toolsets, and professional services firms.
- Prior audit, compliance, risk management experience especially in the third- and extended-party relationship management space
- Prior sourcing, procurement and enterprise supplier management experience is a plus
- Certifications such as CISSP, CISA, Security , AWS, CISM, or CIA are a plus
,
In this role, you will:
- Develop and maintain operational risk methodology to evaluate and implement third party risk assessments through continuous review and application, sharing of best practices and benchmarking analysis. Provides thought leadership and design to new third-party risk modules and technology, development, and stabilization. Regularly reviews third party risk technologies and suggests improvements.
- Develop and cultivate strong relationships with divisional clients. Ensure implementation and maintenance of best practices in response to ongoing risk needs. Build credibility as a thought partner.
- . Analyze assessment data and advises on divisional and some enterprise projects, providing risk expertise, highlighting issues, and encouraging the use of established risk frameworks to mitigate and identify third party risks.
- Develop third party risk metrics and reports on results to internal stakeholders. Maintain library of all required documentation.
- Collaborate with other teams to inform and escalate risk issues and events and stay current with the risk management frameworks.
- Lead enhancement initiatives to improve third party risk oversight and assurance activities.
- Participate in special projects and performs other duties as assigned.
What it takes
- Undergraduate degree or equivalent combination of training and experience.
- Minimum of five years related work experience with at least three years of risk management experience.
Special Factors
- This is a hybrid role with Tues, Wed, Thurs in the office and Mon, Fri is remote
- Vanguard is not offering visa sponsorship for this position.
About Vanguard
We are Vanguard. Together, we’re changing the way the world invests.
For us, investing doesn’t just end in value. It starts with values. Because when you invest with courage, when you invest with clarity, and when you invest with care, you can get so much more in return. We invest with purpose – and that’s how we’ve become a global market leader. Here, we grow by doing the right thing for the people we serve. And so can you.
We want to make success accessible to everyone. This is our opportunity. Let’s make it count.
Inclusion Statement
Vanguard’s continued commitment to diversity and inclusion is firmly rooted in our culture. Every decision we make to best serve our clients, crew (internally employees are referred to as crew), and communities is guided by one simple statement: “Do the right thing.”
We believe that a critical aspect of doing the right thing requires building diverse, inclusive, and highly effective teams of individuals who are as unique as the clients they serve. We empower our crew to contribute their distinct strengths to achieving Vanguard’s core purpose through our values.
When all crew members feel valued and included, our ability to collaborate and innovate is amplified, and we are united in delivering on Vanguard's core purpose.
Our core purpose: To take a stand for all investors, to treat them fairly, and to give them the best chance for investment success.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.Salary : $1 - $1,000,000