The Vanguard Group-posted 9 months ago
Full-time • Senior
Hybrid • Malvern, PA
Securities, Commodity Contracts, and Other Financial Investments and Related Activities

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions. Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource - by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core. The Senior Manager, Cybersecurity Continuous Controls Monitoring and Assurance is a key leadership member of Vanguard's Global Enterprise Security's Governance, Risk, Compliance and Strategic Operations team. This position will oversee a team responsible for continuous controls monitoring and assurance to safeguard information and assets. The scope of this role is to assess adherence to information security policies, procedures, and operational controls to manage cyber security risks within tolerances, satisfy regulatory obligations, and address expanding controls testing requirements, with exceptional stakeholder experience.

  • Leads team of controls and assurance testers and analysts.
  • Provides guidance and training as necessary to develop crew.
  • Sets performance standards, reviews performance, and makes informed compensation decisions in accordance with all applicable Human Resources policies and procedures.
  • Defines and executes the vision, strategy, and roadmap for continuous monitoring and assurance of cybersecurity and fraud controls to support the overall risk objectives and priorities.
  • Develops automations and data driven insights from automations, measurement, and appropriate scoring algorithms.
  • Ensures the development and implementation of the internal control framework, leads complex control identification, design, implementation, testing, and reporting.
  • Implements and manages continuous monitoring solutions and automations to reduce time to risk discovery and reduce testing cycle time.
  • Leads the identification and resolution of complex control gaps and ensures effective design, implementation, and operation of controls across divisions and regions.
  • Identifies and implements actions to increase effectiveness and reduce friction.
  • Briefs leadership on the state of critical cybersecurity and fraud controls including providing insights into trends and impact of strategic business, technology, and cybersecurity investments.
  • Owns relationships with key internal and external stakeholders.
  • Drives strategic alignment between cybersecurity and technology teams, control owners, and risk leads.
  • Minimum twelve years related work experience and five years of management experience.
  • Experience in cybersecurity is required.
  • Undergraduate degree in related field or equivalent combination of training and experience.
  • One or more of CISSP, CISM, CISA, CIA, CPA, or other relevant certifications required as per the role.
  • Proven leadership experience leading global cross-functional teams.
  • Demonstrated experience building and running automation and monitoring of cybersecurity controls for high volume transaction processing such as in the Banking industry.
  • In-depth knowledge of relevant frameworks and control standards (i.e. NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Proficient developing effective cybersecurity GRC OKRs and risk-based controls dashboards.
  • Excellent communication and influencing skills.
  • Comprehensive health and wellness care
  • Work-life balance
  • Investment in your future
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service