Back to positions

Senior Manager, Governance, Risk & Compliance

Remote role Full-time Open position

About the position The Senior Manager, Governance, Risk & Compliance is a key leadership position in Vanguard’s Global Enterprise Security’s Governance, Risk, Compliance (GRC) and Strategic Operations team. This position leads a team which oversees, recommends, develops, implements, and monitors enterprise-wide information security policies, procedures, and operational guidelines. It sets the departmental Enterprise Security and Fraud GRC vision and develops strategies in alignment with the overall mission. Modernize integrated GRC framework to align with evolving risks, technological advancements, business priorities, and regulatory obligations.

Responsibilities

  • Hires, evaluates, and supervises crew. Provides guidance and training as necessary to develop crew. Sets performance standards, reviews performance, and makes informed compensation decisions in accordance with all applicable Human Resources policies and procedures.
  • Defines and executes the vision, strategy, and roadmap for GRC to support the overall cybersecurity and fraud risk objectives and priorities.
  • Oversees partnerships with Enterprise Security and Fraud subdivisions and Vanguard business units regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined security requirements.
  • Defines integration requirements and identifies ramifications on Security and Fraud, IT and business unit operations of their implementation.
  • Develops and maintains a comprehensive portfolio of global security policies and standards. Oversees and manages the entire lifecycle of the portfolio, ensuring alignment with organizational goals and regulatory requirements.
  • Responsible for governance and decision-making related to methodology and policy for all security and fraud functions. Influences key stakeholders and security policy owners during policy discussions.
  • Interfaces with clients on all inquiries related to Information and IT Security capabilities, bringing in technical experts as client situations demand. Responsible for review and approval of all RFP responses related to security.
  • Leads the modernization initiative to update a cohesive GRC framework, aimed at simplifying, upgrading, and creating clear visibility for policies, standards, controls, and taxonomy. Ensures alignment with risk management and compliance obligations at both enterprise and regional levels. Develops automations and data driven insights from to drive effective operations and risk reduction.
  • Briefs leadership on the state of cybersecurity and Fraud GRC to provide insights into trends and impact of strategic business, technology, and cybersecurity investments.
  • Works with Compliance and Regional Security and fraud teams to understand global regulatory requirements for security, develop global Security and Fraud policies and standards, and oversee implementation. Interfaces with external regulators for Security and Fraud.
  • Leads the development and maintenance of the Security and Fraud organization's key risk indicators and key performance indicators in partnership with Line 2 risk management.
  • Participates in special projects and performs other duties as assigned.

Requirements

  • Minimum of ten years related work experience.
  • Undergraduate degree or equivalent combination of training and experience.
  • Proven leadership experience leading global cross-functional teams.
  • Demonstrated experience setting vision, strategy, and modernization service capabilities.
  • In-depth knowledge of relevant frameworks and control standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Proficient in developing effective cybersecurity GRC OKRs and risk-based controls dashboards.
  • Excellent communication and influencing skills. Influence key stakeholders and security policy and control owners.

Nice-to-haves

  • Graduate degree preferred.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Apply tot his job Apply To this Job

Further positions

Senior Governance Risk Compliance Analyst

Remote role Full-time

AI Governance Lead Consultant

Remote role Full-time

Senior Manager, Government Relations, NA Trade and Procurement Policy Analyst

Remote role Full-time

Manager, Government Relations Mid-Atlantic Region

Remote role Full-time

Senior Federal Contracts and Subcontracts Management Consultant

Remote role Full-time

Principal Contracts Specialist (remote)

Remote role Full-time

Grant Writing Consultant - Education - Part-time

Remote role Full-time

Graphic Designer, Card Frames– TCG

Remote role Full-time

VP, Digital & Growth Marketing - Remote

Remote role Full-time

GTM Associate - Growth Marketing

Remote role Full-time

[Remote] Principal PS Consultant, AI Solutions Architect

Remote role Full-time

Plan Consultant - HCM

Remote role Full-time

RN- Telehealth – Virtual Hospital – Amazon Store

Remote role Full-time

Customer Success Manager [REMOTE within the Eastern Time Zone]

Remote role Full-time

Hiring Now: Associate Product Manager

Remote role Full-time

[Remote] Billing Specialist -Remote (CT, PT or MT Time Zones)

Remote role Full-time

Require Student Worker: Success Center Tutors & Zoom Assistants (Pool) in Roseburg, OR

Remote role Full-time

Experienced Full Stack Data Entry Specialist – Web & Cloud Application Development

Remote role Full-time

Experienced Special Needs Healthcare Customer Advisor - National Remote

Remote role Full-time

Customer Service Representative – On‑Site Frontline Support for Global Brands at arenaflex

Remote role Full-time