
Business Information Security Officer for IIG – Vanguard – 154196
Location
Charlotte, NC, US
Scottsdale, AZ, US
Malvern, PA, US
Dallas, TX, US
April 20, 2023
Scottsdale, AZ, US
Scottsdale, AZ, US
Malvern, PA, US
Dallas, TX, US
April 20, 2023
Charlotte, NC, US
Scottsdale, AZ, US
Malvern, PA, US
Dallas, TX, US
Charlotte, NC, US
Scottsdale, AZ, US
Malvern, PA, US
Dallas, TX, US
Job Requisition #154196
Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.
This is an exciting role and function for Vanguard and the global risk and security division. The Business Information Security Officer (BISO) will serve as the primary point of contact between the cybersecurity and fraud functions and the Institutional Investment Group (IIG) at Vanguard. The BISO is a dynamic role which will leverage consulting skills and knowledge of both the Vanguard 401k full-service business and security for the purposes of enabling strategic business outcomes. Besides being a security concierge and relationship manager the BISO is ultimately there to drive cybersecurity into the culture of the business. The BISO will provide subject matter expertise to drive faster outcomes and address security issues within multiple or complex business areas within our full-service 401k business. Identifies and evaluates cyber security/fraud risks and controls, consults, brings subject matter experts into business solutions, and suggests and recommends risk mitigation strategies. This is a dynamic and high exposure role for a good relationship builder and strategic thinker, with a passion for delivering speed to market for the business while partnering with the enterprise security and fraud delivery teams to ensure a high level of security risk mitigation.
Core Responsibilities
- Acts as the single point of contact for the business to engage with and deliver security services. Builds and maintains strategic relationships within the business and security teams to ensure strategic initiatives are met.
- Ensures security risk management practices are embedded into key business processes. Enables security risk reduction by working collaboratively with business partners and security programs to identify, prioritize, and mitigate security risks.
- Advises, coordinates, and reports on the security risk posture, security culture, controls, and assessments of the business. Communicates and presents relevant security metrics, dashboards, and executive reports to senior management.
- Defines and develops security goals, scenarios, and selects use cases to develop acceptable parameters of security risks or guardrails. Recommends changes to processes, software, systems, and platforms based upon security risk.
- Coordinates enterprise security policies and communications. Gathers business participants input, implements changes to policies, and advises the business on policy changes.
- Discusses security trends with security specialists from other institutions and peer organizations.
- Provides thought leadership for the evolution of the business information security program.
- Participates in special projects and performs other duties as assigned.
Qualifications
- Minimum of eight years related work experience, with three years in Security and Compliance required.
- Understanding and prior experience with a full-service 401k provider preferred.
- Undergraduate degree or equivalent combination of training and experience. Graduate degree preferred.
- CISSP and/or CISM required within one year.
Special Factors
- This is a hybrid role with Tues, Wed, Thurs in the office and Mon, Fri is remote.
- Vanguard is not offering visa sponsorship for this position
About Vanguard
We are Vanguard. Together, we’re changing the way the world invests.
For us, investing doesn’t just end in value. It starts with values. Because when you invest with courage, when you invest with clarity, and when you invest with care, you can get so much more in return. We invest with purpose – and that’s how we’ve become a global market leader. Here, we grow by doing the right thing for the people we serve. And so can you.
We want to make success accessible to everyone. This is our opportunity. Let’s make it count.
Inclusion Statement
Vanguard’s continued commitment to diversity and inclusion is firmly rooted in our culture. Every decision we make to best serve our clients, crew (internally employees are referred to as crew), and communities is guided by one simple statement: “Do the right thing.”
We believe that a critical aspect of doing the right thing requires building diverse, inclusive, and highly effective teams of individuals who are as unique as the clients they serve. We empower our crew to contribute their distinct strengths to achieving Vanguard’s core purpose through our values.
When all crew members feel valued and included, our ability to collaborate and innovate is amplified, and we are united in delivering on Vanguard's core purpose.
Our core purpose: To take a stand for all investors, to treat them fairly, and to give them the best chance for investment success.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
April 20, 2023
Charlotte, NC, US
Job Requisition #154196
Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.
This is an exciting role and function for Vanguard and the global risk and security division. The Business Information Security Officer (BISO) will serve as the primary point of contact between the cybersecurity and fraud functions and the Institutional Investment Group (IIG) at Vanguard. The BISO is a dynamic role which will leverage consulting skills and knowledge of both the Vanguard 401k full-service business and security for the purposes of enabling strategic business outcomes. Besides being a security concierge and relationship manager the BISO is ultimately there to drive cybersecurity into the culture of the business. The BISO will provide subject matter expertise to drive faster outcomes and address security issues within multiple or complex business areas within our full-service 401k business. Identifies and evaluates cyber security/fraud risks and controls, consults, brings subject matter experts into business solutions, and suggests and recommends risk mitigation strategies. This is a dynamic and high exposure role for a good relationship builder and strategic thinker, with a passion for delivering speed to market for the business while partnering with the enterprise security and fraud delivery teams to ensure a high level of security risk mitigation.
Core Responsibilities
- Acts as the single point of contact for the business to engage with and deliver security services. Builds and maintains strategic relationships within the business and security teams to ensure strategic initiatives are met.
- Ensures security risk management practices are embedded into key business processes. Enables security risk reduction by working collaboratively with business partners and security programs to identify, prioritize, and mitigate security risks.
- Advises, coordinates, and reports on the security risk posture, security culture, controls, and assessments of the business. Communicates and presents relevant security metrics, dashboards, and executive reports to senior management.
- Defines and develops security goals, scenarios, and selects use cases to develop acceptable parameters of security risks or guardrails. Recommends changes to processes, software, systems, and platforms based upon security risk.
- Coordinates enterprise security policies and communications. Gathers business participants input, implements changes to policies, and advises the business on policy changes.
- Discusses security trends with security specialists from other institutions and peer organizations.
- Provides thought leadership for the evolution of the business information security program.
- Participates in special projects and performs other duties as assigned.
Qualifications
- Minimum of eight years related work experience, with three years in Security and Compliance required.
- Understanding and prior experience with a full-service 401k provider preferred.
- Undergraduate degree or equivalent combination of training and experience. Graduate degree preferred.
- CISSP and/or CISM required within one year.
Special Factors
- This is a hybrid role with Tues, Wed, Thurs in the office and Mon, Fri is remote.
- Vanguard is not offering visa sponsorship for this position
About Vanguard
We are Vanguard. Together, we’re changing the way the world invests.
For us, investing doesn’t just end in value. It starts with values. Because when you invest with courage, when you invest with clarity, and when you invest with care, you can get so much more in return. We invest with purpose – and that’s how we’ve become a global market leader. Here, we grow by doing the right thing for the people we serve. And so can you.
We want to make success accessible to everyone. This is our opportunity. Let’s make it count.
Inclusion Statement
Vanguard’s continued commitment to diversity and inclusion is firmly rooted in our culture. Every decision we make to best serve our clients, crew (internally employees are referred to as crew), and communities is guided by one simple statement: “Do the right thing.”
We believe that a critical aspect of doing the right thing requires building diverse, inclusive, and highly effective teams of individuals who are as unique as the clients they serve. We empower our crew to contribute their distinct strengths to achieving Vanguard’s core purpose through our values.
When all crew members feel valued and included, our ability to collaborate and innovate is amplified, and we are united in delivering on Vanguard's core purpose.
Our core purpose: To take a stand for all investors, to treat them fairly, and to give them the best chance for investment success.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Location Charlotte, NC, US
Scottsdale, AZ, US
Malvern, PA, US
Dallas, TX, US
Scottsdale, AZ, US
Malvern, PA, US
Dallas, TX, US
Our commitment to equal employment opportunity
Vanguard is an equal opportunity employer. Vanguard is committed to providing all crew members a working environment that is free from discrimination, prejudice and bias. Through this Equal Employment Opportunity (EEO) Policy, Vanguard reaffirms its commitment to equal employment opportunity for all applicants and crew members without regard to race, color, national origin or ancestry, religion, gender, sex, sexual orientation, gender identity or expression, age, disability, marital status, veteran or military status. In addition, Vanguard prohibits discrimination based on genetic information, as well as any other characteristic protected by federal, state or local law.
Applicants with disabilities may be entitled to reasonable accommodation under the Americans with Disabilities Act and certain state or local laws. A reasonable accommodation is a change in the way things are normally done which will ensure an equal employment opportunity without imposing undue hardship on Vanguard. Please inform careers@vanguard.com if you need assistance completing this application or to otherwise participate in the application process.
Careers blog


