The Security Assurance Specialist III leads the end‑to‑end coordination and execution of application and infrastructure security risk assessments, ensuring consistent, timely, and high‑quality identification of cybersecurity risks and vulnerabilities. The role partners closely across cybersecurity, IT engineering teams, and business stakeholders to enable effective risk and vulnerability management across the enterprise.
Acting as the central assessment orchestration function, the specialist manages assessment intake, prioritization, scheduling, documentation, execution tracking, reporting, and vulnerability workflow oversight. The role blends deep cybersecurity risk expertise with strong program and project management discipline, leveraging Agile and Scrum‑based practices to meet defined SLAs, quality standards, and reporting expectations.
The Security Assurance Specialist III provides expert‑level technical guidance in evaluating and strengthening the security posture of Vanguard’s systems, architectures, and configurations. This role coordinates and leads comprehensive security assessments, validates risk findings, and supports remediation strategies across critical business applications, infrastructure, networks, and web platforms. Through close collaboration with technology and business partners, the specialist influences secure solution design, drives strategic security improvements, and supports the continuous maturation of Vanguard’s security capabilities.
**this Hybrid Role (in office Tues-Wed-Thurs) is based in Charlotte, NC, Dallas, TX, or Malvern, PA**
Key Responsibilities:
Education & Experience:
Bachelor’s degree in Information Security, Information Technology, Risk Management, or a related field (or equivalent experience).
5+ years of experience in cybersecurity, IT risk management, GRC, or security assessment coordination roles.
Demonstrated experience coordinating application and/or infrastructure security assessments in large, regulated, or complex environments.
Hands‑on experience with GRC platforms, preferably RSA Archer, including assessment tracking, findings management, and workflow.
Strong understanding of cybersecurity risk concepts, vulnerabilities, and control assessment practices.
Preferred Qualifications & Certifications:
Experience working with NIST CSF, NIST 800‑53, ISO 27001, CIS Controls, or similar frameworks.
Program or project management certifications (PMP, PgMP, PRINCE2) or Agile/Scrum certifications (CSM, SAFe, PMI‑ACP).
Familiarity with vulnerability management, remediation tracking, and risk acceptance processes.
Experience supporting metrics, dashboards, and SLA‑driven operational reporting.
Key Skills & Competencies:
Program & Project Management: Planning, prioritization, dependency management, and delivery execution.
Agile / Scrum Facilitation: Backlog management, impediment removal, team coordination.
Stakeholder Management: Ability to influence and coordinate across security, IT, and business teams.
Operational Rigor: Attention to detail, documentation quality, and audit readiness.
Communication: Clear, concise communication of technical risk information to varied audiences.
Process Improvement: Continuous improvement mindset with the ability to standardize and scale operations.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.