Enterprise Security Governance Analyst executing governance programs and supporting security assessments at Vanguard. Engaging with cross-functional teams and maintaining documentation for physical security governance.
Responsibilities
Executes assigned components of Global Physical Security governance programs, including documentation development, updates, evidence collection, control support activities, and remediation tracking
Supports the creation, application, and maintenance of enterprise security policies, standards, controls, procedures, and governance reporting
Maintains governance artifacts, templates, and process documentation in alignment with ASIS, ISO, regulatory, and other best‑practice guidance
Maintains document lifecycle hygiene for assigned governance artifacts, including version control, scheduled review tracking, updates, and publication readiness
Ensures documentation accuracy, consistency, and accessibility to support audits, assurance activities, and leadership reporting
Supports governance and program assessments through structured reviews of security practices, physical security configurations, access control processes, threat management documentation, and related activities
Performs data validation, analysis, and tracking to support program transparency, issue identification, and progress monitoring
Supports execution of assigned security controls, including evidence validation, control testing support, and tracking of control effectiveness over time
Supports quality assurance activities by identifying inconsistencies, documentation gaps, or execution issues and escalating as appropriate
Prepares dashboards, metrics, and governance reports that communicate program status, risks, and remediation progress
Supports recurring governance reporting cycles and standing governance routines
Drafts and maintains security plans, annexes, procedures, and playbooks under direction of governance leadership or specialists
Develops exercise products, including situation manuals, exercise plans, after‑action reports, and improvement plans
Supports exercise execution activities, including coordination, documentation during exercises, and tracking of improvement actions
Coordinates with domestic and international stakeholders, including security teams, facilities, cyber, operational risk, and regulatory partners, to support governance execution and information gathering
Tracks remediation activities and follow‑up actions
Escalates issues, risks, or execution gaps in accordance with established governance processes
Contributes to maturity assessments, operational improvement initiatives, and modernization efforts as assigned.
Requirements
5 years of experience in security management, physical security, emergency management, threat assessment/risk management, business continuity, or related disciplines
Strong organizational skills with demonstrated experience managing detailed workstreams and recurring activities
Strong written communication skills, including drafting plans, policies, procedures, playbooks, checklists, project documentation, and exercise materials
Broad experience developing exercise products, including situation manuals, exercise plans, after‑action reports, and improvement plans, preferred
Knowledge and experience with incident command systems and effective crisis management response processes
Undergraduate degree required or equivalent combination of training and experience.
Cyber Security Engineer II safeguarding systems at MSK, involved with complex technologies in cancer care security. Lead threat investigations and apply technical knowledge for security improvements.
Principal Security Engineer working on network security lifecycle and threat management for Verizon’s 4G/5G Cloud Networks. Collaborating with multiple teams to enhance cybersecurity posture.
Cybersecurity Engineer at Verizon responsible for security lifecycle and effectiveness across networks. Leading incident response and vulnerability management in a hybrid work role.
Director of Security and Compliance safeguarding digital assets and data with a focus on cybersecurity and compliance. Leading risk management, stakeholder engagement, and team leadership initiatives.
Information Security Risk & Compliance Analyst at AAB focusing on ISO 27001 compliance and information security management. Collaborating across teams to ensure robust risk and compliance frameworks.
Information Security Risk & Compliance Analyst at AAB managing compliance with ISO 27001, supporting enterprise risk assessments and enhancing information security systems.
Information Security Risk & Compliance Analyst supporting the maintenance of ISO 27001 standards. Contributing to risk assessments and compliance across AAB’s Business Protection Team.
Security Principal at Optiv designing AI security solutions for clients, leveraging advanced security services and technologies. Driving pipeline generation and maintaining strong client relationships as a trusted advisor.
Cloud Security Architect supporting federal customer projects focused on architecture and security solutions. Conducting risk assessments and defining security requirements within a cloud environment.
Information Security Specialist responsible for enhancing cybersecurity posture through incident management and compliance. Collaborating with cross - functional teams to monitor threats and implement security measures.