Global Risk and Security (GR&S) at Vanguard enables business strategy protects client and Vanguard interests (e.g. assets and data) and stewards a strong risk culture. Our teams leverage enterprise-wide insights deep expertise and trusted advice so that across Vanguard leaders and crew drive faster stronger risk-informed decisions.
Within GR&S the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew property data and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged passionate and diverse talent expected to continuously learn and develop in an ever-changing security landscape.
Our crew are our greatest resource by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care work-life balance and an investment in your future at its core.
Core Responsibilities
- Maintain the Secure Developer Scorecard: Assist in the creation evolution and ongoing management of a secure developer scorecard that measures developer successes and failures in secure coding practices. Help ensure the scorecard reflects key metrics such as vulnerability prevention SDLC adherence time spent on secure coding and alignment with Vanguard-specific expectations.
- Support the Discovery of Community Bottlenecks: Proactively engage with the developer community to identify bottlenecks frustrations and barriers that delay code merges to production or lead to the dismissal of secure coding governance. Analyze feedback and data to pinpoint areas for improvement.
- Support Developer Engagement and Feedback Loops: Facilitate regular sessions with developers to listen gather insights and foster open dialogue about secure development challenges. Act as a liaison to gather developer input and share insights with the security and product teams
- Support the Creation of Business Cases for Secure Development Process Improvements: Translate developer feedback and scorecard insights into actionable business cases for process tooling or cultural changes. Support business case development by organizing feedback drafting summaries and preparing presentation materials for the Specialist/Manager.
- Conduct Learning and Awareness Activities: Develop and deliver targeted learning sessions workshops and awareness campaigns to promote secure coding practices and SDLC governance within the developer community.
Education & Experience Requirements
- Minimum 5 years of related work experience.
- Undergraduate degree in Computer Science Information Technology Cybersecurity Information Systems or a related field. Graduate degree in Cybersecurity Information Assurance or Computer Science is preferred but not mandatory.
- Candidates with relevant experience in cybersecurity software development or technologyrelated roles are encouraged to apply
- 12 years of experience in cybersecurity secure development awareness security awareness developer engagement or related technology roles. Broader experience in IT risk management or technical support may also be applicable.
- Direct developer experience is not strictly required. However candidates must demonstrate:
- Exposure to coding concepts; hands-on coding is not required.
- Awareness of SDLC and secure development principles; training and upskilling provided.
- Familiarity with common developer workflows tools and bottlenecks.
- Highly respected certifications: CISSP CSSLP. Desired: Security or equivalent foundational security certification. Considered: SSAP or similar credentials especially for candidates with a background in security awareness and developer enablement.
- Candidates lacking direct developer experience but possessing a strong background in cybersecurity awareness secure development advocacy or enterprise change management will be strongly considered.
Preferred Technical Skills & Tools
- Experience with any of the following is a plus:
- Using Wiz dashboards or similar tools for extracting insights and informing project decisions
- Qualys CloudFleet or other vulnerability management platforms
- AWS Azure GCP or OCI cloud environments
- Secure code training platforms
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard we dont just have a missionwere on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members designed to capture the benefits of enhanced flexibility while enabling in-person learning collaboration and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.