採用

Application Security Coordinator - Threat Modeling
Malvern; Charlotte; Dallas/Ft. Worth
·
On-site
·
Full-time
·
1mo ago
必須スキル
Project Management
Responsibilities:
Threat Modeling & Secure Design Coordination
- Provide programmatic support and coordination for application and infrastructure security assessments.
- Own and manage the threat modeling engagement from intake through final reporting and closure.
- Coordinate workshop scheduling across multiple concurrent engagements, balancing priorities, dependencies, and resource availability.
- Partner with application teams, infrastructure owners, and product stakeholders to gather pre workshop information, technical documentation, architecture diagrams, and required artifacts.
- Ensure threat modeling workshop scope, assumptions, and prerequisites are clearly defined and validated prior to execution.
2.Stakeholder Engagement & Partnership
- Serve as the primary coordination point between cybersecurity, engineering, architecture, and product stakeholders for threat modeling and secure design activities.
- Build strong relationships with development and infrastructure teams to promote early engagement with security and “shift‑left” practices.
- Clearly communicate expectations, timelines, and outcomes to both technical and non‑technical audiences.
- Escalate risks, delays, or blockers to appropriate leaders in a timely, structured manner.
Documentation, Tracking & Reporting
- Ensure threat modeling sessions and outcomes are accurately documented, including identified threats, assumptions, mitigations, and residual risks.
- Maintain high‑quality records in designated tools and repositories, ensuring traceability from threats to corresponding controls or backlog items.
- Support audit‑ready documentation and evidence requirements related to application and infrastructure security design.
- Produce regular reporting on volume, throughput, cycle times, and themes emerging from threat modeling activities.
Risk & Vulnerability Alignment
- Coordinate with vulnerability management and risk teams to align threat modeling outcomes with broader risk registers, remediation workflows, and standards.
- Ensure that critical threats and design weaknesses are properly logged, tracked, and dispositioned through established risk processes.
- Support remediation follow‑up by partnering with technology owners to monitor progress on agreed mitigations.
Agile Ways of Working & Coordination
- Apply program and project management best practices to manage complex, multi workstream assessment activities.
- Maintain assessment roadmaps, intake queues, and execution plans aligned to business and technology priorities.
- Leverage Agile and Scrum style practices where appropriate, including backlog management, sprint planning, stand ups, retrospectives, and dependency tracking.
- Act as a servant‑leader / facilitator for security‑focused work, removing impediments and enabling smooth execution across teams.
- Contribute to the refinement of threat modeling playbooks, templates, and checklists to drive consistency and ease of use.
Education & Experience:
Bachelor’s degree in Information Security, Information Technology, Risk Management, or a related field (or equivalent experience).
Experience (typically 5+ years) in application security, cybersecurity, IT risk management, software engineering, or technology program coordination.
Demonstrated experience coordinating or facilitating security activities such as threat modeling, security architecture reviews, or application/infrastructure security assessments in large, regulated, or complex environments.
Strong understanding of cybersecurity risk concepts (e.g., vulnerability, risk, threat, attack surface, mitigation)
Understanding of software development lifecycles (Agile, DevOps, CI/CD)
Preferred Qualifications:
Familiarity with structured threat modeling approaches and tools (e.g., STRIDE‑style analysis, attack trees, or similar methodologies).
Familiarity with security and risk frameworks such as NIST CSF, NIST 800‑53, ISO 27001, or CIS Controls.
Program or project management certifications (PMP, PgMP, PRINCE2) or Agile/Scrum certifications (CSM, SAFe, PMI ACP).
Familiarity with vulnerability management, remediation tracking, and risk acceptance processes.
Experience supporting metrics, dashboards, and SLA driven operational reporting.
Key Skills & Competencies
Project Management: Planning, prioritization, dependency management, and delivery execution.
Agile / Scrum Facilitation: Backlog management, impediment removal, team coordination.
Stakeholder Management: Ability to influence without authority across security, IT, and business teams.
Operational Rigor: Attention to detail, documentation quality, and audit readiness.
Communication: Clear, concise communication of technical risk information to varied audiences.
Process Improvement: Continuous improvement mindset with the ability to standardize and scale operations.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
総閲覧数
0
応募クリック数
0
模擬応募者数
0
スクラップ
0
類似の求人

Quantitative Investment Analyst
Fidelity · Boston, Massachusetts, USA

Medicare Sales Field Agent - San Diego, CA
Humana · San Diego, CA

Interest in EY?
EY ·

Sourcing Specialist, Indirect Purchasing (Starlink)
SpaceX · Redmond, WA

UKI Business Consulting - Transformation Architecture, Energy & Utilities, SC / AM
EY ·
Vanguardについて

Vanguard
PublicA client-owned investment company that offers low-cost mutual funds, ETFs, advice, and related services to institutional and individual investors, and financial professionals.
10,001+
従業員数
Kelayres
本社所在地
レビュー
4.1
10件のレビュー
ワークライフバランス
3.8
報酬
2.5
企業文化
4.2
キャリア
3.2
経営陣
4.3
75%
友人に勧める
良い点
Supportive management and leadership
Great work-life balance and flexibility
Strong team collaboration and culture
改善点
Low or non-competitive compensation
Limited career advancement and promotions
Heavy workload and long hours
給与レンジ
756件のデータ
Junior/L3
Mid/L4
Senior/L5
Director
Junior/L3 · Assistant Operations Manager
1件のレポート
$104,000
年収総額
基本給
$80,000
ストック
-
ボーナス
-
$104,000
$104,000
面接体験
3件の面接
難易度
3.0
/ 5
期間
14-28週間
面接プロセス
1
Application Review
2
Online Assessment/Case Study
3
Phone Interview
4
Technical Interview
5
Final Round Interview
6
Offer
よくある質問
Technical Knowledge
Behavioral/STAR
Past Experience
Case Study
Coding/Algorithm
ニュース&話題
Vanguard to Update Names of U.S. Equity Index Funds Tracking Morningstar Indexes - PR Newswire
PR Newswire
News
·
4d ago
VOO vs. VGT: Which Vanguard ETF Has More Room to Run in 2026? - TipRanks
TipRanks
News
·
5d ago
FHSAA flag football highlights from Deltona vs. Vanguard playoff game - Daytona Beach News-Journal
Daytona Beach News-Journal
News
·
5d ago
Vanguard Bundles Bond ETFs Into Ready-Made Income Portfolios - Vanguard Target Maturity 2027 Corporate Bo - Benzinga
Benzinga
News
·
5d ago