Are you applying to the internship?
Job Description
Program Coordinator, Threat Modeling & Secure Design | Vanguard
The Tone:
This is a full-time role at Vanguard, operating under a hybrid working model. Vanguard is on a mission to work for the long-term financial well-being of its clients, leading through products and services that transform client lives. In this pivotal role, you will be instrumental in coordinating complex security assessments and driving “shift-left” security practices, ensuring Vanguard’s applications and infrastructure are designed with security at their core.
The TL;DR
• Role: Full Time
• Type: Full-time
• Location: Hybrid working model
• Team: Cybersecurity team
• Mission: Own the end-to-end threat modeling engagement process, ensuring applications and infrastructure are designed with security at their core.
What You’ll Actually Do
• Threat Modeling Coordination: Own and manage the threat modeling engagement process from intake through final reporting and closure.
• Stakeholder Engagement: Serve as the primary coordination point for secure design activities between cybersecurity, engineering, architecture, and product stakeholders.
• Documentation & Reporting: Ensure threat modeling sessions and outcomes are accurately documented in designated tools, supporting audit readiness and producing regular reports.
• Risk Alignment: Coordinate with vulnerability management and risk teams to align threat modeling outcomes with broader risk registers and remediation workflows.
• Agile Ways of Working: Apply program and project management best practices to manage assessment activities, leveraging Agile and Scrum style practices where appropriate.
The Must-Haves
• Background: Bachelor’s degree in Information Security, Information Technology, Risk Management, or a related field (or equivalent experience).
• Experience: Typically 5+ years of experience in application security, cybersecurity, IT risk management, software engineering, or technology program coordination, with demonstrated experience coordinating or facilitating security activities like threat modeling or security architecture reviews in large, regulated, or complex environments.
• Skills: Project management (planning, prioritization, dependency management), Agile / Scrum facilitation (backlog management, impediment removal), stakeholder management (influencing without authority), operational rigor (attention to detail, documentation quality), and clear communication of technical risk information.
• Bonus: Familiarity with structured threat modeling approaches (e.g., STRIDE-style analysis) or tools, security and risk frameworks (e.g., NIST CSF, ISO 27001), program/project management or Agile/Scrum certifications, and experience with vulnerability management or metrics and dashboard reporting.