Vanguard Logo

Vanguard

Incident Response Specialist

Reposted 13 Days Ago
Be an Early Applicant
In-Office
Melbourne, Victoria, AUS
Mid level
In-Office
Melbourne, Victoria, AUS
Mid level
Respond to and resolve complex security incidents, perform root-cause analysis, build detections and automation, monitor third-party suppliers, conduct audits, correlate data from CND tools, and coordinate cross-functional and executive communications to improve security posture.
The summary above was generated by AI

About Vanguard  

More than 45 years ago, John C. Bogle had a vision to start an investment company that did things differently. A company with no external shareholders. Where all the profits were invested back into the business and used to lower costs. Evidently, it was as bold as it was brilliant. To this day, Vanguard Group still has no external shareholders. That means no share prices to protect, and no profits to generate for outside owners.   

Today, Vanguard is one of the world’s largest investment management companies, serving more than 50 million investors worldwide. For more than 30 years Vanguard Australia has been supporting individual investors, financial advisers, and superannuation 

Role Summary

This role responds to and resolves complex incidents, proactively preventing their reoccurrence, and acts as a point of escalation for junior peers. This role also collects and correlates data from CND tools and coordinates with teams to ensure effective incident handling and security improvement.

Responsibilities

  • Responds to and resolves complex incidents and security issues. Determines the root cause and implements corrective action with appropriate level of assistance. Elevates potential concerns and gaps as appropriate.

  • Monitors Third-Party suppliers for security incidents, security posture changes, networks and endpoints. Produces detailed reports for management, including findings and operation status.

  • Conducts periodic recertification of all tasks and process documentation. Monitors the infrastructure and contractors for security events and provides response to elevated. Identifies computer security requirements for new systems and/or processes under development.

  • Maintains up-to-date documentation, procedures, and workflows to assist in performing event & incident investigations. Identifies opportunities to improve the efficiency and effectiveness of processes and procedures.

  • Performs security audits on a regular basis to ensure compliance with security policies and standards.

  • Monitors threat intelligence for security incidents, security posture changes and critical vulnerabilities.

  • Build, deploy and maintain detections and automation to enable the monitoring and incident response with security incidents involving third-party suppliers.

  • Participates in special projects and performs other duties as assigned.

  • Collect and correlate data from various Computer Network Defense (CND) tools such as intrusion detection system alerts, firewall logs, network traffic logs, and host system logs to identify and evaluate security events.

  • Ability to communicate to senior leadership during a security incident across the business.

  • Coordinate with internal teams and external entities for effective incident handling, ensuring swift resolution and continuous improvement of security practices.

Qualifications and Skills

  • Minimum 4 years of experience in cybersecurity operations or incident response, with expertise in monitoring, detection, and resolution of security events.

  • Bachelor’s degree (B.E./B.Tech) in Computer Science, Information Technology, Cybersecurity, or a related field or a Master’s degree/Diploma in Computer Science or Cybersecurity.

  • Strong understanding of security tools including SIEM, IDS/IPS, firewalls, and log management tools

  • Experience in using ticketing systems like JIRA or ServiceNow and knowledge of incident lifecycle and threat intelligence practices.

  • Experience with cloud security (AWS, Azure) and managing endpoint detection and response (EDR) tools.

  • Must have strong documentation skills and familiarity with reporting tools for management dashboards and compliance tracking.

  • Ability to work in an Agile/DevSecOps environment and contribute to continuous process improvements in cybersecurity workflows.

  • Experience with security orchestration, automation, and response (SOAR) capabilities.

  • Exposure to threat hunting, detection engineering, or advanced cyber defense operations.

  • Demonstrated ability to lead incident response efforts and influence cross-functional teams.

  • Excellent written and verbal communication skills, including the ability to create technical documentation and executive-level reporting.

Inclusion Statement 

Vanguard’s continued commitment to diversity and inclusion is firmly rooted in our culture. Every decision we make to best serve our clients, crew (internally employees are referred to as crew), and communities is guided by one simple statement: “Do the right thing.” 

We believe that a critical aspect of doing the right thing requires building diverse, inclusive, and highly effective teams of individuals who are as unique as the clients they serve. We empower our crew to contribute their distinct strengths to achieving Vanguard’s core purpose through our values. 

When all crew members feel valued and included, our ability to collaborate and innovate is amplified, and we are united in delivering on Vanguard’s core purpose. 

Our core purpose: To take a stand for all investors, to treat them fairly, and to give them the best chance for investment success.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Similar Jobs

23 Minutes Ago
Hybrid
Melbourne, Victoria, AUS
Senior level
Senior level
Cloud • Fintech • Information Technology • Machine Learning • Software
Build and maintain SQL data models, dbt pipelines, governed Snowflake semantic layers, and data products supporting Finance, People Experience, and Legal. Ensure data quality, testing, documentation, and reliable reporting for executive and market-facing insights. Collaborate with business teams to translate questions into trusted metrics, contribute to conversational AI and agentic data capabilities, mentor teammates, and establish consistent engineering standards.
Top Skills: DbtMcp IntegrationsSnowflakeSQL
An Hour Ago
Hybrid
Melbourne, Victoria, AUS
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead talent acquisition strategy and full-cycle recruiting for Sales and Go-to-Market teams across Australia, New Zealand, and the broader APJ region. Partner with senior leaders on workforce planning, build talent pipelines, apply data and market intelligence to hiring decisions, and improve assessment and recruiting processes through AI and automation. Coach another recruiter, manage recruiting metrics and systems, and support regional talent initiatives.
Top Skills: AIBrighthireCandidate.FyiGreenhouseSaaSWorkday
Yesterday
Remote or Hybrid
4 Locations
Entry level
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Investigate and respond to security detections across endpoint, identity, email, network, and cloud environments. Analyze EDR telemetry, logs, forensic artifacts, Microsoft 365 threats, and malware to determine compromise scope and recommend remediation. Handle incidents including business email compromise and adversary-in-the-middle attacks, improve detection and response processes, and communicate findings and guidance clearly to customers and internal teams.
Top Skills: Ai TechnologiesEdrLinuxmacOSMicrosoft 365Mitre Att&CkPrompt EngineeringWindows

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account