|
Job Summary:
(Briefly describe the main objectives and purpose of the job. Why does the job exist? What is it expected to accomplish?)
The Ops SME is responsible for overseeing vulnerability management activities across the organization's infrastructure, applications, databases, and cloud environments. The role focuses on identifying, assessing, tracking, and remediating security vulnerabilities while ensuring compliance with cybersecurity policies, regulatory requirements, and internal risk management standards.
|
|
Essential Functions of the Job:
(Describe essential functions, or primary duties and responsibilities. Assume the reader does not know the role or function of the job.)
Together with the AMS Lead:
- Lead and coordinate end-to-end vulnerability management activities across enterprise systems.
- Review and analyse vulnerability scan results
- Prioritize vulnerabilities based on risk, severity, exploitability, and business impact
- Collaborate with application, infrastructure, cloud, database teams and vendors to drive timely remediation
- Monitor remediation progress and ensure adherence to established SLA requirements
- Prepare and present periodic vulnerability metrics, dashboards, and executive reports
- Support internal and external audits by providing evidence related to vulnerability management controls
- Ensure compliance with cybersecurity policies, security standards, and regulatory requirements
- Coordinate exception management processes and document risk acceptance decisions
- Act as an escalation point for critical and high-risk vulnerabilities
- Required 24/7 on-call support (e.g. escalations, vacation, holiday, weekend coverage)
- Working in a corporate IT environment with multiple disciplines to deliver projects in line with customer needs
- Working in a corporate IT environment in the Operational / Support Service Management role meeting ITIL framework
|
|
Analytical/Decision Making Responsibilities:
(Describe the kind of problems and challenges typically faced, and decisions required to perform the job, as well as recommendations made to supervisors or others. Focus on the nature of existing policies, precedents and procedures used to guide decisions, and the degree to which the incumbent is free to make decisions requiring interpretation and judgment. Provide an example.)
- Ability to prioritize tasks based on criticality.
- Must be able to work within a matrix organization – balancing the needs of the service line against firm initiatives and goals
- Must make decisions, such as prioritize relationships to develop, negotiate with customers and overcome obstacles
- Analyse trends to identify automation and optimization opportunities.
- Identify, manage and resolve complex issues, preventing escalations, where possible.
- Manage, negotiate and resolve risks effectively
- Demonstrate, by example, in-depth knowledge of the EY competency principles and practices, including coaching, learning and mentoring
- Create an open, honest, accountable and collaborative team environment
|
|
Knowledge and Skills Requirements:
(Describe the knowledge or skills needed to perform this job; these may be technical, managerial or behavioral in nature.)
- Strong understanding of Vulnerability Management and Cybersecurity principles
- High level understanding of service line business processes and application landscape.
- Understanding of CVSS scoring, Common Vulnerabilities and Exposures (CVE), and risk assessment methodologies
- Experience working with .Net Applications, Microsoft Azure, SQL/Oracle Databases
- Knowledge on network security, cloud platforms, and application security
- Relationship management (internal & external stakeholders)
- End to end understanding of IT life cycle (pipeline, resource, demand, project delivery, financial)
- 7+ years of application services and/or client/supplier relationship management in a technology environment
- Good business acumen and ability to negotiate with business partners
- Customer centric mindset and able to manage customer expectations
- Good executive presence
- Ability to develop strategic plans and translate them to actionable roadmaps
- Initiates, builds and maintains productive customer relationships
- Flexibility to adjust to multiple demands, shifting priorities, ambiguity and rapid change
- Knowledge of IT Infrastructure – Azure, Windows, SQL Server.
- Basic project management skills. Demonstrates strong understanding of scope, schedule and planning, time management, resource management and cost management.
|
|
Supervision Responsibilities:
(Describe the level of supervision received (i.e., the frequency of supervisory contact, degree to which the individual acts independently and on what kinds of issues). Describe the level of supervision of others, if any (i.e., assigning work, reviewing performance, direct or indirect responsibility).
- No direct reports
- Establish AMS governance processes, SOPs, and compliance guidelines.
- Working relationships (daily) with EY ITSD and AMS Lead
- Working relationships (daily) with TCS AMS team and Infosec Team
- ET Liaison
|
|
Other Requirements:
(Describe other functions or expectations of the job such as whether overtime is regularly required (e.g., during busy season?), whether there are particular times of the year that vacation may not be taken, whether there is frequent travel, whether there are any physical requirements beyond those expected in a normal office environment or any other miscellaneous things about the job that should be made known.)
- Travel may be required (minimal)
- Fluent English speaker
- Excellent communication skills in English
|
|
Job Requirements:
|
|
Education:
(What is the minimum level of education needed/suggested to perform this job?)
- A degree in Computer Science and/or a business-related degree; or equivalent work experience
|
|
Experience:
(What is minimum number of years needed/suggested to perform this job?)
- 7+ years in a corporate IT environment
- Minimum 3+ years in a corporate IT environment working in the Operational / Support Service Management role meeting ITIL framework.
- Minimum 3+ years in corporate IT environment working in security compliance and vulnerability remediation for Infra including Web/App Servers, DB Servers, Cloud.
- ServiceNow experience for ITIL
- Work experience in a professional services industry, preferred
|
|
Certification Requirements:
(Describe and explain any certifications and/or licenses needed or helpful to perform this job).
- Certifications in the following industry practices would be a plus (ITIL, BPM, etc)
|