Apply now »

Talent Operate - InfoSec EXP/RP & GVM Remediation Lead - EY GDS

Location:  CABA
Other locations:  Primary Location Only
Salary: Competitive
Date:  3 Sept 2026

Job description

Requisition ID:  1739656

Talent Operate – InfoSec EXP/RP & GVM Remediation Lead
Role Overview
The InfoSec EXP/RP & GVM Remediation Lead is responsible for driving the end-to-end remediation of security vulnerabilities, risk exceptions, and compliance findings across Talent applications. This role partners with Product Owners, Application Leads, Infrastructure, InfoSec, and vendor teams to ensure timely risk mitigation, governance compliance, audit readiness, and reduction of overall security risk exposure.
Key Responsibilities
1.    Own and drive the remediation of InfoSec findings, GVM vulnerabilities, and security risks across Talent applications.
2.    Review, triage, prioritize, assign, and track GVM vulnerabilities through resolution.
3.    Coordinate remediation activities with Application Leads, Product Owners, Infrastructure teams, vendors, and InfoSec stakeholders.
4.    Manage the complete lifecycle of Security Exceptions (EXP) and Risk Profiles (RP), including submission, review, approval, renewal, and closure.
5.    Monitor aging vulnerabilities, exceptions, and remediation plans; escalate overdue items and critical risks to leadership.
6.    Maintain remediation trackers, security documentation, audit evidence, and compliance records.
7.    Facilitate regular governance reviews to track remediation progress, open risks, and compliance obligations.
8.    Develop and maintain dashboards, metrics, and executive reporting for GVM, EXP, RP, and remediation activities.
9.    Support security and compliance assessments related to infrastructure upgrades, application changes, and environment refresh activities.
10.    Drive continuous improvement initiatives to reduce recurring vulnerabilities and strengthen the Talent security posture.
11.    Ensure adherence to EY security policies, standards, regulatory requirements, and audit expectations.
Required Skills
1.    Strong understanding of vulnerability management, risk remediation, and security governance processes.
2.    Experience managing GVM findings, remediation plans, security exceptions, and risk acceptance processes.
3.    Excellent stakeholder management skills with the ability to coordinate across Product, Application, Infrastructure, Vendor, and Security teams.
4.    Strong analytical, prioritization, and risk management capabilities.
5.    Experience developing and maintaining dashboards, reporting, and remediation metrics.
6.    Strong communication and presentation skills for leadership, audit, and governance forums.
7.    Ability to manage multiple remediation initiatives and competing priorities across global teams.
Preferred Qualifications
1.    Experience working within enterprise security, compliance, or risk management programs.
2.    Familiarity with EY security standards, audit requirements, and governance processes.
3.    Knowledge of vulnerability management tools and security reporting platforms.
4.    Experience supporting infrastructure refreshes, application upgrades, and security compliance initiatives.
5.    Security-related certifications (e.g., Security+, CISSP, CISM, CRISC, ISO 27001) preferred.
Key Success Measures
•    Reduction in overdue GVM vulnerabilities and EXP/RP items.
•    Achievement of remediation SLA and compliance targets.
•    Timely approval, renewal, and closure of security exceptions.
•    Accurate reporting, audit readiness, and governance compliance.
•    Improved visibility of security risks and remediation progress.
•    Reduction in overall security risk exposure across Talent applications.

Apply now »