Talent Ops SME/SMR - Global Vulnerability Management - EY GDS
Job description
Job Summary:
The Ops SME/SMR for Global Vulnerability Management (GVM), is responsible for leading the organization's vulnerability management program, ensuring effective assessment, prioritization, remediation of security vulnerabilities across on-premises, cloud, application, database, and network environments. The role provides strategic oversight, governance, stakeholder management, and executive reporting to continuously strengthen the organization's cybersecurity posture and reduce technology risk.
Essential Functions of the Job:
Together with the AMS Lead:
• Define vulnerability management strategy, policies, standards, and procedures aligned with organizational risk appetite
• Lead and coordinate end-to-end vulnerability management activities across enterprise systems.
• Establish governance frameworks, remediation SLAs, and performance metrics
• Partner with infrastructure, cloud, application development, operations, and security teams to ensure timely vulnerability remediation
• Prioritize vulnerabilities based on risk, severity, exploitability, and business impact
• Monitor remediation progress and ensure adherence to established SLA requirements
• Present vulnerability risk posture and remediation progress to senior leadership and governance committees
• Support internal and external audits by providing evidence related to vulnerability management controls
• Ensure compliance with cybersecurity policies, security standards, and regulatory requirements
• Coordinate exception management processes and document risk acceptance decisions
• Act as an escalation point for critical and high-risk vulnerabilities
• Required 24/7 on-call support (e.g. escalations, vacation, holiday, weekend coverage)
• Working in a corporate IT environment with multiple disciplines to deliver projects in line with customer needs
• Working in a corporate IT environment in the Operational / Support Service Management role meeting ITIL framework
Analytical/Decision Making Responsibilities:
• Ability to prioritize tasks based on criticality.
• Must be able to work within a matrix organization – balancing the needs of the service line against firm initiatives and goals
• Must make decisions, such as prioritize relationships to develop, negotiate with customers and overcome obstacles
• Analyse trends to identify automation and optimization opportunities.
• Identify, manage and resolve complex issues, preventing escalations, where possible
• Manage, negotiate and resolve project risks effectively
• Demonstrate, by example, in-depth knowledge of the EY competency principles and practices, including coaching, learning and mentoring
• Leader and team player
• Create an open, honest, accountable and collaborative team environment
Knowledge and Skills Requirements:
• Strong understanding of Vulnerability Management and Cybersecurity principles
• High level understanding of service line business processes and application landscape.
• Understanding of CVSS scoring, Common Vulnerabilities and Exposures (CVE), and risk assessment methodologies
• Experience working with .Net Applications, Microsoft Azure, SQL/Oracle Databases
• Knowledge on network security, cloud platforms, and application security
• Relationship management (internal & external stakeholders)
• End to end understanding of IT life cycle (pipeline, resource, demand, project delivery, financial)
• 7+ years of application services and/or client/supplier relationship management in a technology environment
• Good business acumen and ability to negotiate with business partners
• Customer centric mindset and able to manage customer expectations
• Good executive presence
• Ability to develop strategic plans and translate them to actionable roadmaps
• Initiates, builds and maintains productive customer relationships
• Flexibility to adjust to multiple demands, shifting priorities, ambiguity and rapid change
• Knowledge of IT Infrastructure – Azure, Windows, SQL Server.
• Basic project management skills. Demonstrates strong understanding of scope, schedule and planning, time management, resource management and cost management.
Supervision Responsibilities:
• No direct reports
• Establish AMS governance processes, SOPs, and compliance guidelines.
• Working relationships (daily) with EY ITSD and AMS Lead
• Working relationships (daily) with TCS AMS team and Infosec Team
• ET Liaison
Other Requirements:
• Travel may be required (minimal)
• Fluent English speaker
• Excellent communication skills in English
Job Requirements:
Education:
• A degree in Computer Science and/or a business-related degree; or equivalent work experience
Experience:
• 10+ years in a corporate IT environment
• Minimum 5+ years in a corporate IT environment working in the Operational / Support Service Management role meeting ITIL framework.
• Minimum 5+ years in corporate IT environment working in security compliance and vulnerability remediation for Infra including Web/App Servers, DB Servers, Cloud.
• ServiceNow experience for ITIL
• Work experience in a professional services industry, preferred
Certification Requirements:
• Certifications in the following industry practices would be a plus (ITIL, BPM, etc)
• SAP SuccessFactors RCM/RMK/Onboarding Certification