ET Stay-In-Compliance Consultant
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
ET Stay-In-Compliance Consultant
EY is a global leader in assurance, tax, transaction and advisory services. Technology is at the heart of what we do and deliver at EY. Technology solutions are integrated in the client services we deliver and are key to our innovation as an organization. Fueled by a US$1.5+B investment in technology and innovation, EY is primed to guide clients in their efforts to drive sustainable growth, create new value, and build new and better ways of working. As part of Enterprise Technology, you’ll be at the forefront of integrating technology into what we do at EY. That means more growth for you, exciting learning opportunities, career choices and the chance to make a real impact.
The role
Stay-In-Compliance Consultant is responsible for overseeing vulnerability management for ET (excluding Platform Mgmt) and managing risk mitigation activities.
This position requires close collaboration with global teams across ET, Infosec and business functions to align the risk processes with the broader frameworks. The consultant will also be responsible for driving compliance to vulnerability mgmt goals, ensuring that vulnerabilities are either remediated or plans are approved within the defined SLA targets. Responsibilities also include monitoring, reporting, and providing insights on compliance status through regular assessments, on-going leadership reviews and real-time dashboards.
As part of the role the individual will be responsible to assess the existing processes, refine as per the changing business needs (e.g. define the governance framework to manage vulnerabilities with unknown owners) working closely with Infosec and other stakeholders and develop / deploy governance models to operationalize the processes within Enterprise Technology. The ideal candidate brings deep expertise in IT risk management, governance, and operational resilience, playing a pivotal role in strengthening EY’s overall risk management plan.
Your key responsibilities
As the Stay-In-Compliance Consultant, the key responsibilities would include:
- Ensure Global Vulnerability mgmt compliance plans are developed / remediated as per business requirements for all in scope IT functions within Enterprise Technology (excluding Platform Mgmt); Drive GRAC plans for in-scope I&O functions
- Responsible for vulnerability identification and remediation with the product group; maintain a comprehensive plan for remediation / exception through data-driven insights and analytics
- Responsible for compliance management within agreed SLA’s as established by Infosec, tracking the progress of vulnerability remediation, and adherence to security policies
- Establishing a governance framework / review mechanism with ET & Infosec leaders on SIC updates to provide insights into vulnerability mgmt on a weekly / monthly basis
- Policy and Procedure Oversight – Partner with Infosec and other relevant stakeholders in enforcing the policies and procedures that govern the organization's activities, ensuring they are in line with best practices and regulatory expectations
- Establishing and maintaining a control framework that guides the operation of risk management and compliance activities.
- Collaborate with Infosec and I&O product managers to understand the as-is and road map for future products
- Accountable for end-to end life cycle management of vulnerabilities for ET (excluding Platform Management), work on the remediation plans with the product owners, work on necessary approvals and driving remediations to closure
- Work closely with Infosec and stakeholders within ET for Critical Vulnerability Response Plan (CVRP) exercise
- Vulnerability management reporting
- Collaborate with stakeholders: Need to collaborate with various stakeholders and act as a conduit between Infosec, Product/Application, Engineering, Operations & Management, also responsible to provide technical assistance to address vulnerabilities.
- Vulnerability remediation for Data Restricted Countries (DRCS) and Local Support teams (excluding Platform Management): This role plays a pivotal role in coordinating with Infosec, product teams, DRCS and local support teams to drive remediation in DRCS countries and help local support teams to address vulnerabilities.
- Risk Assessment and Mitigation: Identifying, assessing, and prioritizing risks to the organization, and implementing strategies to mitigate their impact for I&O (excluding Platform Mgmt).
- Compliance Management: Ensure that in-scope portfolios for I&O adhere to GCoC recommended policies, compliances, regulations and standards.
Skills and attributes for success
- Well experienced in managing key Stakeholder relationships, including Senior Management.
- In-depth understanding of Industry GRAC and vulnerability mgmt Standards
- Should have strong knowledge of other Risk domains like Operations Risk Management, IT Security, Cyber Risks, to be able to evaluate these Risks.
- Should possess good working knowledge about IT Operations and IT practices.
- Can work with minimum direction. Possess a high drive for delivering timely, high-quality results.
- Hold high integrity; dedicated to excellence; highly attentive to details; flexible. Possess strong Project Management skills.
- Self-motivated, with ability to work independently, as well as with other stakeholders in a collaborative manner.
- Strong problem-solving skills
- A proven expert in managing multiple stakeholders at all levels of the organization, specifically at senior management level.
- Excellent communication skills, especially related to facilitation, documentation and reporting
- Supervisory skills and the ability to leverage support from other parts of the organization
- Ability to work with cross-functional stakeholders and senior leadership
To qualify for the role, you must have
Education:
- Bachelor or Master’s degree in Information Technology / Engineering
Experience:
- 10 -12+ years of relevant experience in Service Delivery
What we look for
- Thought leadership
- Strategic Thinking
- Automation & standardization
- Relationship Management
- Interpersonal & Influencing skills
- Good communication skills
- Data-driven decision making
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.