EYP-IDD-Assistant Manager
EY
EY
Join EY, a global leader, and shape a career as unique as you are. Leverage our expansive resources, inclusive culture, and cutting-edge technology to achieve your full potential. Your distinct perspective is invaluable in helping EY achieve greater heights. Together, we can craft exceptional personal experiences and foster a better world of work for everyone.
We are seeking a cyber strategy professional for our Strategy & Execution team, operating as an Assistant Manager. This role blends hands-on expertise in cybersecurity, architecture, and privacy with experience in transaction advisory. You will guide private equity investors and corporate clients through Cyber Due Diligence, post-deal integration, cybersecurity assessments, and privacy compliance using frameworks like GDPR. Collaborate with diverse teams to evaluate critical controls, translate technical findings into business implications, and develop actionable recommendations and roadmaps. This is a prime opportunity to expand your M&A lifecycle experience and deepen your skills in cyber strategy, transformation, and execution.
Support global EY practice teams in managing cybersecurity and privacy engagements throughout the M&A transaction lifecycle. Conduct thorough buy-side, sell-side, and red-flag Cyber Due Diligence to pinpoint material risks and evaluate transaction impacts, providing clear recommendations and cost considerations for remediation.
Aid in cyber workstreams for post-deal integration, carve-outs, and separations, focusing on Day 1 readiness, 100-day planning, transition requirements, and TSA dependencies. Perform comprehensive cybersecurity maturity assessments against established standards, identifying gaps, benchmarking capabilities, and developing prioritized improvement plans. Evaluate privacy and data protection compliance with regulations like GDPR, covering governance, data lifecycle, third-party processing, and data subject rights.
Assess a wide range of cybersecurity capabilities, including network security, identity and access management, privileged access, security operations, vulnerability management, incident response, cloud security, and endpoint protection. Analyze transaction-specific risks related to shared infrastructure, applications, identities, security tools, data, third parties, and transitional service agreements. Assist in designing target-state security architectures, operating models, governance frameworks, policies, and implementation roadmaps. Conduct targeted external research, including OSINT and dark web analysis, as needed. Effectively communicate complex findings into understandable business risks and actionable recommendations. Prepare high-quality deliverables such as diligence reports, gap analyses, risk registers, and executive presentations. Manage assigned tasks, coordinate with stakeholders, monitor timelines and quality, and guide junior team members. Foster strong relationships with regional EY-Parthenon teams and contribute to proposals and practice development initiatives.
Demonstrated experience in delivering cybersecurity engagements, including Cyber Due Diligence, post-deal integration or separation, cybersecurity maturity assessments, privacy assessments, or cyber transformation projects. Ability to manage defined workstreams, engaging effectively with client stakeholders and multidisciplinary advisory teams.
Possess a strong grasp of security architecture and design principles, such as Zero Trust, defence in depth, and secure-by-design concepts. Capable of facilitating stakeholder discussions, gathering and scrutinizing information, presenting findings clearly, and supporting decision-making under senior guidance. Exhibit strong analytical and commercial judgment, linking technical findings to business risks, deal value, and implementation priorities. Excellent written and verbal communication skills, with a proven track record of producing concise, executive-ready deliverables using PowerPoint, Word, and Excel.
Bring an innovative and collaborative mindset, adept at developing practical solutions tailored to client and transaction needs. Possess the ability to mentor junior team members and contribute to recruitment, training, and wider practice development activities. Flexibility to support broader IT, cybersecurity, and operational transaction work, including international travel as required.
To be successful, you must have four to six years of experience in information and cybersecurity, with exposure to M&A, cyber or privacy assessments, security architecture, security operations, or related consulting. A B.E., B.Tech., or equivalent degree in Computer Science or Information Technology from a reputable institution is required; an MBA or PGDM from a Tier 1 or Tier 2 institution is preferred. A leading cybersecurity qualification (CISSP, CISA, CCSP, CISM, or ISO 27001 ISMS) is essential. Familiarity with cybersecurity and privacy regulations like GDPR, NIS2, CCPA, and relevant frameworks is necessary. Experience with recognized cybersecurity frameworks such as NIST CSF, ISO 27001, CIS Controls, and PCI DSS is required. A strong understanding of network and cloud security, IAM, PAM, and security operations, including SIEM, threat monitoring, incident response, and vulnerability management, is crucial. Knowledge of OT security is a plus.
EY Global Delivery Services ( EY GDS)
Management Consulting