Stay In Compliance Lead - DWES
EY
EY
Join EY and advance your career in a role focused on digital workplace compliance. As the Stay In Compliance Lead within Digital Workplace & Experience Services (DWES), you will shape and enforce the strategy ensuring endpoints, collaboration tools, and Microsoft 365 services remain current, secure, and aligned with industry standards.
This position drives the ongoing maintenance of the digital workplace environment, covering Windows and macOS endpoints, mobile devices, virtual solutions, and key M365 platforms. Your efforts will involve leading software upgrades, security patching, hardware refresh governance, and configuration management to mitigate risks and maintain a secure operational state.
By leveraging advanced tools and intelligence platforms, you'll proactively identify and address security risks, assessing the digital workplace's exposure to emerging threats. Collaborating with various internal teams and external partners, you will champion enterprise-wide compliance initiatives and enhance the organization's overall security posture. This role is pivotal for global endpoint and platform lifecycle governance, vulnerability management, and risk reduction.
Spearhead the DWES vulnerability management program, overseeing identification, assessment, prioritization, remediation, and reporting across all DWES products.
Develop and execute a comprehensive roadmap for vulnerability remediation and risk management, utilizing data analytics and risk-based prioritization to minimize security exposure.
Establish and implement global compliance plans for vulnerability management across a wide range of endpoints and M365 platforms.
Govern the end-to-end remediation process for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions.
Maintain accountability for compliance with remediation Service Level Agreements (SLAs) and security standards, tracking performance and aging across the DWES estate.
Partner with key stakeholders, including Information Security, Product Owners, and various IT teams, to ensure effective security remediation activities.
Define, implement, and continuously improve policies, standards, processes, and procedures for vulnerability management, software currency, hardware lifecycle, and security remediation.
Establish a robust controls framework for governance, auditability, compliance monitoring, and risk management within DWES services.
Lead DWES participation in critical vulnerability response and enterprise-wide cyber response activities.
Continuously monitor OEM advisories, security bulletins, and threat intelligence feeds to identify risks impacting DWES infrastructure.
Collaborate with vendors and OEMs to assess emerging threats and recommended mitigations.
Drive the execution of critical security patching, emergency remediation, and infrastructure upgrades.
Serve as the primary DWES representative for security vulnerability management and risk response within the Intelligent Operations Center (IOC).
Review and validate risk exception requests, ensuring thorough documentation of justification, controls, and business impact.
Provide technical guidance and risk advisory support to leadership and stakeholders on remediation strategies and compliance obligations.
Develop and publish executive dashboards and management reports on vulnerability exposure, remediation progress, security compliance, and risk posture.
Define and monitor Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to measure program effectiveness.
Drive automation and process improvement initiatives for vulnerability assessment, remediation tracking, software upgrades, and compliance reporting.
Partner with Service Management teams to ensure adherence to governance, change management, and ITSM requirements.
Own stakeholder communications regarding security vulnerabilities, remediation plans, and risk mitigation strategies.
Lead incident-related vulnerability remediation and coordinate technical teams for timely stakeholder communication.
Manage the DWES Stay In Compliance team, ensuring clear accountability and execution of vulnerability management activities.
Demonstrate deep expertise in digital workplace technologies including Windows/macOS endpoint management, mobile device management (Intune), virtual solutions, and core Microsoft 365 services like Exchange, SharePoint, OneDrive, and Teams.
Possess strong experience in vulnerability management, digital workplace security compliance, patch management, and endpoint/platform lifecycle governance.
Have hands-on experience with OEM security advisory tools and vulnerability management platforms such as Microsoft MSRC, Defender for Endpoint, Intune, SCCM, ServiceNow VR, Tenable, or Qualys.
Exhibit solid knowledge of security frameworks, risk management methodologies, and principles of endpoint and platform hardening.
Proven track record in managing software upgrades, OS and application lifecycle programs, and executing security remediation initiatives.
Showcase strong analytical skills for assessing business risk, prioritizing remediation, and driving measurable outcomes.
Experience in developing compliance dashboards, executive reporting, and operational metrics is essential.
Excellent stakeholder management skills with the ability to influence and coordinate across diverse technology, security, vendor, and business teams.
Familiarity with infrastructure lifecycle management, End-of-Life/End-of-Support (EOL/EOS) governance, and technology refresh planning.
Experience leveraging automation and AI-driven capabilities to enhance compliance monitoring and remediation processes.
Strong communication and presentation skills, capable of articulating technical risks to both technical and non-technical audiences.
Ability to lead complex global initiatives involving multiple stakeholders, regions, and vendor organizations.
Demonstrate leadership capabilities with a proactive, outcome-driven, and risk-focused approach.
Requires a Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related technical discipline.
Minimum of 12 years of experience in digital workplace, endpoint, or Microsoft 365 platform technology support.
EY Global Delivery Services ( EY GDS)
IT Consulting