Stay in Compliance Lead-GCS

EY

12+ yrs Kochi Full Time Hybrid (office + remote)
EY logo
Posted : yesterday
Actively hiring

Job description

EY seeks a Stay in Compliance Lead for its Global Connectivity Solutions (GCS) team. This role is pivotal in defining and executing the global network infrastructure compliance strategy. The focus is on ensuring network devices are secure, current, and aligned with supported hardware and software standards. The Lead will oversee software upgrades, security patching, hardware refresh governance, and configuration remediation across various network platforms.

This position plays a crucial part in proactively identifying and mitigating security risks by utilizing OEM tools and vulnerability intelligence. Collaboration with key internal teams like I&O Stay in Compliance, BRMs, OSTS, Network Engineering, Operations, Product Owners, and external vendor partners is essential. The goal is to drive enterprise-wide compliance, ensure timely remediation, and enhance the overall network security posture.

The Stay in Compliance Lead will act as the central authority for network lifecycle governance, vulnerability management, compliance reporting, and risk reduction across the global connectivity estate. This is an opportunity to build a unique career at EY, leveraging global scale and an inclusive culture to achieve your potential.

Responsibilities

Lead the GCS vulnerability management program, encompassing identification, assessment, prioritization, remediation, and reporting. Develop and maintain a comprehensive vulnerability remediation and risk management roadmap. Establish and execute Global Vulnerability Management compliance plans for WAN, LAN, WiFi, SD-WAN, Telephony, NAC, and Internet Edge. Drive end-to-end remediation governance for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions. Maintain accountability for compliance against remediation SLAs and security standards. Partner with Information Security, Product Owners, Network Engineering, Network Operations, and other stakeholders for effective security remediation. Define, implement, and enhance policies, standards, processes, and procedures for vulnerability management and security remediation. Establish and maintain a robust controls framework for governance, auditability, and risk management. Lead GCS participation in Critical Vulnerability Response Plan (CVRP) exercises. Continuously monitor OEM advisories, vulnerability intelligence feeds, and security bulletins. Partner with vendors and OEMs to assess emerging security threats and lifecycle risks. Drive execution of critical security patching and infrastructure upgrades. Serve as the primary GCS representative in the Intelligent Operations Center (IOC) for security vulnerability management. Review and validate risk exception requests, ensuring proper documentation. Provide technical guidance and risk advisory support to leadership and stakeholders. Develop, maintain, and publish executive dashboards and reports on vulnerability exposure, remediation progress, and security compliance. Define and monitor key performance indicators (KPIs) and risk indicators (KRIs). Drive automation and continuous process improvement initiatives. Ensure security remediation activities adhere to governance, change management, and ITSM requirements. Own stakeholder communications related to security vulnerabilities and remediation plans. Lead incident-related vulnerability remediation activities and coordinate across technical teams.

Qualifications

Deep understanding of enterprise networking technologies including routing, switching, wireless, SD-WAN, telephony, NAC, DNS, DHCP, and network security platforms. Strong expertise in vulnerability management, network security compliance, patch management, and infrastructure lifecycle governance. Experience with OEM security advisory tools and vulnerability management platforms (e.g., Cisco PSIRT, ServiceNow Vulnerability Response, Tenable, Qualys). Solid knowledge of security frameworks, risk management methodologies, and infrastructure hardening principles. Proven experience managing software upgrades, firmware lifecycle programs, and security remediation initiatives. Strong analytical skills for business risk assessment and prioritization of remediation activities. Experience developing compliance dashboards, executive reporting, and operational metrics. Excellent stakeholder management skills to influence and coordinate across diverse teams. Knowledge of infrastructure lifecycle management, EOL/EOS governance, and technology refresh planning. Experience leveraging automation and AI-driven capabilities to enhance compliance monitoring. Strong communication and presentation skills, with the ability to explain technical risks to both technical and non-technical audiences. Capability to lead complex global initiatives involving multiple stakeholders and vendors. Demonstrated leadership with a proactive, outcome-driven, and risk-focused approach. Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related technical discipline. Minimum of 12 years of experience in Network technology support. CCNP certification is preferred; Versa or CCIE certification is a plus.

Essential Skills

Network SecurityVulnerability ManagementPatch ManagementInfrastructure Lifecycle ManagementRisk ManagementStakeholder ManagementNetwork EngineeringSD-WANWireless NetworkingTelephonyDNSDHCPRoutingSwitchingNACITSMChange ManagementCompliance ReportingAutomation

Good to Have

CCNPVersa CertificationCCIE

Highlights

  • Actively hiring

More Details

RoleStay in Compliance Lead-GCS
IndustryInformation Technology & Services, Management Consulting, Financial Services
DepartmentCybersecurity
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

Information Technology & Services

Stay in Compliance Lead-GCS at EY | SkillMX | SkillMX