TC-CS-SRCR- Cyber Risk and Compliance- Senior
EY
EY
Join EY's Strategy, Risk, Compliance and Resilience (SRCR) Technology Consulting team and embark on a career defining journey. You'll engage in global SRCR projects, cultivating essential internal and external relationships while identifying potential business opportunities for EY. Proactively manage engagement risks and ensure the highest quality of work, adhering to EY's rigorous standards.
As a pivotal team member, you will contribute to a positive learning environment by coaching and mentoring junior colleagues, fostering their professional development. This role offers a unique chance to be part of a leading firm and significantly contribute to the growth of a dynamic new service offering.
Engage in diverse cyber security initiatives, including strategy, governance, risk, compliance, resilience, transformation, co-sourcing, and application/network security. Collaborate effectively within a team, sharing responsibilities, providing support, and maintaining clear communication with senior management regarding project progress.
Execute engagement deliverables, meticulously reviewing the work of junior team members. Develop compelling client-facing reports and schedules. Cultivate and maintain strong, productive relationships with client personnel and across EY's global consulting network.
Actively participate in talent initiatives, contributing to the recruitment and retention of Cyber Transformation professionals. Drive continuous learning through educational programs and maintain adherence to workplace policies. Support performance reviews and provide constructive feedback to junior staff. Manage the performance of direct reports according to organizational policies, fostering teamwork and leading by example through training and mentorship.
We seek a Senior Security Consultant with a minimum of 5 years of hands-on experience in core cybersecurity domains. This includes expertise in Vendor/3rd Party Risk Management, Cyber Strategy & Governance, Cyber Transformation, and Cyber Dashboarding.
Familiarity with key regulations and standards like ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, and NIST 800-53 is essential. Experience in Business Continuity & Disaster Recovery is also required.
Candidates must possess client-facing experience, including interacting with third parties and assessing various IT and non-IT environments. The ability to apply cyber security concepts across diverse sectors is crucial. Demonstrated experience in creating and reviewing security policies/procedures, alongside performing risk assessments, is a must.
A solid understanding of VAPT processes, common application security vulnerabilities, exploitation techniques, and remediation measures is necessary. Basic knowledge of Network Security, network architecture diagrams, access controls, perimeter controls, vulnerability management, and intrusion detection is expected.
Proficiency in leading medium to large engagements and mentoring junior staff is vital. Strong Excel and PowerPoint skills are mandatory. An educational background including BE/B.Tech, BCA, MCA, M.Tech, or MBA with a computer science and programming focus is required.
EY Global Delivery Services ( EY GDS)
Technology Consulting