Expoint – all jobs in one place
The point where experts and best companies meet

Gps - Cyber Security Engineer Supervising Associate jobs at Ey in United States, Arlington

Discover your perfect match with Expoint. Search for job opportunities as a Gps - Cyber Security Engineer Supervising Associate in United States, Arlington and join the network of leading companies in the high tech industry, like Ey. Sign up now and find your dream job with Expoint
Company (1)
Job type
Job categories
Job title (1)
United States
State
Arlington
23 jobs found
Yesterday
EY

EY Chief Information Security Officer CISO - US Government & Pu... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Clearance: The ability to obtain and maintain top secret required
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
Yesterday
EY

EY GPS - Cyber Security Engineer Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Minimum 1+ years of experience with Power Apps development and good experience in Canvas & model driven application development. Environment setup for Development, managing & publishing apps. Developing Microsoft Flows...
Description:

Position Details

Ever-increasing regulations require audit departments to gather, organize and analyses more data than ever before. Often the data necessary to satisfy these ever-increasing and complex regulations must be collected from a variety of systems and departments throughout an organization. Effectively and efficiently handling the variety and volume of data is often extremely challenging and time consuming for a company.GDS Assurance Digital provides solution architecture, application development, testing and maintenance support to the global Assurance service line both on a pro-active basis and in response to specific requests.

Requirements (including experience, skills and additional qualifications) A Bachelor's degree (BE/BTech/MCA & MBA) in Computer Science, Engineering, Information Systems Management, Accounting, Finance or a related field with adequate industry experience.

Technical skills requirements
• Minimum 1+ years of experience with Power Apps development and good experience in Canvas & model driven application development
• Environment setup for Development, managing & publishing apps
• Developing Microsoft Flows with REST-APIs, automated emails and SMS
• Localization (PowerApps app Language based on to region)
• Experience in sending Push notification to a specific user
• Some experience in SharePoint, SPFx/React
• Experience in Power BI Dashboard Development


Good to have skill

• Experience in Azure DevOps
• Experience in Agile / Scrum methodology
• Integrating MS Remote Assist or any similar video chatting tools/services
• SharePoint User Management/Permissions and List Settings

Analytical/Decision Making Responsibilities:

• An ability to quickly understand complex concepts and use technology to support data modeling, analysis, visualization or process automation
• Selects appropriately from applicable standards, methods, tools and applications and uses accordingly
• Ability to work within a multi-disciplinary team structure, but also independently
• Demonstrates analytical and systematic approach to problem solving
• Communicates fluently orally and in writing and can present complex technical information to both technical and non-technical audiences
• Able to plan, schedule and monitor work activities in order to meet time and quality targets
• Able to absorb rapidly new technical information, business acumen, and apply it effectively
• Ability to work in a team environment with strong customer focus, good listening, negotiation and problem-resolution skills


Additional skills requirements:• The expectations are that a Senior will be able to maintain long-term client relationships and network and cultivate business development opportunities
• Provide high quality client services by directing daily progress of engagement work, informing engagement manager of engagement status, and managing staff performance.
• Must have presentation skills ' ability to create PowerPoint deck to communicate solution architecture to various stakeholders.
• Should have understanding and experience of software development best practices
• Excellent business communication, Consulting, Quality process skills
• Must be a team player

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Show more
Yesterday
EY

EY Azure Cloud Platform Engineer - GPS United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Have experience in the infrastructure sector, particularly in transport, power and utilities, health, and education projects. Experience in the UK, Australia, or Canada in the PPP/PFI and project financing sector...
Description:

By joining this team, you will support our clients from the earliest stages of project analysis and evaluation through procurement, financial close, construction, and operations.

You will assist clients in devising and comparing financial plans and delivery approaches for projects involving public, federal, or private financing, project revenues, and/or grants, while providing support for the implementation of those plans.

As part of our project finance team, you will enhance your commercial capabilities by working with our global networks and fast-moving, emerging clients.

Our diverse client portfolio will help you build skills in pitching, briefing, managing relationships, and challenging assumptions.

In our friendly and collaborative environment, you will receive the support, formal training, and coaching needed to progress quickly along your chosen career path.

Your key responsibilities

In Infrastructure Advisory you will:

  • Have experience in the infrastructure sector, particularly in transport, power and utilities, health, and education projects. Experience in the UK, Australia, or Canada in the PPP/PFI and project financing sector is advantageous, as is experience in Asia.
  • Develop and manage key client relationships and deal origination capabilities, from securing advisory mandates to achieving transaction closure, acting on government and private sector transactions in the infrastructure sector.
  • Possess knowledge of PPP/PFI, concessions, and acquisition and project financing structures/contracts related to the infrastructure sector.
  • Work on project delivery covering feasibility, design, procurement, construction, and handover.
  • Have project financing knowledge, with an understanding of project financial modeling and financing markets, which would be highly valued.
  • Understand economic or social infrastructure procurement and delivery.

To qualify for the role you must have

  • More than 8 years of experience in a top-tier advisory firm, infrastructure service provider, bank, relevant government agency or other relevant sector.
  • A university degree, preferably majoring in Economics, Finance, Accounting, Management, Law, or Engineering from reputable local or overseas universities. A Master's degree is ideal.
  • Professional qualifications such as CFA, FRM, ASIA, CPA, CA, or CMA are considered advantageous.
  • A high-performance professional who can articulate a value proposition, developing business cases/ models and lead and advise on projects in the infrastructure sector from bid stage to financial close
  • Advanced financial modelling skills, project finance modelling experience s an advantage.
  • Willingness and ability to travel when necessary.

What’s most important is that you’re dedicated to supporting your colleagues as part of a high-performing team. You’ll need to thrive in picking up new skills and talents as you go, so natural curiosity, a lot of questions and the confidence to speak up when you see something that could be improved are essential.

If you’ve got the right combination of technical knowledge and communication skills, this role is for you.

Show more
18.11.2025
EY

EY GPS - Assistant Facility Security Officer Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance. Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies,...
Description:

As Assistant Facility Security Officer (AFSO) you will be responsible for ensuring the protection of National Security Information in accordance with the National Industrial Security Program Operating Manual (NISPOM)/32 CFR Part 117. Responsibilities include program oversight, evaluations, and educating cleared employees on promulgated government and company initiatives, policies and procedures. The candidate will serve as the primary security liaison with government agencies, sponsor representatives and integrate security solutions across business portfolios.

Your key responsibilities

  • Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance.
  • Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies, and established regulations.
  • Enforce procedures for accounting, controlling, transmitting, safeguarding, and destroying classified information.
  • Support a security education, training, and awareness program.
  • Support the FSO with preparing reports and presentations for all levels of Management.
  • Maintains data compliance in DISS, NISS, NBIS, SWFT and other system of records.
  • Maintain and update Standard Practices and Procedures (SPP) documentation.
  • Support and mature the NISP annual security self-inspection, coordinating with internal stakeholders and DCSA representatives.
  • Provide support for classified meetings, including coordination and visitor management (e.g., processing Visitor Approval Requests (VARs)).
  • Lead security incident investigations in accordance with EY policy, NISPOM/32 CFR Part 117, and DCSA guidelines, collaborating with internal and external stakeholders.
  • Analyze and validate security processes, procedures, and standards to ensure compliance, identify trends and root-causes and facilitate multi-disciplinary teams to address gaps.
  • Prepare, track, and maintain Prime and Subcontractor DD-254s forms to ensure accuracy of security requirements. Coordinate with applicable stakeholders to facilitate actions necessary to execute and update such documentation.
  • Demonstrate professionalism, independent engagement, and collaboration with peers and external personnel to ensure adherence to regulations and guidelines.
  • Exhibit strong decision-making, individual initiative, organizational skills, and the ability to function with minimal supervision.

Skills and attributes for success

  • The AFSO must be a strategic thinker who can exercise independent judgment and knowledge to manage risks, deliver Industrial security support and align security solutions with business needs.
  • Candidate will collaborate with Senior security staff, employees and government clients to meet objectives while ensuring EY security program remains effective, compliant with Defense Counterintelligence and Security Agency (DCSA) standards, and aligned with corporate security requirements
  • In addition to technical expertise and independent initiative, the ideal AFSO will demonstrate a collaborative spirit and the ability to work seamlessly within multidisciplinary teams. Strong interpersonal skills are essential, enabling the candidate to foster open communication, support colleagues in joint problem solving, and cultivate an environment of mutual respect and shared accountability. A commitment to partnership—both within the security staff and across business units—ensures robust information exchange, effective coordination, and unified progress toward security and organizational objectives.

To qualify for the role you must have

  • Bachelor’s degree (Criminal Justice preferred) or equivalent experience
  • Strong organizational and communications skills, and the ability to effectively interact with staff and customers at all levels.
  • Proficiency in Microsoft Office products is required, with particular emphasis on Microsoft Access for database management and Microsoft Copilot for workflow optimization and automation.
  • DCSA Center for Development of Security Excellence (CDSE) FSO Program Management for Possessing Facilities courses.
  • Ability to obtain and maintain a TS/SCI Fullscope polygraph clearance
  • This position has an on-site requirement of 5 days a week on-site in the Tysons, VA and Arlington, VA office locations

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $57,400 to $104,100. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $68,800 to $118,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
18.11.2025
EY

EY GPS - ServiceNow Developer Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Configure and manage ServiceNow instances, ensuring the platform is performing optimally. Administer user roles, permissions, and security settings in accordance with company policies. Perform routine system maintenance, including upgrades, patch...
Description:

Your key responsibilities

  • Configure and manage ServiceNow instances, ensuring the platform is performing optimally.
  • Administer user roles, permissions, and security settings in accordance with company policies.
  • Perform routine system maintenance, including upgrades, patch management, and performance monitoring.
  • Troubleshoot and resolve issues within the ServiceNow platform, ensuring minimal downtime and maximum performance.
  • Develop and manage ServiceNow workflows, notifications, and business rules to streamline IT and business processes.
  • Design, develop, and customize ServiceNow applications and modules (ITSM, ITOM, SPM, etc.) based on business requirements.
  • Create and manage custom scripts (e.g., Business Rules, Script Includes, UI Policies, etc.) using ServiceNow scripting languages such as JavaScript, Glide, and AngularJS.
  • Build custom forms, reports, and dashboards for business users.
  • Implement and manage integrations between ServiceNow and third-party systems (REST/SOAP integrations, import sets, etc.).
  • Provide technical expertise and training to users and other team members on ServiceNow functionality and best practices.
  • Provide Tier 2/3 support for complex incidents or requests related to ServiceNow.
  • Troubleshoot, debug, and resolve complex ServiceNow issues, ensuring fast resolution and minimal impact on business operations.
  • Document solutions and issues in a knowledge base for future reference.

Skills and attributes for success

  • Undergraduate degree in Computer Science, Information Systems, Business Administration or related field
  • Proficiency in ServiceNow development including scripting business rules, workflows, and UI Policies.
  • Experience with ServiceNow integrations (REST, SOAP, Import Sets).
  • Familiarity with ServiceNow Studio, Service Portal, and other development tools within the platform.
  • Knowledge of ServiceNow reporting, dashboards, and performance analytics.
  • Experience with workflow tools
  • Strong understanding of US Government’s expectations for IT control environment
  • Ability to plan, execute and deliver on projects in a timely manner
  • Ability to multi-task on varying projects and initiatives
  • Attention to detail; organized and thorough
  • Excellent analytical and critical thinking skills
  • Ability to work with a diverse and geographically distributed team

To qualify for the role, you must have

  • 3+ years of experience as a ServiceNow Developer and/or Administrator.
  • Strong hands-on experience with ServiceNow ITSM, ITOM, SPM etc. modules is required.
  • ServiceNow Certified System Administrator (CSA) is required.
  • ServiceNow Certified Application Developer (CAD) is preferred.
  • Ability to obtain and maintain a Top Secret Security Clearance

Ideally, you’ll also have

  • ServiceNow Certified Implementation Specialist (CIS) in relevant modules (ITSM, ITOM, SPM etc.) is a plus.

We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package includes medical and dental coverage, both pension and 401(k) plans, a flexible time off policy with plus 19 observed holidays, and a range of programs and benefits designed to support your physical, financial and social well-being.Plus, we offer:

  • Support and coaching from some of the most engaging colleagues in the industry
  • Opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that’s right for you

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $89,600 to $167,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $107,600 to $190,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
18.11.2025
EY

EY GPS - IAM Operations Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Define and maintain a clear product vision and roadmap aligned with client and business objectives, with a focus on delivering measurable business value and user adoption. Lead strategy data engagements,...
Description:

Key Responsibilities:

Strategic Ownership

  • Define and maintain a clear product vision and roadmap aligned with client and business objectives, with a focus on delivering measurable business value and user adoption.

  • Lead strategy data engagements, helping clients design target operating models, data governance frameworks, and data products (incl. Dashboards, Reports, Real-time data feeds, Data ingestion pipelines to analytics platforms).

Backlog & Delivery Management

  • Translate complex business needs into actionable data product backlogs.

  • Prioritize features and tasks based on value, ROI, and milestone goals.

  • Conduct User Story refinement sessions to ensure clarity and feasibility of requirements.

  • Monitor project progress and ensure deliverables meet expectations and timelines.

  • Facilitate Sprint Reviews and gather feedback for continuous improvement.

Stakeholder Collaboration

  • Act as the primary liaison between development, DevOps, QA teams and stakeholders.

  • Manage client expectations and communicate progress across engagements.

Cross-Functional Leadership

  • Collaborate with consultants, engineers, designers, and analysts to ensure successful delivery of the product roadmap.

  • Guide the team using Agile and Scrum methodologies.

  • Understand and leverage the technology stack to make informed decisions.

Qualifications:

  • 2+ years of experience in Agile delivery methodologies as a Product Owner, Product Manager, Scrum Master or Consultant within technology or consulting environments.

  • Good understanding of tools and concepts related to data: Data pipelines, ETL, Data visualization, Cloud Platforms (Azure, AWS, GCP) and data governance frameworks.

  • Understanding of concepts like data warehouses and data lakes.

  • Experience in implementing large-scale Insurance or Banking related data projects ideally with a focus on Cloud Data Platform Implementation and Cloud Data Platform Migration.

  • Proven success in delivering data products and strategic initiatives across multiple client-facing projects.

  • Strong stakeholder management and communication skills, with demonstrated excellence in both oral and written communication.

  • Deep understanding of Agile frameworks such as Scrum and hands-on experience with industry-standard tools like Jira and Confluence.

  • Ability to prioritize and manage product backlogs effectively, ensuring alignment with business goal.

Ideally, you will also have:

  • A willingness to travel to meet client needs as required

  • Appetite to take ownership of several complex initiatives

  • Good appreciation of current market trends (Cloud, Data Analytics, Emerging Technologies etc.) and how these are likely to impact key industry players

  • Dedication to working with your colleagues as part of a high-performing team

  • Natural curiosity and the confidence to provide alternative options or suggestions when you see something that could be improved

What we offer you

In addition to a competitive salary, our benefits include but are not limited to:

  • 13th salary

  • Provident Fund

  • Private Medical and Life Insurance

  • Flexible working arrangements (hybrid work and flexible work schedule)

  • Friday afternoon off

  • EY Tech MBA and EY MSc in Business Analytics

  • EY Badges - digital learning certificates

  • Mobility programs (if interested to work abroad)

  • Paid Sick Leave

  • Paid Paternity Leave

  • Yearly wellbeing days off

  • Maternity, Wedding and New Baby Gifts

  • EY Employee Assistance Program (EAP) (counselling, legal and financial consultation services)

Building a better working world

Show more
18.11.2025
EY

EY DHS Sales Executive Associate Director United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Assist in the preparation of accurate assurance documentation for review. Assist in nominated audit area(s) and/or delivery and completion of smaller clients. Gain an in depth understanding of the audit...
Description:

Job purpose:

As an Intern within Assurance, you will be a fundamental part of a multi-disciplinary team, working closely with our Associates and clients delivering efficient and effective assurance services.

You will:-

  • Assist in the preparation of accurate assurance documentation for review
  • Assist in nominated audit area(s) and/or delivery and completion of smaller clients
  • Gain an in depth understanding of the audit process from your peers
  • Complete work allocated to you by team members within agreed deadlines
  • Gain understanding of client/business issues, e.g. by using the firm’s knowledge resources
  • Gather and assist in analysis of data, and perform low level audit testing to support the team

You will:-

  • Develop an effective working relationship with your assigned teams
  • Seek opportunities to expand your knowledge
  • Keep the team up to date with your progress/issues
  • Be proactive about your own learning and development
  • Seek feedback on your personal performance and areas for improvement

How will an internship with EY help you to increase your employability?

  • Organisational and time management skills
  • Questioning and listening skills
  • Good writing skills
  • IT skills
  • Strong communication skills
  • Team working skills

Entry Requirements

  • A-Levels/Highers or equivalent
  • Studying towards a degree
  • Local to the Channel Islands or a close family connection to the Islands
  • Ability to take part in our online strengths based competency testing as part of our assessment process

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Show more
Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Clearance: The ability to obtain and maintain top secret required
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
Find your dream job in the high tech industry with Expoint. With our platform you can easily search for Gps - Cyber Security Engineer Supervising Associate opportunities at Ey in United States, Arlington. Whether you're seeking a new challenge or looking to work with a specific organization in a specific role, Expoint makes it easy to find your perfect job match. Connect with top companies in your desired area and advance your career in the high tech field. Sign up today and take the next step in your career journey with Expoint.