Expoint – all jobs in one place
מציאת משרת הייטק בחברות הטובות ביותר מעולם לא הייתה קלה יותר

דרושים Government Public Sector - Technology Consulting ב-Ey ב-United States, Arlington

מצאו את ההתאמה המושלמת עבורכם עם אקספוינט! חפשו הזדמנויות עבודה בתור Government Public Sector - Technology Consulting ב-United States, Arlington והצטרפו לרשת החברות המובילות בתעשיית ההייטק, כמו Ey. הירשמו עכשיו ומצאו את עבודת החלומות שלך עם אקספוינט!
חברה (1)
אופי המשרה
קטגוריות תפקיד
שם תפקיד (1)
United States
אזור
Arlington
נמצאו 78 משרות
Yesterday
EY

EY Chief Information Security Officer CISO - US Government & Pu... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
תיאור:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
Yesterday
EY

EY Government Public Sector - FAAS Senior Manager United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year. Direct field work, inform...
תיאור:

Our Government & Public Sector-Financial Accounting Advisory Services (GPS-FAAS) team is growing exponentially, and as a Senior Manager you'll play a key role in that growth. Working across all Federal GPS sector service lines, you'll develop your career by communicating creative, strategic goals both internally and externally. It's all about listening to and understanding our clients to give them a truly exceptional experience in a field where there really are no off-the-shelf recommendations.

Your key responsibilities

The nature of this role means no two projects will be the same. That means you'll need to think on your feet and challenge existing practices to develop answers to complex issues. You'll also be collaborating with colleagues across multiple service lines, so we'll look to you to build relationships and identify opportunities for our clients to benefit from our knowledge in other areas. Regular travel will be required as you will be meeting with key clients, some of those being the most respected in their fields.

Skills and attributes for success

  • Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Demonstrate a thorough understanding of complex accounting and auditing concepts and apply them to client situations
  • Develop people through effectively delegating audit tasks and providing guidance to assurance staff
  • Provide performance feedback, training and performance reviews for assurance staff
  • Contribute ideas/opinions to the assurance teams and listen/respond to other assurance team members' views
  • Foster an efficient, innovative and team-oriented work environment
  • Use technology to continually learn, share knowledge with assurance team members and enhance service delivery
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Foster an efficient, innovative and team-oriented work environment
  • Use technology to continually learn, share knowledge with assurance team members and enhance service delivery
  • Develop an understanding of EY's service lines and actively seek/encourage assurance team members to contribute ideas and identify opportunities to apply the firm's services

To qualify for the role you must have

  • A bachelor's degree in accounting, finance or business discipline, supported by 7 years of progressive post baccalaureate work experience with Federal US GAAP
  • U.S. CPA license in your work state
  • Excellent project management skills
  • Excellent communication and negotiation skills and a collaborative approach to management
  • A proven record of excellence when managing, mentoring and improving a team of high-performing colleagues
  • Dedication to teamwork and leadership
  • Integrity within a professional environment
  • The ability to obtain and maintain a security clearance
  • Due to the nature of our work in the Government and Public Sector, work may be required to be completed at client, EY and/or contractor sites. Our goal is to assign professionals to projects within a commutable distance of their work location office. In certain circumstances, travel may be required beyond your work location based on client and project needs. Candidates should be willing to travel on average 25% to 30% or more in a hybrid environment.

Ideally you’ll also have

  • CGFM and/or CDFM

What we look for

We're interested in versatile people with the ability to take on new responsibilities and listen to clients to get things done. We're not just looking for accounting and audit experience — we're after genuinely interesting people with the ability to build relationships, negotiate and think in unique and creative news ways. If you're a confident leader with a curious mind and the ability to solve complex issues, this role is for you.

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $145,200 to $331,800. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $174,300 to $337,000. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

משרות נוספות שיכולות לעניין אותך

Yesterday
EY

EY Government Public Sector - Technology Consulting United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Collaborating with clients to gather and analyze requirements, ensuring that the final product meets their needs. Designing and developing user interfaces that are not only functional but also enhance user...
תיאור:

Digital Engineering – Microsoft Senior Developer

Our practice combines an understanding of the public sector's diverse mission needs with private sector leading practices. We respond to each client's issues by bringing together highly skilled professionals across our Consulting, Assurance, Tax and Strategy and Transactions service lines. This integrated approach provides the support and flexibility to meet the unique requirements of our clients.

You will join a talented group of professionals who are advising U.S. government agencies with digital strategy, customer experience, process improvement, technology effectiveness, digital architecture and program integration.

Your key responsibilities

As a Senior Developer, you will be responsible for the following:

  • Collaborating with clients to gather and analyze requirements, ensuring that the final product meets their needs
  • Designing and developing user interfaces that are not only functional but also enhance user experience
  • Writing clean, maintainable code and creating specifications that support business objectives
  • Actively participate in the design of software components. Use experience to help translate requirements into technical design and tasks.
  • Interacting and communicating effectively with teammates, clients, stakeholders, and executives
  • Assist with providing estimates on assigned tasks
  • Independently write quality code that is simple, reliable, and scalable
  • Analyze and fix moderate to complex problems during development and support. Document and communicate results appropriately
  • Participate in white-boarding sessions and impact analysis and explore methods and tools to improve the overall development process
  • Learn new client information quickly, and translate data modeling, process modeling, and revision control systems
  • Strong understanding of agile delivery and development methodologies
  • Proficiency in application development tools and quality assurance practices

In addition to your client’s responsibilities, you will also be expected to fulfil senior-level responsibilities within the firm. EY seniors support people-related initiatives, including recruiting events and interview nights. Seniors are also expected to support and participate in internal, firm activities, including training programs and courses to stay current on training requirements and continuously improve technical skills. Lastly, you will be expected to understand and follow all workplace policies and procedures, including all applicable Independence policies.

Skills and attributes for success

  • Experience gathering and analyzing requirements
  • Experience in Microsoft Power Platform, Power Apps, and/or Dynamics
  • Designing and developing user interfaces
  • Experience participating in the design of software components
  • Experience interacting and communicating effectively with teammates, clients, stakeholders, and executives
  • Be able to independently write quality code
  • Be able to learn new client information quickly, and translate data modeling, process modeling, and revision control systems
  • Possess strong understanding of agile delivery and development methodologies
  • Proficient in application development tools and quality assurance practices

To qualify for the role, you must have

  • Bachelor's degree
  • Candidate must be able to obtain/maintain a DoD Secret clearance
  • 5+ years of relevant experience
  • Extensive knowledge of C#, SQL, JavaScript, HTML
  • JavaScript UI frameworks such as React or Angular
  • Experience integrating with external systems
  • Must be comfortable working in-person as needed

Ideally, you'll also have

  • Expertise in developing written and visual communication products
  • Excellent written and oral communication skills
  • Ability to collaborate with clients and identify engagement follow-on opportunities

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $102,500 to $187,900. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $122,900 to $213,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

משרות נוספות שיכולות לעניין אותך

08.12.2025
EY

EY Financial Services - Technology Consulting UX/UI Designer St... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Bachelor’s degree in Graphic Design, UX Design, Industrial or Product Design and 2 years of progressive, post-baccalaureate work experience. Alternatively, will accept a Master’s degree and 1 years of work...
תיאור:

Your key responsibilities

As a UX/UI Designer, you will act as the design discipline lead on multidisciplinary teams of researchers, technologists and engagement team members. You will create as well as translate schematic wireframes to high fidelity mockups and work with developers and animators to create stunning prototypes.

To qualify for the role you must have

  • Bachelor’s degree in Graphic Design, UX Design, Industrial or Product Design and 2 years of progressive, post-baccalaureate work experience. Alternatively, will accept a Master’s degree and 1 years of work experience.
  • Proficient in Photoshop, Illustrator, Creative Cloud apps, Sketch, Keynote, InVision, Figma and other prototyping software
  • Ability to multitask and work in a fast-paced, collaborative team environment
  • Outstanding written and verbal communication skills

Ideally, you’ll also have

  • Passion and interests in working in the Financial Services industry or
  • Writing, publishing and conference-level presentation skills preferred

What we look for

We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package includes medical and dental coverage, both pension and 401(k) plans, a minimum of 15 days of vacation plus ten observed holidays and three paid personal days, and a range of programs and benefits designed to support your physical, financial and social well-being. Plus, we offer:

  • Excellent training and development opportunities through established programs and on-the-job training
  • Feedback on your performance that will accelerate your growth

What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,600 to $126,300. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,900 to $143,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

משרות נוספות שיכולות לעניין אותך

08.12.2025
EY

EY Government Public Sector - Technology Consulting United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Function as part of a team during technical implementations for Dynamics/Power Platform to finalize architecture specification, create designs as they relate to customizations and/or integration of platform. Lead system design...
תיאור:

Government and Public Sector – Technology Consulting - Digital Engineering – Microsoft Technical Architect - Senior Manager

Our practice combines an understanding of the public sector's diverse mission needs with private sector leading practices. We respond to each client's issues by bringing together highly skilled professionals across our Consulting, Assurance, Tax and Strategy and Transactions service lines. This integrated approach provides the support and flexibility to meet the unique requirements of our clients.

You will join a talented group of professionals who are advising U.S. government agencies with digital strategy, customer experience, process improvement, technology effectiveness, digital architecture and program integration.

Your key responsibilities

As a Technical Architect, you will be responsible for the following:

  • Function as part of a team during technical implementations for Dynamics/Power Platform to finalize architecture specification, create designs as they relate to customizations and/or integration of platform
  • Lead system design discussions and recommend alternate choices, trade-offs, and impact analysis
  • Participate in and lead white-boarding sessions
  • Assist with providing estimates on assigned tasks
  • Learn new client information quickly, and translate data modeling, process modeling, and revision control systems
  • Lead a team of developers through technical architecture
  • Provide mentoring and leadership to less experienced developers
  • Independently write quality code that is simple, reliable, and scalable
  • Perform code reviews and ensure best practices are being adhered to by development team on engagements
  • Lead solution deployments to downstream environments

In addition to your client’s responsibilities, you will also be expected to fulfil Senior Manager-level responsibilities within the firm such as:

  • Establish, maintain and strengthen internal and external relationships
  • Create innovative insights for clients, adapt methods and practices to fit operational team and cultural needs, and contribute to thought leadership
  • Anticipate and identify risks, and escalate any issues as appropriate
  • Develop people through effectively supervising, coaching and mentoring staff; help create a positive learning culture
  • Conduct performance reviews and contribute to performance feedback for staff
  • Participate in business development initiatives

Skills and attributes for success

  • Strong written and verbal communication, presentation, client service and technical writing skills, coupled with a strong interest in further developing and integrating operations with technology skills
  • Ability and comfort level researching client inquiries and emerging issues, including regulations, industry practices, and new technologies
  • Ability to create innovative insights for clients, adapt methods and practices to fit operational team and cultural needs, and contribute to thought leadership
  • Prior consulting experience

To qualify for the role, you must have

  • Bachelor's degree
  • Candidate must be able to obtain/maintain a DoD Secret clearance
  • 10-12+ years of related work experience
  • Must be comfortable working in-person as needed

Ideally, you'll also have

  • Microsoft Certifications and prior consulting experience highly preferred
  • Expertise in developing written and visual communication products
  • Excellent written and oral communication skills
  • Ability to collaborate with clients and identify engagement follow-on opportunities

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $171,600 to $392,100. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $205,900 to $445,700. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

משרות נוספות שיכולות לעניין אותך

08.12.2025
EY

EY Government Public Sector - Assurance United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Demonstrate working knowledge and aptitude in our key capabilities for example, IT general and application controls, risk management, information security, and information assurance. Take a practical approach to solving issues...
תיאור:

Your key responsibilities

As a member of our Technology Risk (IT Audit) team, you will serve as a key resource in delivering quality client services on financial statement audits, attestation engagements and IT control projects. You will conduct research as needed, assist in the testing of IT general and application controls, prepare for and potentially lead client meetings, establish relationships with client personnel at the appropriate levels, and deepen sector and client knowledge.

Some key capabilities you should be prepared to bring to client-facing and internal teams include:

  • Demonstrate working knowledge and aptitude in our key capabilities for example, IT general and application controls, risk management, information security, and information assurance
  • Take a practical approach to solving issues and gaining client agreement
  • Collaborate among team members; promote an inclusive working environment

To qualify for the role, you must have the following

  • Bachelor's degree in Business, Accounting, Finance, Information Systems, Information Technology or closely related field
  • Must have an active Top Secret SCI clearance
  • 3+ years of relevant experience in information assurance, information security, risk management, IT and application controls, leading standards (e.g., COSO, ERM, FISCAM, FISMA, NIST), IT technologies (e.g., Windows, UNIX, Oracle, Mainframe, SAP), preparing written or verbal materials, and assisting with presenting project results to clients
  • Participated in relevant audit/control testing engagement (e.g., CFO Act/FISCAM, OMB Circular A-123 internal control over financial reporting/Systems (ICOFR/ICOFS) assessments, audit readiness (DOD FIAR), ATC-320 SOC-1 Examinations (SSAE-18), and FISMA security reviews/implementations
  • Possess an understanding of IT technical security controls (e.g. NIST 800 series requirements, DOD Security Technical Implementation Guides (STIGS)), FIPS guidance, and Federal IT audit/examination methodologies (e.g. GAO FISCAM, Financial Audit Manual (FAM), and NIST RMF Assessment and Authorization)
  • Experience in completing Control testing over financial system controls compliance, IT general and application controls, and information assurance controls in areas of information assurance, access control, change control, segregation of duties and disaster recovery
  • The Government and Public Sector Practice’s staffing model is to assign resources to projects aligned to the office within the metropolitan area you have been hired; however, in certain circumstances, travel may be required within and/or beyond your geographic region based on client and project needs. For roles within the federal practice, the flexibility to travel up to approximately 30% is preferred. Within the state, local and education practice, the flexibility to travel up to approximately 80% is preferred
  • Candidate MUST be comfortable working in-person/onsite as needed

Ideally, you’ll also have

  • Experience working on large, complex engagements within the Government and Public Sector.
  • Worked in a Big Four, global management consulting firm or blue-chip company, preferably with a government and public sector focus
  • Strong analytical and problem-solving skills
  • Ability to collaborate with clients and identify engagement follow-on opportunities
  • Excellent verbal and written communication skills
  • Preferred Certification
    • Certified Information Systems Auditor (CISA)
    • Certified Information Systems Security Professional (CISSP)

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $87,800 to $160,900. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $105,400 to $182,800. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

משרות נוספות שיכולות לעניין אותך

08.12.2025
EY

EY Government Public Sector - Assurance Manager United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year. Direct field work, inform...
תיאור:

Our Government & Public Sector Assurance practice is growing exponentially, and as a manager, you'll play a key role in that growth. Together with our substantial investments in technology, knowledge, and learning resources on behalf of our audit professionals, this commitment will enable us to deliver quality assurance services to our clients and their stakeholders. While interacting with our clients, you'll develop your career by communicating and providing expertise around data integrity that can provide improved insight within the accounting, finance, governance, and regulatory space.

Your key responsibilities

The nature of this role means that you will be recognized as a primary day-to-day contact for our clients. That means you'll develop your knowledge by learning about current issues, profession, and business developments relevant to the client's industry, so we'll look to you to build relationships and manage teams.

Skills and attributes for success

  • Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Demonstrate a thorough understanding of complex accounting and auditing concepts and apply them to client situations
  • Develop people through effectively delegating audit tasks and providing guidance to assurance staff
  • Provide performance feedback, training and performance reviews for assurance staff
  • Contribute ideas/opinions to the assurance teams and listen/respond to other assurance team members' views
  • Foster an efficient, innovative and team-oriented work environment
  • Use technology to continually learn, share knowledge with assurance team members and enhance service delivery
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Develop an understanding of EY's service lines and actively seek/encourage assurance team members to contribute ideas and identify opportunities to apply the firm's services

To qualify for the role you must have

  • A bachelor's degree an approximately 5 years of related work experience; or a graduate degree and approximately 4 years of related work experience, with approximately 2 years of audit experience with a public accounting firm
  • A degree in Accounting, Finance, or related field
  • U.S. CPA license
  • Must be able to obtain and maintain a secret clearance or higher.
  • Excellent project management skills; advanced written and verbal communication skills
  • Dedication to teamwork and leadership
  • Integrity within a processional environment
  • The EY Government and Public Sector Practice's staffing model is to assign resources to projects aligned to the office within the metropolitan area you have been hired; however, in certain circumstances, travel may be required within and/or beyond your geographic region based on client and project needs. For roles within the federal practice, the flexibility to travel up to approximately 30% is preferred. Within the state, local and education practice, the flexibility to travel up to approximately 80% is preferred.

Ideally you'll also have

  • CGFM and/or CDFM

What we look for

We're interested in versatile people with the ability to take on new responsibilities and listen to clients to get things done. We're not just looking for accounting and audit experience — we're after genuinely interesting people with the ability to build relationships, negotiate and think in unique and creative news ways. If you're a confident leader with a curious mind and the ability to solve complex issues, this role is for you.

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $97,200 to $178,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $116,700 to $202,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

משרות נוספות שיכולות לעניין אותך

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
תיאור:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
בואו למצוא את עבודת החלומות שלכם בהייטק עם אקספוינט. באמצעות הפלטפורמה שלנו תוכל לחפש בקלות הזדמנויות Government Public Sector - Technology Consulting בחברת Ey ב-United States, Arlington. בין אם אתם מחפשים אתגר חדש ובין אם אתם רוצים לעבוד עם ארגון ספציפי בתפקיד מסוים, Expoint מקלה על מציאת התאמת העבודה המושלמת עבורכם. התחברו לחברות מובילות באזור שלכם עוד היום וקדמו את קריירת ההייטק שלכם! הירשמו היום ועשו את הצעד הבא במסע הקריירה שלכם בעזרת אקספוינט.