Expoint - all jobs in one place

המקום בו המומחים והחברות הטובות ביותר נפגשים

Limitless High-tech career opportunities - Expoint

EY Portfolio Compliance Enablement Leader 
United States, Florida, Jacksonville 
717515125

26.01.2025

The role involves comprehensive management of the Portfolio and service line of risk with the primary accountability of reducing that risk by engaging directly with key EY Leaders and ensures the company’s technical systems and information assets are protected in accordance with compliance requirements by doing pro-active compliance management and compliance hunting. Furthermore, the role focuses end-to-end security compliance enablement and is responsible for identifying, evaluating and reporting on information security risks when technological systems and software are not meeting compliance requirements.

Key responsibilities


This position is a leading role in managing the compliance portfolio for all global, regional, and country-based assets and systems. As a compliance consultant dedicated to the EY Service Line and function, you will be both an individual contributor capable of supporting multiple projects and lead a team of compliance specialists focused on improving the risk posture of the Service Line or function. In other words, it is not just an oversight role, but one that requires detailed understanding of the Service Line, business drivers, key risks and issues, and can help strategize on risk reduction strategies based on analysis of compliance data and trends.

You will lead a team focusing on these pillars:

  • Risk Management and Reduction: Take ownership of the Portfolio or Service Line of security risk and compliance, engaging directly with key EY leaders to reduce risks by providing insights on top risks impacting the security posture of the businesses. Engage in compliance and risk-based investment planning to mitigate these risks effectively.
  • Trend Identification and Remediation: Identify security risk trends and themes that require a comprehensive approach to remediation. Lead and spearhead these efforts, ensuring that risks are mitigated in a timely and efficient manner.
  • Proactive Security Initiatives: Proactively seeking out and identifying security risks, weaknesses, and potential vulnerabilities in systems and processes before they can be exploited and independently stand-up initiatives to address them. Improve compliance with security standards and policies though continuous improvement and innovation in security practices.
  • Governance, Risk, and Compliance (GRC) Management: Manage the end-to-end workflow of security compliance of risk findings in our Governance, Risk, and Compliance (GRC) tool to ensure continuity and compliance with security policies, standards and regulations.

And focus on the following responsibilities:

  • Define compliance strategies and remediation recommendations that provide pragmatic security guidance that balance business benefit and risks.
  • Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or audits.
  • Translate technical vulnerabilities into business risk terminology for the business.
  • Maintain compliance framework assessment toolkits used in testing and validation procedures.
  • Be accountable for and lead assessments for technology infrastructure, applications and third-party dependencies, aligning to regulations, best practices and corporate governance.

Skills and attributes for success


Significant working security experience and knowledge in the management of compliance with company security policies in the following areas:

  • Strong leadership and organizational skills
  • Strategic skills to assist with the development of a long-term vision for EY’s risk management security framework & approach
  • Ability to appropriately balance firm security needs with business impact & benefit
  • Ability to facilitate compromise to incrementally advance security strategy and objectives
  • An overall understanding of the business objectives of EY with an ability to build relationships across EY
  • Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
  • Experience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromise
  • Execute top-down assessment of risk based on policy compliance data and risks
  • Experience conducting risk assessments, vulnerability assessments, vendor and third-party risk assessments and recommending risk remediation strategies
  • Looks for ways to continually improve our compliance with Information Security policies
  • Create, promote, and oversee enforcement protocols, enabling consistency across diverse internal stakeholders
  • Investigate any violations of policies and recommend corrective action.
  • Develop training materials and conduct training sessions to educate on policies and enforcement protocols
  • Develop metrics to evaluate the effectiveness of policy enforcement, and generate regular reports
  • Identify policy and enforcement gaps and propose improvements.
  • Projects advanced consultative skills to conduct effective questioning to break down complex issues into core elements, formulate appropriate ideas or planning and negotiate those ideas and plans clearly and concisely to advance a cooperative engagement by all levels of the organization including senior and/or executive management
  • Proficient understanding of business focus and processes and the ability to inject cybersecurity compliance into the business through teamwork and influence
  • Ability to maintain a high level of integrity, trustworthiness and confidence to represent the company and security leadership with the highest level of professionalism
  • Ability to remain credible with the team and external constituents through sustained industry knowledge
  • Proven project leadership with both legacy and emerging technologies to assess and manage business risk and enforce security controls
  • Wide-ranging knowledge in technical infrastructure and applications, from legacy through next generation

To qualify for the role, you must have

  • A minimum of 10 years' experience in the field of Cyber Security, Information Security, or related discipline
  • At least 5 years’ experience in a leadership role managing a distributed team and workforce
  • Advanced degree in Cyber Security, Information Security, Computer Science or a related discipline; or equivalent work experience
  • One or more of the following or equivalent certifications: Certified Risk and Information Systems Control (CRISC), Certified Information Systems Security Processional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), Certified Internal Auditor (CIA), Global Information Assurance Certification (GIAC) in related area, CIPP, CIPT
  • Experience working with common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, COBIT
  • Demonstrated leadership experience and thorough understanding of various regulatory requirements and laws such as, but not limited to, PCI, SOX, HIPAA, HITRUST, GDPR and GLBA.
  • Experience in policy enforcement and security compliance, awareness and learning at a publicly traded company
  • Strong understanding of governance, risk, and compliance (GRC) frameworks and tools
  • Proven competence in communicating confidently and effectively with clients, vendors, and all levels of management
  • Experience in managing the communication of security findings and recommendations to IT project teams and management
  • Skilled in executive level presentations and briefings
  • Proven ability to identify and mitigate security risks proactively
  • Insight into the business advantages of good risk management and internal controls beyond compliance purposes
  • Demonstrated leadership, negotiation and collaboration skills, and ability to influence up and down
  • Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment
  • Demonstrated experience in managing end-to-end security compliance enablement projects
  • Extensive experience with security compliance regulations
  • Strong English language skills: excellent writing, presentation, interpersonal, and communication skills are required
  • Capable of working with diverse teams and promoting an enterprise-wide, collaborative security culture
  • Ability to work flexibly and adapt to changing environments

Ideally, you’ll also have

  • Exceptional judgment, tact, and decision-making ability
  • Familiarity with local and regional regulatory requirements and how they impact IT policies
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change
  • Outstanding management, interpersonal, communication, organizational, and decision-making skills
  • Experience with RSA Archer and/or IBM Open Pages
  • An ability to utilize core risk and controls skills in a broad range of projects both in a traditional internal audit and in advisory projects aimed at assisting in the implementation of controls / improvements

What we offer
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges.
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $148,900 to $286,700. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $178,700 to $325,700. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.