Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 1000 people who collaborate to support the business of EY by protecting EY and client information assets!
Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
The opportunity
As a Supervising Associate in the Information Security Portfolio Compliance Enablement function, you will play a key role in supporting EYs digital services by ensuring adherence to Information Security policies. This position involves working directly on projects to enhance risk posture, collaborating with business teams, and contributing to the maintenance of the technology compliance posture through effective governance.
Your key responsibilities
- Actively contribute to projects aimed at improving EYs risk posture.
- Manage delivery of one or more processes and/or solutions with a focus on quality and effective risk management.
- Assist in the development of compliance strategies and remediation plans.
- Help translate technical vulnerabilities into business risk terms for stakeholders.
- Contribute to the maintenance and enhancement of compliance assessment toolkits.
- Participate in security assessments for technology infrastructure and application risks and vulnerabilities, and third-party dependencies.
- Contribute to continuous improvement, the identification of innovative solutions through research, analysis, and the application of best practices.
- Support a team of compliance specialists, providing guidance and expertise on specific projects and initiatives.
Skills and attributes for success
- Solid experience in compliance management within Information Security.
- Ability to understand and balance security needs with business impact.
- Strong organizational skills and a proactive approach to problem-solving.
- Effective communication skills, technical writing, capable of building relationships and facilitating compliance with security policies and documenting processes.
- Experience in conducting risk assessments and recommending remediation strategies.
- Knowledgeable in technical infrastructure, applications, and compliance frameworks.
- Capable of evaluating security policies and systems to ensure compliance with standards.
To qualify for the role, you must have
- A minimum of 5 years of experience in Cyber Security, Information Security, or a related field.
- A degree in Cyber Security, Information Security, Computer Science, or a related discipline.
- Relevant certifications such as CRISC, CISSP, CISM, CISA, or equivalent.
- Familiarity with common information security standards like ISO 27001/27002, NIST, PCI DSS.
- Understanding of regulatory requirements such as PCI, SOX, HIPAA, GDPR.
- Strong communication skills and the ability to collaborate effectively with teams.
Ideally, you’ll also have
- Excellent problem-solving and decision-making abilities.
- Adaptability to changing priorities and project scopes.
- Strong interpersonal and communication skills and ability to present information with purpose and clarity.
- Experience with GRC platforms like RSA Archer or IBM Open Pages is a plus.
What we offer
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
EY is committed to providing equal opportunities to all applicants regardless of their background, culture, and personal circumstances.