Job Description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Stay in Compliance Lead – GCS
Job Summary:
The Stay In Compliance Lead within Global Connectivity Solutions (GCS) is responsible for defining, governing, and driving the global network infrastructure compliance strategy to ensure network devices remain current, secure, and aligned with supported hardware and software standards. The role is responsible for maintaining the software and hardware currency of network infrastructure across WAN, LAN, WiFi, SD-WAN, telephony, and related connectivity platforms by leading regular software upgrades, security patching, hardware refresh governance, and configuration remediation activities.
The position proactively identifies and mitigates security risks by leveraging OEM tools, vulnerability intelligence platforms, and security advisories to assess the exposure of network infrastructure to emerging threats and vulnerabilities. Working closely with I&O Stay in Compliance (SIC), Business Relationship Managers (BRMs), OSTS, Network Engineering, Network Operations, Product Owners, and vendor partners, the role drives GCS enterprise-wide compliance initiatives, ensures timely execution of remediation activities, and strengthens the organization's overall network security posture. The Stay In Compliance Lead serves as the central authority for network lifecycle governance, vulnerability management, compliance reporting, and risk reduction across the global connectivity estate.
Job Description
- Own and lead the Global Connectivity Solutions (GCS) vulnerability management program, ensuring identification, assessment, prioritisation, remediation, and reporting of security vulnerabilities across the entire GCS product portfolio.
- Develop and maintain a comprehensive vulnerability remediation and risk management roadmap, leveraging data-driven insights, analytics, and risk-based prioritisation to reduce overall security exposure.
- Establish and execute Global Vulnerability Management compliance plans across WAN, LAN, WiFi, SD-WAN, Telephony, NAC, Internet Edge, and associated network infrastructure platforms.
- Drive end-to-end remediation governance for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions in accordance with business and security requirements.
- Maintain accountability for compliance against remediation SLAs and security standards established by Information Security, tracking progress, ageing, and compliance performance across the GCS estate.
- Partner with Information Security, Product Owners, Network Engineering, Network Operations, Service Management, OSTS, BRMs, and other stakeholders to ensure effective execution of security remediation activities.
- Define, implement, and continuously enhance policies, standards, processes, and procedures governing vulnerability management, software currency, hardware lifecycle compliance, and security remediation activities.
- Establish and maintain a robust controls framework that ensures effective governance, auditability, compliance monitoring, and risk management across GCS services.
- Collaborate closely with Information Security and Enterprise Technology stakeholders to lead GCS participation in Critical Vulnerability Response Plan (CVRP) exercises and enterprise-wide cyber response activities.
- Continuously monitor OEM advisories, vulnerability intelligence feeds, security bulletins, and threat intelligence platforms to identify risks impacting GCS infrastructure and services.
- Partner with vendors and OEMs to assess the impact of emerging security threats, recommended mitigations, software defects, and lifecycle-related risks.
- Drive execution of critical security patching, emergency remediation activities, and infrastructure upgrades to reduce organisational risk exposure.
- Act as the primary GCS representative within the Intelligent Operations Center (IOC) for security vulnerability management, remediation coordination, and risk response activities.
- Review, challenge, and validate risk exception requests, ensuring technical justification, compensating controls, and business impact assessments are appropriately documented before approval.
- Provide technical guidance and risk advisory support to leadership teams, product owners, and business stakeholders regarding vulnerability remediation strategies and compliance obligations.
- Develop, maintain, and publish executive dashboards, scorecards, and management reports covering vulnerability exposure, remediation progress, security compliance, software currency, hardware currency, and risk posture across GCS.
- Define and monitor key performance indicators (KPIs), risk indicators (KRIs), remediation targets, and compliance metrics to measure programme effectiveness.
- Drive automation and continuous process improvement initiatives across vulnerability assessment, remediation tracking, software upgrades, patch management, compliance reporting, and IOC operational activities.
- Partner with Service Management teams to ensure all security remediation activities adhere to established governance, change management, ITSM, and operational compliance requirements.
- Own stakeholder communications related to security vulnerabilities, remediation plans, compliance risks, maintenance activities, and risk mitigation strategies.
- Lead incident-related vulnerability remediation activities, ensuring effective coordination across technical teams and timely communication to stakeholders.
- Lead and manage the GCS Stay In Compliance team, ensuring clear accountability, ownership, and execution of vulnerability management and remediation activities.
Knowledge & Competencies Required:
- Deep understanding of enterprise networking technologies including routing, switching, wireless, SD-WAN, telephony, NAC, DNS, DHCP, and network security platforms.
- Strong expertise in vulnerability management, network security compliance, patch management, and infrastructure lifecycle governance.
- Experience working with OEM security advisory tools and vulnerability management platforms such as Cisco PSIRT, Meraki, Arista, Palo Alto, Versa, ServiceNow Vulnerability Response, Tenable, Qualys, or similar technologies.
- Strong knowledge of security frameworks, risk management methodologies, and infrastructure hardening principles.
- Proven experience managing software upgrades, firmware lifecycle programs, and security remediation initiatives.
- Strong analytical skills with the ability to assess business risk, prioritize remediation activities, and drive measurable outcomes.
- Experience developing compliance dashboards, executive reporting, and operational metrics.
- Strong stakeholder management skills with the ability to influence and coordinate across technology, security, vendor, and business teams.
- Knowledge of infrastructure lifecycle management, EOL/EOS governance, and technology refresh planning.
- Experience leveraging automation and AI-driven capabilities to enhance compliance monitoring and remediation processes.
- Strong communication and presentation skills with the ability to explain technical risks to both technical and non-technical audiences.
- Ability to lead complex global initiatives involving multiple stakeholders, regions, and vendor organizations.
- Demonstrated leadership capability with a proactive, outcome-driven, and risk-focused approach.
Job Requirements:
Education:
Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related technical discipline
Experience:
Minimum of 12 years of experience in Network technology support.
Certification Requirements:
CCNP preferred, Certification on Versa or CCIE is value add.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.