Portfolio Compliance Specialist - Supervising Associate - EY Global Delivery Services
CABA, B, AR, 1001
EY
Tarjoamme palveluita, jotka auttavat ratkaisemaan asiakkaidemme vaikeimmat haasteetPortfolio Compliance Enablement Compliance Specialist
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 1000 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The Opportunity
As a Supervising Associate in the Information Security Portfolio Compliance Enablement function, you will play a key role in supporting EY's digital services by ensuring adherence to Information Security policies. This position involves working directly on projects to enhance risk posture, collaborating with business teams, and contributing to the maintenance of the technology compliance posture through effective governance. You will also assist in ensuring data protection, privacy, and software development practices are compliant with legal and regulatory standards.
Key Responsibilities
-
Actively contribute to projects aimed at improving EY's risk posture.
-
Manage delivery of one or more processes and/or solutions with a focus on quality and effective risk management.
-
Assist in the development of compliance strategies and remediation plans.
-
Help translate technical vulnerabilities into business risk terms for stakeholders.
-
Contribute to the maintenance and enhancement of compliance assessment toolkits.
-
Participate in security assessments for technology infrastructure and application risks and vulnerabilities, and third-party dependencies.
-
Contribute to continuous improvement, the identification of innovative solutions through research, analysis, and the application of best practices.
-
Support a team of compliance specialists, providing guidance and expertise on specific projects and initiatives.
Skills and Attributes for Success
-
Solid experience in compliance management within Information Security.
-
Ability to understand and balance security needs with business impact.
-
Strong organizational skills and a proactive approach to problem-solving.
-
Effective communication skills, technical writing, capable of building relationships and facilitating compliance with security policies and documenting processes.
-
Experience in conducting risk assessments and recommending remediation strategies.
-
Knowledgeable in technical infrastructure, applications, and compliance frameworks.
-
Capable of evaluating security policies and systems to ensure compliance with standards.
To Qualify for the Role, You Must Have
-
A minimum of 5 years of experience in Cyber Security, Information Security, or a related field.
-
A degree in Cyber Security, Information Security, Computer Science, or a related discipline.
-
Relevant certifications such as CRISC, CISSP, CISM, CISA, or equivalent.
-
Familiarity with common information security standards like ISO 27001/27002, NIST, PCI DSS.
-
Understanding of regulatory requirements such as PCI, SOX, HIPAA, GDPR.
-
Strong communication skills and the ability to collaborate effectively with teams.
Ideally, You’ll Also Have
-
Excellent problem-solving and decision-making abilities.
-
Adaptability to changing priorities and project scopes.
-
Strong interpersonal and communication skills and ability to present information with purpose and clarity.
-
Experience with GRC platforms like RSA Archer or IBM Open Pages is a plus.
What we look for
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
What we offer
As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:
-
Continuous learning: You will develop the mindset and skills to navigate whatever comes next.
-
Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way.
-
Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs.
-
Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs.
We ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions and to receive other benefits and privileges of employment. Please contact us to request accommodations.
EY is committed to being an inclusive employer, and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
Build your legacy with us.
Apply now.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security CISA CISM CISSP Compliance Computer Science CRISC Cyber defense GDPR Governance HIPAA ISO 27001 NIST PCI DSS Privacy Risk assessment Risk management RSA Security assessment SOX Strategy Vulnerabilities
Perks/benefits: Career development Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.