Portfolio Compliance Enablement Leader in Jacksonville, Florida

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.

The exceptional EY experience. It’s yours to build.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 1000 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

Working closely with our service lines and functions and with our technologists across the world, the Portfolio Compliance Enablement function supports digitally enabled services that take advantage of emerging technologies in concert with EY’s broad industry-specific experience and professional services knowledge. The Information Security Portfolio Compliance Enablement Leader leads our EY Portfolio business team to improve their risk posture through compliance enablement with Information Security policies. This lead will partner with requisite SL/Functional leaders and business stakeholders to reinforce policies, control ownership, and compliance responsibilities. They are responsible for and will maintain the overall technology compliance posture for the portfolio leveraging effective governance and oversight. In addition to requiring adequate information security controls, data protection, privacy and software development practices, this role is responsible for helping the organization understand and comply with all laws, rules and regulations governing the company’s technology, including third parties and vendor dependencies.

The role involves comprehensive management of the Portfolio and service line of risk with the primary accountability of reducing that risk by engaging directly with key EY Leaders and ensures the company’s technical systems and information assets are protected in accordance with compliance requirements by doing pro-active compliance management and compliance hunting. Furthermore, the role focuses end-to-end security compliance enablement and is responsible for identifying, evaluating and reporting on information security risks when technological systems and software are not meeting compliance requirements.

As a Portfolio Compliance Enablement Lead within EY’s Global Information Security function, this individual will be a trusted compliance advisor to the organization and serve as a trusted advisor for security compliance. This role will directly engage in managing a team of Compliance Enablement specialists who will drive improvements to the overall risk posture of EY, provide compliance enablement guidance on projects and programs, lead projects aimed at reducing risk, provide insight on top risks impacting the security posture or our businesses, and help define mitigation strategies for strategic compliance risks. The role will directly consult on security vulnerabilities and translation of security compliance risks into business risk terminology for risk-based investment planning. This role is expected to notably enhance the Service Line’s abilities to competently manage and reduce a range of security risks. In doing so, it will add value by protecting the company’s reputation and stability and accelerate the effective and de-risked use of technology.

Furthermore, this role will closely collaborate with leaders within Information Security to implement the team’s strategy, vision, and objectives.

Key responsibilities

This position is a leading role in managing the compliance portfolio for all global, regional, and country-based assets and systems. As a compliance consultant dedicated to the EY Service Line and function, you will be both an individual contributor capable of supporting multiple projects and lead a team of compliance specialists focused on improving the risk posture of the Service Line or function. In other words, it is not just an oversight role, but one that requires detailed understanding of the Service Line, business drivers, key risks and issues, and can help strategize on risk reduction strategies based on analysis of compliance data and trends.

You will lead a team focusing on these pillars:

  • Risk Management and Reduction: Take ownership of the Portfolio or Service Line of security risk and compliance, engaging directly with key EY leaders to reduce risks by providing insights on top risks impacting the security posture of the businesses. Engage in compliance and risk-based investment planning to mitigate these risks effectively.

  • Trend Identification and Remediation: Identify security risk trends and themes that require a comprehensive approach to remediation. Lead and spearhead these efforts, ensuring that risks are mitigated in a timely and efficient manner.

  • Proactive Security Initiatives: Proactively seeking out and identifying security risks, weaknesses, and potential vulnerabilities in systems and processes before they can be exploited and independently stand-up initiatives to address them. Improve compliance with security standards and policies though continuous improvement and innovation in security practices.

  • Governance, Risk, and Compliance (GRC) Management: Manage the end-to-end workflow of security compliance of risk findings in our Governance, Risk, and Compliance (GRC) tool to ensure continuity and compliance with security policies, standards and regulations.

And focus on the following responsibilities:

  • Define compliance strategies and remediation recommendations that provide pragmatic security guidance that balance business benefit and risks.

  • Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or audits.

  • Translate technical vulnerabilities into business risk terminology for the business.

  • Maintain compliance framework assessment toolkits used in testing and validation procedures.

  • Be accountable for and lead assessments for technology infrastructure, applications and third-party dependencies, aligning to regulations, best practices and corporate governance.

Skills and attributes for success

Significant working security experience and knowledge in the management of compliance with company security policies in the following areas:

  • Strong leadership and organizational skills

  • Strategic skills to assist with the development of a long-term vision for EY’s risk management security framework & approach

  • Ability to appropriately balance firm security needs with business impact & benefit

  • Ability to facilitate compromise to incrementally advance security strategy and objectives

  • An overall understanding of the business objectives of EY with an ability to build relationships across EY

  • Ability to team well with others to facilitate and enhance the understanding & compliance to security policies

  • Experience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromise

  • Execute top-down assessment of risk based on policy compliance data and risks

  • Experience conducting risk assessments, vulnerability assessments, vendor and third-party risk assessments and recommending risk remediation strategies

  • Looks for ways to continually improve our compliance with Information Security policies

  • Create, promote, and oversee enforcement protocols, enabling consistency across diverse internal stakeholders

  • Investigate any violations of policies and recommend corrective action.

  • Develop training materials and conduct training sessions to educate on policies and enforcement protocols

  • Develop metrics to evaluate the effectiveness of policy enforcement, and generate regular reports

  • Identify policy and enforcement gaps and propose improvements.

  • Projects advanced consultative skills to conduct effective questioning to break down complex issues into core elements, formulate appropriate ideas or planning and negotiate those ideas and plans clearly and concisely to advance a cooperative engagement by all levels of the organization including senior and/or executive management

  • Proficient understanding of business focus and processes and the ability to inject cybersecurity compliance into the business through teamwork and influence

  • Ability to maintain a high level of integrity, trustworthiness and confidence to represent the company and security leadership with the highest level of professionalism

  • Ability to remain credible with the team and external constituents through sustained industry knowledge

  • Proven project leadership with both legacy and emerging technologies to assess and manage business risk and enforce security controls

  • Wide-ranging knowledge in technical infrastructure and applications, from legacy through next generation

To qualify for the role, you must have

  • A minimum of 10 years’ experience in the field of Cyber Security, Information Security, or related discipline

  • At least 5 years’ experience in a leadership role managing a distributed team and workforce

  • Advanced degree in Cyber Security, Information Security, Computer Science or a related discipline; or equivalent work experience

  • One or more of the following or equivalent certifications: Certified Risk and Information Systems Control (CRISC), Certified Information Systems Security Processional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), Certified Internal Auditor (CIA), Global Information Assurance Certification (GIAC) in related area, CIPP, CIPT

  • Experience working with common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, COBIT

  • Demonstrated leadership experience and thorough understanding of various regulatory requirements and laws such as, but not limited to, PCI, SOX, HIPAA, HITRUST, GDPR and GLBA.

  • Experience in policy enforcement and security compliance, awareness and learning at a publicly traded company

  • Strong understanding of governance, risk, and compliance (GRC) frameworks and tools

  • Proven competence in communicating confidently and effectively with clients, vendors, and all levels of management

  • Experience in managing the communication of security findings and recommendations to IT project teams and management

  • Skilled in executive level presentations and briefings

  • Proven ability to identify and mitigate security risks proactively

  • Insight into the business advantages of good risk management and internal controls beyond compliance purposes

  • Demonstrated leadership, negotiation and collaboration skills, and ability to influence up and down

  • Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment

  • Demonstrated experience in managing end-to-end security compliance enablement projects

  • Extensive experience with security compliance regulations

  • Strong English language skills: excellent writing, presentation, interpersonal, and communication skills are required

  • Capable of working with diverse teams and promoting an enterprise-wide, collaborative security culture

  • Ability to work flexibly and adapt to changing environments

Ideally, you’ll also have

  • Exceptional judgment, tact, and decision-making ability

  • Familiarity with local and regional regulatory requirements and how they impact IT policies

  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change

  • Outstanding management, interpersonal, communication, organizational, and decision-making skills

  • Experience with RSA Archer and/or IBM Open Pages

  • An ability to utilize core risk and controls skills in a broad range of projects both in a traditional internal audit and in advisory projects aimed at assisting in the implementation of controls / improvements

What we look for

We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.

What we offer

The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges.

We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $148,900 to $286,700. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $178,700 to $325,700. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.

  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.

  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.

  • Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.

EY accepts applications for this position on an on-going basis. If you can demonstrate that you meet the criteria above, please contact us as soon as possible.

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

For those living in California, please click here (https://ey-preview.ey.com/content/ey-unified-site/ey-com/local/us/en_us/home/legal-and-privacy/fair-chance-ordinance.html?token=68cf9ed2-94e5-4db9-83cf-5c6aa14619de) for additional information.

EY is an equal opportunity, affirmative action employer providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at [email protected]

To help us track our recruitment effort, please indicate in your cover//motivation letter where (jobsinusa.pro) you saw this job posting.

Application ends on January 1, 1970
Job ID: 213148 Application ends on January 1, 1970

Overview

EY

  • Jacksonville, Florida