The opportunity
As a Security Consultant within EY’s internal Security Consulting and Assurance team, the individual will be a trusted security advisor to EY’s Advisory and TAS service lines including delivery of a global managed services platform, big data and analytics solutions as well as individual line of business solutions and services. This role will directly engage in delivery on programs and projects, defining security architectures, providing security guidance, identifying and prioritizing security-related requirements, promoting secure-by-default designs and facilitating delivery of information security services throughout the system development life cycle (SDLC). The role will also direct consultants in developing appropriate risk treatment and mitigation options to address security vulnerabilities to translate these vulnerabilities into business risk terminology for communication to business stake holders.
Your key responsibilities
- Define security architectures and provide pragmatic security guidance that balance business benefit and risks.
- Engage IT project teams throughout the SDLC to identify and prioritize applicable security controls and provide guidance on how to implement these controls
- Perform risk assessments of information systems and infrastructure
- Maintain and enhance the Information Security risk assessment methodology
- Define security configuration standards for platforms and technologies
- Develop appropriate risk treatment and mitigation options to address security risks identified during security review or audit
- Translate technical vulnerabilities into business risk terminology for business units and recommend corrective actions to customers and project stake-holders
- Provide knowledge sharing and technical assistance to other team members
- Act as Subject Matter Expert (SME) in responsible technologies and have deep technical understanding of responsible portfolios
Skills and attributes for success
Strategic skills to assist with the development of a long-term vision for the firms risk management security framework & approachAbility to appropriately balance firm security needs with business impact & benefitAbility to facilitate compromise to incrementally advance security strategy and objectivesAn overall understanding of the business objectives of EY with an ability to build relationships across EY ITAbility to team well with others to facilitate and enhance the understanding & compliance to security policiesExperience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromiseHigh degree of tolerance for ambiguityFive or more years Working experience with the architecture, design and engineering of web-based multi-tier information systems or network infrastructuresExperience with security architecture, design and assessment of messaging, ERP, CRM and or data analytics solutionsExperience conducting risk assessments, vulnerability assessments, vendor and third party risk assessments and recommending risk remediation strategiesExperience working with common information security standards, such as : ISO 27001 / 27002, NIST, PCI DSS, ITIL, COBITExperience with architecture, design and assessment of cloud technologies and cloud-based solutions, ideally Microsoft Azure.To qualify for the role you must have
EducationAn advanced degree in Computer Science or a related discipline, or equivalent work experienceExperienceFive or more years of experience in the management of a significant Information Security risk management function8 or more years of experience in an Information Security or Information Technology disciplineExperience in managing the communication of security findings and recommendations to IT project teams and managementExceptional judgment, tact, and decision-making abilityFlexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid changeOutstanding management, interpersonal, communication, organizational, and decision-making skillsTwo or more years’ experience with architecture, design and assessment of cloud technologies and solutions.Strong English language skills are requiredIdeally, you’ll also have
Candidates are preferred to hold or be actively pursuing related professional certifications within the GIAC family of certifications or CISSP, CISM or CISA
What working at EY offers
We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer :
Support, coaching and feedback from some of the most engaging colleagues aroundOpportunities to develop new skills and progress your careerThe freedom and flexibility to handle your role in a way that’s right for youEY | Building a better working world