Jump to content

Stay In Compliance Lead - DWES | ErnstYoung Job


 Share

Job Opportunity Details

Type

Full Time

Salary

Not Telling

Work from home

No

Weekly Working Hours

Not Telling

Positions

Not Telling

Working Location

Kochi, Kochi, KL, 682303, India   [ View map ]

Job Description

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Job Title   :   Stay in Compliance Lead - DWES

 

 

Job Summary:

 

The Stay In Compliance Lead within Digital Workplace & Experience Services (DWES) is responsible for defining, governing, and driving the digital workplace compliance strategy to ensure endpoints, collaboration platforms, and Microsoft 365 services remain current, secure, and aligned with supported hardware and software standards. The role is responsible for maintaining the software and hardware currency of the digital workplace estate across Windows and macOS endpoints, mobile devices, virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and related M365 platforms by leading regular software upgrades, security patching, hardware refresh governance, and configuration remediation activities.

 

The position proactively identifies and mitigates security risks by leveraging OEM tools, vulnerability intelligence platforms (including MSRC advisories and Microsoft Defender for Endpoint), and security advisories to assess the exposure of the digital workplace estate to emerging threats and vulnerabilities. Working closely with I&O Stay in Compliance (SIC), Business Relationship Managers (BRMs), OSTS, Endpoint Management, Collaboration & Platforms, M365 Foundation Services, Ops & Engineering, Product Owners, and vendor partners, the role drives DWES enterprise-wide compliance initiatives, ensures timely execution of remediation activities, and strengthens the organization's overall digital workplace security posture. The Stay In Compliance Lead serves as the central authority for endpoint and platform lifecycle governance, vulnerability management, compliance reporting, and risk reduction across the global digital workplace estate.

 

 

Job Description

 

  • Own and lead the Digital Workplace & Experience Services (DWES) vulnerability management program, ensuring identification, assessment, prioritisation, remediation, and reporting of security vulnerabilities across the entire DWES product portfolio.
  • Develop and maintain a comprehensive vulnerability remediation and risk management roadmap, leveraging data-driven insights, analytics, and risk-based prioritisation to reduce overall security exposure.
  • Establish and execute Global Vulnerability Management compliance plans across Windows and macOS endpoints, mobile devices, virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and associated Microsoft 365 platforms.
  • Drive end-to-end remediation governance for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions in accordance with business and security requirements.
  • Maintain accountability for compliance against remediation SLAs and security standards established by Information Security, tracking progress, ageing, and compliance performance across the DWES estate.
  • Partner with Information Security, Product Owners, Endpoint Management, Collaboration & Platforms, Ops & Engineering, Service Management, OSTS, BRMs, and other stakeholders to ensure effective execution of security remediation activities.
  • Define, implement, and continuously enhance policies, standards, processes, and procedures governing vulnerability management, software currency, hardware lifecycle compliance, and security remediation activities.
  • Establish and maintain a robust controls framework that ensures effective governance, auditability, compliance monitoring, and risk management across DWES services.
  • Collaborate closely with Information Security and Enterprise Technology stakeholders to lead DWES participation in Critical Vulnerability Response Plan (CVRP) exercises and enterprise-wide cyber response activities.
  • Continuously monitor OEM advisories, MSRC and vulnerability intelligence feeds, security bulletins, and threat intelligence platforms to identify risks impacting DWES infrastructure and services.
  • Partner with vendors and OEMs to assess the impact of emerging security threats, recommended mitigations, software defects, and lifecycle-related risks.
  • Drive execution of critical security patching, emergency remediation activities, and infrastructure upgrades to reduce organisational risk exposure.
  • Act as the primary DWES representative within the Intelligent Operations Center (IOC) for security vulnerability management, remediation coordination, and risk response activities.
  • Review, challenge, and validate risk exception requests, ensuring technical justification, compensating controls, and business impact assessments are appropriately documented before approval.
  • Provide technical guidance and risk advisory support to leadership teams, product owners, and business stakeholders regarding vulnerability remediation strategies and compliance obligations.
  • Develop, maintain, and publish executive dashboards, scorecards, and management reports covering vulnerability exposure, remediation progress, security compliance, software currency, hardware currency, and risk posture across DWES.
  • Define and monitor key performance indicators (KPIs), risk indicators (KRIs), remediation targets, and compliance metrics to measure programme effectiveness.
  • Drive automation and continuous process improvement initiatives across vulnerability assessment, remediation tracking, software upgrades, patch management, compliance reporting, and IOC operational activities.
  • Partner with Service Management teams to ensure all security remediation activities adhere to established governance, change management, ITSM, and operational compliance requirements.
  • Own stakeholder communications related to security vulnerabilities, remediation plans, compliance risks, maintenance activities, and risk mitigation strategies.
  • Lead incident-related vulnerability remediation activities, ensuring effective coordination across technical teams and timely communication to stakeholders.
  • Lead and manage the DWES Stay In Compliance team, ensuring clear accountability, ownership, and execution of vulnerability management and remediation activities.

 

 

Knowledge & Competencies Required:

 

  • Deep understanding of digital workplace technologies including Windows and macOS endpoint management, mobile device management (Intune), virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and Microsoft 365 security platforms.
  • Strong expertise in vulnerability management, digital workplace security compliance, patch management, and endpoint/platform lifecycle governance.
  • Experience working with OEM security advisory tools and vulnerability management platforms such as Microsoft MSRC, Microsoft Defender for Endpoint, Microsoft Intune, SCCM, ServiceNow Vulnerability Response, Tenable, Qualys, or similar technologies.
  • Strong knowledge of security frameworks, risk management methodologies, and endpoint and platform hardening principles.
  • Proven experience managing software upgrades, OS and application lifecycle programs, and security remediation initiatives.
  • Strong analytical skills with the ability to assess business risk, prioritize remediation activities, and drive measurable outcomes.
  • Experience developing compliance dashboards, executive reporting, and operational metrics.
  • Strong stakeholder management skills with the ability to influence and coordinate across technology, security, vendor, and business teams.
  • Knowledge of infrastructure lifecycle management, EOL/EOS governance, and technology refresh planning.
  • Experience leveraging automation and AI-driven capabilities to enhance compliance monitoring and remediation processes.
  • Strong communication and presentation skills with the ability to explain technical risks to both technical and non-technical audiences.
  • Ability to lead complex global initiatives involving multiple stakeholders, regions, and vendor organizations.
  • Demonstrated leadership capability with a proactive, outcome-driven, and risk-focused approach.

 

 

Job Requirements:

 

Education:

  • Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related technical discipline

 

Experience:

  • Minimum of 12 years of experience in digital workplace, endpoint, or Microsoft 365 platform technology support.

 

Certification Requirements:

  • Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) or Microsoft Certified: Security, Compliance, and Identity Fundamentals preferred; Microsoft Certified: Cybersecurity Architect Expert (SC-100) is value add.

 

 

 

EY | Building a better working world 

 

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

 

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

 

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  


More Information

Application Details

  • Organization Details
    Ernst & Young
 Share


User Feedback

Recommended Comments

There are no comments to display.

Join the conversation

You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Add a comment...

×  Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×  Your link has been automatically embedded.   Display as a link instead

×  Your previous content has been restored.   Clear editor

×  You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...