- Support execution and operational management of the Data Risk Control program, including the Dataguard program
- Coordinate activities to prevent data exfiltration across regions and service lines
- Coordinate implementation and operational management of data protection controls across EY
- Work with business stakeholders, Information Security teams, product owners and regional leaders to facilitate control deployment
- Address implementation challenges and support risk mitigation efforts
- Serve as a primary point of contact for regional teams and business stakeholders regarding control deployment and adoption
- Track implementation progress, remediation activities, risk mitigation plans and key program milestones
- Support stakeholder engagement, communications, education and awareness activities
- Prepare program metrics, status reports, executive presentations and governance materials for leadership review
- Coordinate testing, validation and documentation related to control implementations
- Support continuous improvement initiatives to enhance program effectiveness and operational efficiency
Requirements
- A minimum of 8 years' experience in Technology Risk Management and/or a similar Information Security capability
- An advanced degree in Computer Science, Information Security or a related discipline, or equivalent work experience
- Proficiency in policy frameworks such as ISO and COBIT
- Strong English language skills, including excellent writing, presentation, interpersonal and communication skills
- Proven ability to manage multiple projects and meet deadlines in a fast-paced, changing environment
- Skilled in executive-level presentations and briefings
- Demonstrated leadership, negotiation, collaboration and influencing skills
- One or more relevant certifications ideally, including CRISC, CISSP, CISM, CISA, CIA, GIAC, CIPP or CIPT
- Strong understanding and continual awareness of external risk trends and business standards
- Strong understanding of EY Business and Service Line Risk Priorities
Core Competencies
Demonstrates expertise in Technology Risk Management and Information Security, with a strong focus on data protection controls, stakeholder engagement, and program management. Proficient in policy frameworks and skilled in executive-level communication and presentations.
Highest-signal resume keywords
- Technology Risk Management
- Data Protection Controls
- ISO Policy Framework
- Executive-Level Presentations
- CRISC Certification
Hard Skills
- Data Risk Control Program
- Control Deployment
- Risk Mitigation
- Implementation Tracking
- Program Metrics Preparation
Soft Skills
- Leadership
- Collaboration
- Negotiation
- Interpersonal Skills
- Communication Skills
Certifications & Qualifications
- CRISC
- CISSP
- CISM
- CISA
- CIA
Industry Keywords
- Information Security
- Data Exfiltration
- Stakeholder Engagement
- Continuous Improvement
- EY Business Risk Priorities