Stay In Compliance Lead - DWES

EY

Ernakulam

On-site

INR 4,000,000 - 7,000,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

EY in India is seeking a Stay in Compliance Lead for DWES to define and govern the digital workplace compliance strategy. You will oversee endpoint management, vulnerability remediation, and security reporting across Windows, macOS, and Microsoft 365 platforms.

The role requires coordinating with multiple teams and vendors to strengthen the organization’s security posture. The ideal candidate has 12+ years of experience in digital workplace or Microsoft 365 platform security, with strong

Qualifications

  • Extensive experience in vulnerability management and remediation governance.
  • Strong knowledge of Microsoft 365 security platforms and endpoint hardening.
  • Proven ability to lead cross‑functional teams and drive security compliance.

Responsibilities

  • Own and lead DWES vulnerability management program across the product portfolio.
  • Develop remediation roadmaps and track progress against SLAs and standards.
  • Define policies, controls, and governance for vulnerability remediation activities.
  • Publish executive dashboards and risk reports on exposure and remediation.
  • Collaborate with Information Security and Enterprise Technology stakeholders.
  • Lead global initiatives with multiple regions and vendor organizations.

Skills

Vulnerability management
Endpoint security
Compliance reporting
Stakeholder management
Microsoft 365 security
Security governance

Education

Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related technical discipline

Tools

Microsoft Defender for Endpoint
Intune
SCCM
MSRC advisories
ServiceNow Vulnerability Response
Tenable/Qualys

Job description

Job Description

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Job Title : Stay in Compliance Lead - DWES
Job Summary

The Stay In Compliance Lead within Digital Workplace & Experience Services (DWES) is responsible for defining, governing, and driving the digital workplace compliance strategy to ensure endpoints, collaboration platforms, and Microsoft 365 services remain current, secure, and aligned with supported hardware and software standards. The role is responsible for maintaining the software and hardware currency of the digital workplace estate across Windows and macOS endpoints, mobile devices, virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and related M365 platforms by leading regular software upgrades, security patching, hardware refresh governance, and configuration remediation activities.

The position proactively identifies and mitigates security risks by leveraging OEM tools, vulnerability intelligence platforms (including MSRC advisories and Microsoft Defender for Endpoint), and security advisories to assess the exposure of the digital workplace estate to emerging threats and vulnerabilities. Working closely with I&O Stay in Compliance (SIC), Business Relationship Managers (BRMs), OSTS, Endpoint Management, Collaboration & Platforms, M365 Foundation Services, Ops & Engineering, Product Owners, and vendor partners, the role drives DWES enterprise-wide compliance initiatives, ensures timely execution of remediation activities, and strengthens the organizations overall digital workplace security posture. The Stay In Compliance Lead serves as the central authority for endpoint and platform lifecycle governance, vulnerability management, compliance reporting, and risk reduction across the global digital workplace estate.

Job Description
  • Own and lead the Digital Workplace & Experience Services (DWES) vulnerability management program, ensuring identification, assessment, prioritisation, remediation, and reporting of security vulnerabilities across the entire DWES product portfolio.
  • Develop and maintain a comprehensive vulnerability remediation and risk management roadmap, leveraging data-driven insights, analytics, and risk-based prioritisation to reduce overall security exposure.
  • Establish and execute Global Vulnerability Management compliance plans across Windows and macOS endpoints, mobile devices, virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and associated Microsoft 365 platforms.
  • Drive end-to-end remediation governance for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions in accordance with business and security requirements.
  • Maintain accountability for compliance against remediation SLAs and security standards established by Information Security, tracking progress, ageing, and compliance performance across the DWES estate.
  • Partner with Information Security, Product Owners, Endpoint Management, Collaboration & Platforms, Ops & Engineering, Service Management, OSTS, BRMs, and other stakeholders to ensure effective execution of security remediation activities.
  • Define, implement, and continuously enhance policies, standards, processes, and procedures governing vulnerability management, software currency, hardware lifecycle compliance, and security remediation activities.
  • Establish and maintain a robust controls framework that ensures effective governance, auditability, compliance monitoring, and risk management across DWES services.
  • Collaborate closely with Information Security and Enterprise Technology stakeholders to lead DWES participation in Critical Vulnerability Response Plan (CVRP) exercises and enterprise-wide cyber response activities.
  • Continuously monitor OEM advisories, MSRC and vulnerability intelligence feeds, security bulletins, and threat intelligence platforms to identify risks impacting DWES infrastructure and services.
  • Partner with vendors and OEMs to assess the impact of emerging security threats, recommended mitigations, software defects, and lifecycle-related risks.
  • Drive execution of critical security patching, emergency remediation activities, and infrastructure upgrades to reduce organisational risk exposure.
  • Act as the primary DWES representative within the Intelligent Operations Center (IOC) for security vulnerability management, remediation coordination, and risk response activities.
  • Review, challenge, and validate risk exception requests, ensuring technical justification, compensating controls, and business impact assessments are appropriately documented before approval.
  • Provide technical guidance and risk advisory support to leadership teams, product owners, and business stakeholders regarding vulnerability remediation strategies and compliance obligations.
  • Develop, maintain, and publish executive dashboards, scorecards, and management reports covering vulnerability exposure, remediation progress, security compliance, software currency, hardware currency, and risk posture across DWES.
  • Define and monitor key performance indicators (KPIs), risk indicators (KRIs), remediation targets, and compliance metrics to measure programme effectiveness.
  • Drive automation and continuous process improvement initiatives across vulnerability assessment, remediation tracking, software upgrades, patch management, compliance reporting, and IOC operational activities.
  • Partner with Service Management teams to ensure all security remediation activities adhere to established governance, change management, ITSM, and operational compliance requirements.
  • Own stakeholder communications related to security vulnerabilities, remediation plans, compliance risks, maintenance activities, and risk mitigation strategies.
  • Lead incident-related vulnerability remediation activities, ensuring effective coordination across technical teams and timely communication to stakeholders.
  • Lead and manage the DWES Stay In Compliance team, ensuring clear accountability, ownership, and execution of vulnerability management and remediation activities.
Knowledge & Competencies Required
  • Deep understanding of digital workplace technologies including Windows and macOS endpoint management, mobile device management (Intune), virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and Microsoft 365 security platforms.
  • Strong expertise in vulnerability management, digital workplace security compliance, patch management, and endpoint/platform lifecycle governance.
  • Experience working with OEM security advisory tools and vulnerability management platforms such as Microsoft MSRC, Microsoft Defender for Endpoint, Microsoft Intune, SCCM, ServiceNow Vulnerability Response, Tenable, Qualys, or similar technologies.
  • Strong knowledge of security frameworks, risk management methodologies, and endpoint and platform hardening principles.
  • Proven experience managing software upgrades, OS and application lifecycle programs, and security remediation initiatives.
  • Strong analytical skills with the ability to assess business risk, prioritize remediation activities, and drive measurable outcomes.
  • Experience developing compliance dashboards, executive reporting, and operational metrics.
  • Strong stakeholder management skills with the ability to influence and coordinate across technology, security, vendor, and business teams.
  • Knowledge of infrastructure lifecycle management, EOL/EOS governance, and technology refresh planning.
  • Experience leveraging automation and AI-driven capabilities to enhance compliance monitoring and remediation processes.
  • Strong communication and presentation skills with the ability to explain technical risks to both technical and non-technical audiences.
  • Ability to lead complex global initiatives involving multiple stakeholders, regions, and vendor organizations.
  • Demonstrated leadership capability with a proactive, outcome-driven, and risk-focused approach.
Job Requirements
Education
  • Bachelors degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related technical discipline
Experience
  • Minimum of 12 years of experience in digital workplace, endpoint, or Microsoft 365 platform technology support.
Certification Requirements
  • Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) or Microsoft Certified: Security, Compliance, and Identity Fundamentals preferred; Microsoft Certified: Cybersecurity Architect Expert (SC-100) is value add.
Requirements

EY | Building a better working world

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Stay in Compliance Lead-GCS
Stay in Compliance Lead-GCS

EY • Ernakulam

On-site
INR 4,000,000 - 6,000,000
Stay in Compliance Lead-GCS
Stay in Compliance Lead-GCS

Ernst & Young Advisory Services Sdn Bhd • Ernakulam

On-site
INR 2,500,000 - 4,500,000
Windows And Linux Compliance SME
Windows And Linux Compliance SME

EY • Ernakulam

On-site
INR 2,400,000 - 3,600,000
ET Stay-In-Compliance Consultant
ET Stay-In-Compliance Consultant

EY • Ernakulam

On-site
INR 3,500,000 - 6,500,000
Windows and Linux Compliance SME
Windows and Linux Compliance SME

Ernst & Young Advisory Services Sdn Bhd • Thrippunithura

Hybrid
INR 1,800,000 - 2,400,000
TC-CS-Cyber Architecture- OT and Engineering-infrastructure Security-Manager
TC-CS-Cyber Architecture- OT and Engineering-infrastructure Security-Manager

EY • Thiruvananthapuram

On-site
INR 1,400,000 - 2,100,000
Health insurance
Flexible work environment
Learning opportunities
Platform Infrastructure Patching and Vulnerability Compliance Lead
Platform Infrastructure Patching and Vulnerability Compliance Lead

Ernst & Young Advisory Services Sdn Bhd • Ernakulam

On-site
INR 4,000,000 - 7,000,000
Continuous learning
Career development
Total rewards
TC-CS-Cyber Architecture- OT And Engineering-infrastructure Security-Manager
TC-CS-Cyber Architecture- OT And Engineering-infrastructure Security-Manager

EY • Chennai District

On-site
INR 4,000,000 - 7,000,000
Health insurance
Learning & development
Inclusive culture
Tech S and T-DWP Engineer-Senior-GDSN02
Tech S and T-DWP Engineer-Senior-GDSN02

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 1,200,000 - 2,400,000
TC-CS-Cyber Architecture- OT And Engineering-infrastructure Security-Manager
TC-CS-Cyber Architecture- OT And Engineering-infrastructure Security-Manager

EY • Gurugram District

On-site
INR 3,000,000 - 5,000,000
Health and wellness benefits
Learning and development programs