- Support execution and operational management of the Data Risk Control program, including the Dataguard program
- Coordinate activities designed to prevent data exfiltration across regions and service lines
- Coordinate implementation and operational management of data protection controls across EY
- Work with business stakeholders, Information Security teams, product owners, and regional leaders
- Facilitate control deployment, address implementation challenges, and support risk mitigation
- Serve as a primary point of contact for regional teams and business stakeholders regarding control deployment and adoption
- Track implementation progress, remediation activities, risk mitigation plans, and key program milestones
- Support stakeholder engagement, communications, education, and awareness efforts
- Prepare program metrics, status reports, executive presentations, and governance materials for leadership review
- Coordinate testing, validation, and documentation of control implementations
- Support continuous improvement to enhance program effectiveness and operational efficiency
Requirements
- A minimum of 8 years' experience in Technology Risk Management and/or a similar Information Security field
- An advanced degree in Computer Science, Information Security or a related discipline, or equivalent work experience
- Proficiency in policy frameworks such as ISO and COBIT
- Strong English language skills, including excellent writing, presentation, interpersonal, and communication skills
- Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment
- Skilled in executive-level presentations and briefings
- Demonstrated leadership, negotiation, collaboration, and influencing skills
- Insight into the business advantages of risk management and internal controls beyond compliance
- Ideally, one or more equivalent certifications such as CRISC, CISSP, CISM, CISA, CIA, GIAC, CIPP, or CIPT
- Strong understanding of external risk trends and business standards
- Strong understanding of EY Business and Service Line Risk Priorities
Core Competencies
Demonstrates expertise in Technology Risk Management and Information Security, with a strong focus on data protection controls, stakeholder engagement, and program effectiveness. Proficient in policy frameworks and skilled in executive-level communication and presentations.
Highest-signal resume keywords
- Technology Risk Management
- Data Protection Controls
- ISO Policy Framework
- Executive-Level Presentations
- CRISC Certification
ATS Optimization Keywords
Hard Skills
- Data Risk Control Program
- Control Deployment
- Risk Mitigation
- Implementation Tracking
- Program Metrics Preparation
Soft Skills
- Leadership
- Negotiation
- Collaboration
- Interpersonal Skills
- Communication Skills
Certifications & Qualifications
- CRISC
- CISSP
- CISM
- CISA
- CIA
Industry Keywords
- Data Exfiltration
- Information Security
- Business Standards
- Risk Management
- EY Business Risk Priorities