Data Stewardship - Risk and Controls Senior Associate
Other locations: Primary Location Only
Date: 17 Jul 2026
Requisition ID: 1713420
Data Stewardship – Risk and Controls Senior Associate
The opportunity
You will be part of the GDS RMS Data Risk Exceptions team responsible for operating a centralized Data Risk Exceptions Management process. This role supports EY Member Firms and Regions across EMEIA by providing a consistent and standardized approach for managing exception requests related to data transfer restrictions and controls.
The role contributes to protecting EY and client data by ensuring that all exception requests are reviewed, triaged, and processed in line with EY policies, while enabling business needs to be met in a controlled and compliant manner.
Your key responsibilities
- Act as part of a centralized team responsible for intake, triage and processing of data transfer exception requests across multiple controls and regions
- Perform initial review of exception requests, ensuring completeness, appropriate business justification, and required approvals
- Conduct risk‑based assessment of requests, identifying potential data protection, confidentiality and insider threat risks
- Provide clear recommendations and summaries to support decision‑making by control owners and approvers
- Coordinate across multiple stakeholders, including: Engagement teams, Information Security teams, Control owners, Track requests through their lifecycle, ensuring timely processing and adherence to defined SLAs, Maintain accurate documentation of requests, decisions, and conditions applied, Support development of centralized reporting and dashboards, identifying trends, recurring risks and improvement opportunities, Contribute to process standardization and documentation (playbooks, SOPs, guidance materials), Provide guidance to requestors on secure alternatives and compliant data transfer practices
Skills and attributes for success
- Strong understanding of data protection, confidentiality and information security principles
- Ability to apply structured, risk‑based thinking in operational decision support
- High attention to detail and ability to manage process‑driven work with accuracy and consistency
- Strong communication and stakeholder management skills in a global, cross‑functional environment
- Ability to prioritize and manage multiple requests across tools and processes
- A proactive mindset with focus on continuous improvement and standardization
Good knowledge of:
- Data transfer channels
- EY Acceptable Use of Technology Policy and relevant InfoSec guidance
To qualify for the role, you must have
- You should be fluent in English (C1)
- 4+ years of related work experience
- Relevant professional experience in:
- Data Risk / Information Security / Data Exfiltration
- Compliance or operational governance processes
- Experience working with structured processes, workflows or case management systems
- Ability to analyze information and support risk‑based decision‑making
- Experience engaging with senior stakeholders demonstrating confidence in communication and presenting risk‑related topics
Ideally, you’ll also have
- IAPP certifications (either CIPP/E, CIPP/US and/or CIPM)
What we look for
- A risk‑aware mindset, balancing business needs with data protection requirements
- Confidence in working within a new and evolving process environment
- Strong ownership and accountability for quality and outcomes
- Ability to collaborate effectively across geographies and seniority levels
- A continuous improvement mindset, contributing to shaping a scalable and sustainable global service
What we offer
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.