About this role
<div> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">At EY, we’re all in to shape your future with confidence. </span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.</span></p> </div> <div> </div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets. Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>The opportunity</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stepping into the role of America’s Technology Risk Leader offers a compelling opportunity to shape the technology and data risk posture across the Americas while aligning with EY’s global Information Security strategy.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">This position requires navigating a complex landscape of business priorities, regulatory expectations, operating models and risk scenarios across the Americas. As the steward of the technology risk posture for the area, the role has a clear mandate to identify, evaluate and mitigate significant technology risks, while also leading the implementation of people, process and technical controls designed to prevent data exfiltration and strengthen control effectiveness.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The role is designed for a senior leader who can translate complex technical risk and control concepts into clear, business-friendly guidance; influence senior stakeholders across Area, Regional and Member Firm leadership; and ensure that risk mitigation strategies are practical, well sponsored and consistently executed. It offers the chance to make a meaningful strategic impact, improve resilience, strengthen trust with clients and regulators, and shape the future of risk management practices in one of the firm’s most important areas.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your key responsibilities</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Area technology and data risk leadership</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead a strategic approach to identifying, evaluating and mitigating technology risks across the Americas area.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Serve as the steward of the organization’s technology risk posture across the area and ensure the most significant risks receive appropriate sponsorship, budget and support for effective remediation.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead the consistent implementation of people, process and technical controls designed to prevent data exfiltration across regions, service lines and business environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Validate that implementations adhere to global standards and policies while accommodating local regulatory and operational requirements.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Risk assessments, methodology and remediation strategy</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Oversee the delivery of TARP service offerings and coordinate comprehensive risk assessments using TARP methodology.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Drive the identification, assessment and prioritization of technology and data risks, and develop risk management and mitigation strategies tailored to area needs.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Facilitate the smooth implementation of Information Security programs that involve Area, Regional and Member Firm Risk Management stakeholders.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Collaborate with business and technology stakeholders to understand technology dependencies, relevant threat scenarios and control gaps, and convert those insights into actionable remediation plans.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stakeholder advisory, escalation and communication</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Act as the primary liaison between Information Security and business stakeholders at all levels of the firm, explaining the purpose, design and benefits of technology risk and control initiatives in clear, business-friendly language.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Become the trusted advisor on technology risk topics for Area, Regional and Member Firm Risk Management leaders, Business Relationship Managers, IT leaders and other senior stakeholders.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Serve as the primary escalation point for technology risks and implementation challenges, coordinating with regional and global teams to resolve issues and maintain program alignment.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Use strong executive presentation and briefing skills to communicate strategy, progress, risk posture and required decisions to senior management, the program steer co and the Information Security Leadership Team.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Control enablement, education and continuous improvement</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Drive stakeholder engagement through education, communication and collaboration to foster a culture of compliance, proactive risk management and adoption of controls.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead educational initiatives on technology risks, control expectations and external risk trends relevant to the Americas area.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Monitor progress and regularly report on risk status, mitigation efforts and program performance to senior leaders and governance forums.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stay informed on emerging threats, technologies, methodologies, regulatory changes and business standards in order to continuously refine strategies, processes and policies.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Skills and attributes for success</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Insight into the business advantages of good risk management and internal controls beyond compliance purposes.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Skilled in executive-level presentations and briefings.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Demonstrated leadership, negotiation and collaboration skills, with the ability to influence both upward and downward across the organization.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strategic mindset and the ability to connect technical risk, business priorities and control outcomes in a way that drives action.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>To qualify for the role you must have</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A minimum of 15 years’ experience in Technology Risk Management and/or a similar field within Information Security.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">An advanced degree in Computer Science, Information Security or a related discipline, or equivalent work experience.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proficiency in policy and control frameworks such as ISO and COBIT.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong English language skills, including excellent writing, presentation, interpersonal and communication capabilities.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A minimum of 10 years of experience managing senior or managerial staff in Governance, Risk and Compliance (GRC) or related areas.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Ideally, you’ll also have</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">One or more of the following or equivalent certifications: CRISC, CISSP, CISM, CISA, CIA, GIAC in a related area, CIPP, or CIPT.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A strong understanding of external risk trends and business standards, and a commitment to staying current on methodologies and external developments that EY should prepare for from a risk perspective.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A strong understanding of EY business and Service Line risk priorities.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>What we look for</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We seek an individual with a strategic mindset and expertise in technology risk management who can proactively identify, assess and mitigate risks while strengthening the organization’s resilience against an evolving threat landscape. The ideal candidate will bring strong leadership skills, the ability to collaborate across departments and geographies, and a clear commitment to maintaining compliance with industry standards and regulatory requirements.</span></p><div> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>What we offer you</strong></span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn <a href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ey.com%2Fen_gl%2Fcareers&data=05%7C02%7Cdeborah.compagner%40ey.com%7C41999b589ae04d7f6b8a08dd04d62e9a%7C5b973f9977df4bebb27daa0c70b8482c%7C0%7C0%7C638672040144488329%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Mb96MEoh9R3oQ1cGLr73tEDtKTSUYCyfOhCZ%2BmMHY9w%3D&reserved=0">more</a>.</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $152,700 to $294,000. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $183,300 to $334,100. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Are you ready to shape your future with confidence? Apply today. </strong></span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY accepts applications for this position on an on-going basis.<strong> </strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">For those living in California, please click <a href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ey.com%2Fen_us%2Flegal-and-privacy%2Ffair-chance-ordinance&data=05%7C02%7CKatie.Fusco%40ey.com%7Ca854c911111641604b1908dcbae61395%7C5b973f9977df4bebb27daa0c70b8482c%7C0%7C0%7C638590744554256267%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=OMroKPwn6YEFe32dLGrEivljaobbnMbqSwp4tFRvnfc%3D&reserved=0">here</a> for additional information.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>EY | Building a better working world</strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. </span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at <a href="mailto:[email protected]">[email protected]</a>.</span></p> </div>