Vulnerability Management & Compliance Engineer - EY Global Delivery Services
EY
Security Monitoring – Vulnerability Management & Compliance Engineer
Today’s world is fueled by vast amounts of information, which means that data is even more valuable than ever before. Protecting data and information systems is central to doing business, and therefore everyone in EY Information Security has an important role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond when things go wrong. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology service solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting, and enabling the business through secure solutions and information systems.
The opportunity
As a Security Engineer for SIEM technologies within the Security Technology Services (STS) group, you will become part of a global team responsible for the complete life cycle of our solutions and services; design, engineering, implementation, and early life cycle support within our EY multi-cloud and on-premises environments. This role will work closely with Security Architects, Security Service Delivery, Security Operations, and Information Security teams for enablement of security solutions and services across various Security Domains, as well as, across various Global EY Teams and Technologies. You will also provide consulting services to other teams, as well as a level four contact for operational issues.
- Articulate technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to technology leaders.
- Engineer security solutions and services following all relevant EY standards and practices for On-Premise, Hybrid and Cloud-Based environments.
- Provide detailed input into the design and leads the implementation and testing of security solutions and services for large, complex projects from initial design to completion which includes production support and documentation.
- Take accountability for the design, delivery and maintenance of new and existing security solutions or services, driving compliance with and contributing to the development of relevant standards.
- Apply modern standards/principles, global product-specific guidelines, security standards, design standards, to security solutions and services as appropriate.
- Collaborate with Security Architecture, Service Owners, and Security Operations teams to promote automation and innovation throughout the security solutions that are being maintained, thereby enhancing the security posture of these solutions.
- Represent the team in specific Project activities, including participating in projects and driving your deliverables towards successful completion.
- Work in a diverse global environment and build strong relationships across all levels of a matrixed, geographically and culturally dispersed organization.
- No direct supervisory responsibilities, however, Technical Leadership will be required within assigned services and solutions.
Skills and Attributes for Success
We are seeking individuals with practical experience in functional and/or technical security engineering within a large enterprise setting, specifically in the implementation and maintenance of Compliance, Vulnerability and Response security solutions.
The successful candidate will have:
- Advanced technical proficiency in designing and implementing security compliance and risk solutions within a very large enterprise:
- Experience with Archer applications, solutions, and components.
- Windows Server Support.
- Knowledge of IIS configuration.
- Knowledge of languages such as Python and or PowerShell a plus.
- Several years’ experience working in a large global virtual environment.
- Experience with data analytics, including designing, creating, and implementing data models for enterprise-level programs and systems.
- Knowledge of various cloud computing platforms, including Azure, Google Cloud, and Amazon Web Services.
- Experience with in ETL Tools like Azure Data Factory, SSIS.
- Knowledge of GitHub.
- Basic scripting and automation skills.
- Communicate fluently in English, both written and verbal, and able to communicate technical concepts effectively.
- Excellent interpersonal communication and organizational skills and the ability to work within tight timeframes.
- Rapidly learn new and emerging technologies with the ability to define engineering standards quickly and efficiently.
To qualify for the role, you must have
- Detailed knowledge of several of the following: EDR, AV/AM, Vulnerability Scanning, Cloud Operations, IPS/IDS, O365 Tenants, networking concepts & mechanisms, scripting in Python or another language, and other relevant technologies.
- At least 5 years of experience in Security, including demonstratable knowledge of Compliance and Vulnerability technologies.
- 3+ years demonstrated ability in an engineering function.
- Several years’ experience working in a large global virtual environment and enterprise environments at scale.
- A strong understanding of other technologies required to run a secure, enterprise level infrastructure that adhere to security best practices.
- Excellent time management, organizational, and decision-making skills.
- The ability to design and document processes, procedures, and security designs clearly and accurately for distribution to internal teams and customers.
- Demonstrated experience in dealing with external vendors and suppliers in the security industry.
- Technical proficiency with interacting with APIs and scripting tools (Python, Ansible, PowerShell, etc.), is a plus.
Ideally, you’ll also have
- A bachelor's degree in Computer Science, Engineering, IT, Mathematics or a related field, or equivalent work experience.
- GSEC/CISSP or other security related generalist certification from ISC2 or GIAC.
- Experience in project management, service introduction, and service readiness.
What we look for
This role is perfect for you, if you have excellent problem solving, decision making, and communication skills.
We are looking for people who are comfortable working with culturally diverse on/offshore team members, able to react appropriately during stressful and ambiguous situations.
Independent thinkers with team driven values.
What we offer
As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial, and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:
- Continuous learning: You will develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way.
- Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs.
We ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions and to receive other benefits and privileges of employment. Please contact us to request accommodations.
EY is committed to being an inclusive employer, and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
Join us in building a better working world.
Apply now.