Global Lead Security Compliance & Enforcement - Director
EY
- Location
- Hoboken, NJ, US, 07030 +19 more…
- Work model
- On-Site
- Level
- Staff
About this role
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunity The Global Lead Security Compliance & Enforcement owns the strategy, operating model, and outcomes for the global Security Compliance function within Technology Assurance, Risk & Policy. The role transforms Security Compliance into a proactive, intelligence-driven, and enforcement-capable organization that reduces risk debt, sustains critical governance, risk, and compliance operations and provides defensible, audit-ready governance. The Director creates clear global accountability for security compliance and converts fragmented or ambiguous risk situations into prioritized action. Using policy, compliance-posture data, risk appetite, escalation protocols, and executive decision forums, the role addresses situations in which ownership, remediation capacity, enforcement authority, or risk tolerance are unclear. This includes clearing persistent enforcement backlogs, sequencing scarce specialist capacity across concurrent initiatives, expanding control monitoring, resolving technology-lifecycle exposure, and establishing governance for frontier AI and DataGuard obligations. Working with CTOs, Service Line Quality Leaders, Technology Risk & Compliance, Information Security leadership, risk and control owners, technology teams, and audit and governance stakeholders, the Director balances policy requirements with business impact, technology delivery, client confidence, and documented risk acceptance. The role sets the multi-year roadmap, leads a globally distributed organization, and provides senior leaders with decision-quality information on compliance posture, risk trends, enforcement, and remediation. Key Responsibilities
Strategic Leadership
Define and execute the global Security Compliance strategy, target operating model, multi-year roadmap, priorities, performance measures, and resource plan in alignment with risk appetite and business objectives. Lead and develop a globally distributed, capability-led organization that proactively addresses the highest-risk exposures while sustaining business-as-usual GRC operations and talent succession.
Compliance Governance & Enforcement
Own global policy compliance and the Non-Compliance Consequence Framework, including consistent enforcement, escalation, investigation, corrective action, backlog reduction, and documented risk acceptance.
Risk Intelligence & Remediation
Build data-driven risk intelligence and expand control monitoring and assurance through clear evidence, metrics, trends, dashboards, executive reporting, and risk burn-down tracking. Direct remediation and technology-lifecycle governance, including out-of-SLA vulnerability triage, End-of-Life exposure, exceptions, and emerging AI and DataGuard obligations.
AI Governance & Emerging Technologies
Establish compliance governance, monitoring, accountability, and reporting for frontier AI, DataGuard, and other emerging-technology obligations.
Stakeholder & Executive Engagement
Partner with CTOs, Service Line Quality Leaders, risk, security, audit, governance, and technology teams to balance policy, business impact, client confidence, and delivery, while advancing automation and continuous improvement.
Supervision Responsibilities The Director reports to the Global Leader, Technology Assurance, Risk & Policy within Information Security and leads the global Security Compliance function. Knowledge and Skills Requirements
Deep knowledge of cyber security, technology and data risk, policy compliance, control assurance, GRC operations, enterprise remediation, exception governance, and risk acceptance. Practical understanding of ISO 27001/27002, ISO 31000, COBIT, unified compliance frameworks, audit expectations, and