Stay in Compliance Lead-GCS
EY
- Location
- Kochi, KL, IN, 682303
- Work model
- On-Site
- Level
- Senior
About this role
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Stay in Compliance Lead – GCS Job Summary: The Stay In Compliance Lead within Global Connectivity Solutions (GCS) is responsible for defining, governing, and driving the global network infrastructure compliance strategy to ensure network devices remain current, secure, and aligned with supported hardware and software standards. The role is responsible for maintaining the software and hardware currency of network infrastructure across WAN, LAN, WiFi, SD-WAN, telephony, and related connectivity platforms by leading regular software upgrades, security patching, hardware refresh governance, and configuration remediation activities. The position proactively identifies and mitigates security risks by leveraging OEM tools, vulnerability intelligence platforms, and security advisories to assess the exposure of network infrastructure to emerging threats and vulnerabilities. Working closely with I&O Stay in Compliance (SIC), Business Relationship Managers (BRMs), OSTS, Network Engineering, Network Operations, Product Owners, and vendor partners, the role drives GCS enterprise-wide compliance initiatives, ensures timely execution of remediation activities, and strengthens the organization's overall network security posture. The Stay In Compliance Lead serves as the central authority for network lifecycle governance, vulnerability management, compliance reporting, and risk reduction across the global connectivity estate. Job Description
Own and lead the Global Connectivity Solutions (GCS) vulnerability management program, ensuring identification, assessment, prioritisation, remediation, and reporting of security vulnerabilities across the entire GCS product portfolio. Develop and maintain a comprehensive vulnerability remediation and risk management roadmap, leveraging data-driven insights, analytics, and risk-based prioritisation to reduce overall security exposure. Establish and execute Global Vulnerability Management compliance plans across WAN, LAN, WiFi, SD-WAN, Telephony, NAC, Internet Edge, and associated network infrastructure platforms. Drive end-to-end remediation governance for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions in accordance with business and security requirements. Maintain accountability for compliance against remediation SLAs and security standards established by Information Security, tracking progress, ageing, and compliance performance across the GCS estate. Partner with Information Security, Product Owners, Network Engineering, Network Operations, Service Management, OSTS, BRMs, and other stakeholders to ensure effective execution of security remediation activities. Define, implement, and continuously enhance policies, standards, processes, and procedures governing vulnerability management, software currency, hardware lifecycle compliance, and security remediation activities. Establish and maintain a robust controls framework that ensures effective governance, auditability, compliance monitoring, and risk management across GCS services. Collaborate closely with Information Security and Enterprise Technology stakeholders to lead GCS participation in Critical Vulnerability Response Plan (CVRP) exercises and enterprise-wide cyber response activities. Continuously monitor OEM advisories, vulnerability intelligence feeds, security bulletins, and threat intelligence platforms to identify risks impacting GCS infrastructure and services. Partner with vendors and OEMs to assess the impact of emerging security threats, recommended mitigations, software defects, and