ET SIC Reporting Analyst
EY
- Location
- Kochi, KL, IN, 682303
- Work model
- On-Site
- Level
- Mid
About this role
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
ET SIC Reporting Analyst EY is a global leader in assurance, tax, transaction and advisory services. Technology is at the heart of what we do and deliver at EY. Technology solutions are integrated in the client services we deliver and are key to our innovation as an organization. Fueled by a US$1.5+B investment in technology and innovation, EY is primed to guide clients in their efforts to drive sustainable growth, create new value, and build new and better ways of working. As part of Enterprise Technology, you’ll be at the forefront of integrating technology into what we do at EY. That means more growth for you, exciting learning opportunities, career choices and the chance to make a real impact. The role SIC Reporting Analyst is responsible for supporting vulnerability management reporting for ET (excluding Platform Mgmt) and providing accurate, timely and actionable compliance insights. This position requires close collaboration with global teams across ET, Infosec and business functions to align reporting with the broader risk frameworks. The analyst will be responsible for monitoring progress against vulnerability mgmt goals, validating that vulnerabilities are remediated or approved plans are recorded within defined SLA targets, and providing compliance status through regular assessments, on-going leadership reviews and real-time dashboards. As part of the role, the individual will assess existing reporting processes, refine them as business needs change, and work closely with Infosec and other stakeholders to strengthen data quality, reporting controls and governance models within Enterprise Technology. The ideal candidate brings relevant experience in IT risk reporting, governance and analytics, contributing to EY’s overall risk management plan. Your key responsibilities As the SIC Reporting Analyst, the key responsibilities would include:
Prepare and maintain Global Vulnerability mgmt compliance reports for all in-scope IT functions within Enterprise Technology (excluding Platform Mgmt), including GRAC reporting for in-scope I&O functions. Consolidate vulnerability, remediation and exception data from approved sources; validate completeness and accuracy before reports are published. Monitor compliance within agreed SLA’s as established by Infosec, tracking remediation progress, overdue items and adherence to security policies. Prepare weekly / monthly SIC updates and leadership review materials to provide clear insights into vulnerability mgmt performance. Maintain reporting definitions, templates, calculation logic and documented controls to enable consistent and repeatable reporting. Collaborate with Infosec and I&O product managers to understand reporting requirements, source-data changes and future product road maps. Maintain end-to-end reporting views for vulnerabilities across ET (excluding Platform Management), including remediation plans, exceptions, approvals and closure status. Work closely with Infosec and stakeholders within ET to provide reporting support for Critical Vulnerability Response Plan (CVRP) exercises. Produce vulnerability management dashboards, scorecards, trend analysis and actionable insights for operational and leadership reviews. Collaborate with stakeholders and act as a reporting conduit between Infosec, Product/Application, Engineering, Operations & Management; follow up on data gaps and unresolved ownership issues. Provide segmented reporting and follow-up views for Data Restricted Countries (DRCS) and Local Support teams (excluding Platform Management). Identify, assess and