FS-RISK CONSULTING-TPRM-SENIOR
About this role
The opportunity
This role provides intermediate technical expertise on the development and support of activities, processes, and tools used for assessing, validating, and ensuring the vulnerability and integrity of systems, while conducting vulnerability scans, supporting security solutions, and contributing to disaster recovery and secure system design.
Your key responsibilities
- Conducts security assessments to measure the adequacy of existing information security controls. Identifies potential and actual system vulnerabilities and emerging strategic security needs, and recommends corrective measures.
- Consults with IT sub-divisions, third party partners, and business units in defining standard consistent reporting formats and providing standard data reports.
- Participates and documents evaluation and assessment of security requirements for data systems, networks, or websites.
- Leads technical support for assessments of assets, risks, and the implementation of appropriate data security procedures and products.
- Assists in the review, development, testing, and implementation processes for security plans, risk assessments, products and control techniques.
- Administers asset inventory and assessment schedules, and provides metrics on security consulting resources, assists with managing vendor relationships.
- Participates in special projects and performs other duties as assigned.
- Conducts regular vulnerability scans on networks and web applications, and performs password audits.
- Supports virus protection, intrusion detection, and security monitoring solutions.
- Assists in planning and implementation of disaster recovery procedures to maintain business continuity.
- Monitors access logs and flags anomalies indicative of possible security breaches.
- Contributes to secure design of systems and infrastructure by offering risk-based recommendations.
- Drive outcomes and results through effective execution and follow-through.
- Resolve issues in a timely and effective manner to support service continuity.
- Ability to handle multiple priorities and manage to service level.
Skills and attributes for success
- A team player with strong analytical, communication and interpersonal skills
- Constantly updating yourself about new technologies in the market
- A winning personality and the ability to become a trusted advisor to the stakeholders
To qualify for the role, you must have
- Minimum 3 to 5 years of related work experience required.
- Undergraduate degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field. Graduate degree in Cybersecurity, Information Assurance, or Computer Science is preferred but not mandatory.
- Experience in IT security or application development preferred.
- Preferred certifications include CISSP, GSEC, GPEN, GWPN, CEH, or other equivalent credentials.
- Strong understanding of IT security controls, risk management, and system assessment practices.
- Practical knowledge of vulnerability scanning tools and security monitoring systems.
- Familiarity with secure coding principles and common system vulnerabilities.
- Experience preparing security reports and assessment documentation for varied stakeholders.
- Analytical mindset with attention to detail for identifying risks and anomalies.
- Strong collaboration and communication skills to coordinate with technical and non-technical teams.
- Working knowledge and experience with IT General Controls for on-prem technical infrastructure (change management, problem management, incident management, backup, replication, job scheduling, physical security, access management).
- Experience with NetBackup and CNTL-M.
- Hands-on experience with ServiceNow.
- Working knowledge of Linux operating systems.
- Working knowledge of Windows operating systems.
- Experience working with Oracle environments.
- Experience with SailPoint.
- Foundational knowledge of AWS.
- Experience with system development pipelines using GitHub.
- CISA/CISSP is preferred
- Must have work experience in technical internal auditing or technical controls assurance testing
Ideally, you’ll also have
- Strong verbal and written communication, facilitation, relationship-building, presentation and negotiation skills.
- Be highly flexible, adaptable, and creative.
- Comfortable interacting with senior executives (within the firm and at the client)
What we look for
Strong teamwork, work ethic, product mindset, client centricity and a relentless commitment to EY values.
What working at EY offers
We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer:
- Support, coaching and feedback from some of the most engaging colleagues around
- Opportunities to develop new skills and progress your career
- The freedom and flexibility to handle your role in a way that’s right for you
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
- Start applying with LinkedIn
- Apply Now Start
-
Please wait...
- Connect with us
- Our locations
- My EY
- Site map
- Legal and privacy
- Labor condition applications
- Cookie Consent Manager
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.