at EY in Topeka, Kansas, United States
Job Description
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets. Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
Stepping into the role of America’s Technology Risk Leader offers a compelling opportunity to shape the technology and data risk posture across the Americas while aligning with EY’s global Information Security strategy.
This position requires navigating a complex landscape of business priorities, regulatory expectations, operating models and risk scenarios across the Americas. As the steward of the technology risk posture for the area, the role has a clear mandate to identify, evaluate and mitigate significant technology risks, while also leading the implementation of people, process and technical controls designed to prevent data exfiltration and strengthen control effectiveness.
The role is designed for a senior leader who can translate complex technical risk and control concepts into clear, business-friendly guidance; influence senior stakeholders across Area, Regional and Member Firm leadership; and ensure that risk mitigation strategies are practical, well sponsored and consistently executed. It offers the chance to make a meaningful strategic impact, improve resilience, strengthen trust with clients and regulators, and shape the future of risk management practices in one of the firm’s most important areas.
Your key responsibilities
Area technology and data risk leadership
+ Lead a strategic approach to identifying, evaluating and mitigating technology risks across the Americas area.
+ Serve as the steward of the organization’s technology risk posture across the area and ensure the most significant risks receive appropriate sponsorship, budget and support for effective remediation.
+ Lead the consistent implementation of people, process and technical controls designed to prevent data exfiltration across regions, service lines and business environments.
+ Validate that implementations adhere to global standards and policies while accommodating local regulatory and operational requirements.
Risk assessments, methodology and remediation strategy
+ Oversee the delivery of TARP service offerings and coordinate comprehensive risk assessments using TARP methodology.
+ Drive the identification, assessment and prioritization of technology and data risks, and develop risk management and mitigation strategies tailored to area needs.
+ Facilitate the smooth implementation of Information Security programs that involve Area, Regional and Member Firm Risk Management stakeholders.
+ Collaborate with business and technology stakeholders to understand technology dependencies, relevant threat scenarios and control gaps, and convert those insights into actionable remediation plans.
Stakeholder advisory, escalation and communication
+ Act as the primary liaison between Information Security and business stakeholders at all levels of the firm, explaining the purpose, design and benefits of technology risk and control initiatives in clear, business-friendly language.
+ Become the trusted advisor on technology risk topics for Area, Regional and Member Firm Risk Management leaders, Business Relationship Managers, IT leaders and other senior stakeholders.
+ Serve as the primary escalation point for technology risks and implementation challenges, coordinating with regional and global teams to resolve issues and maintain program alignment.
+ Use strong executive presentation and briefing skills to communicate strategy, progress, risk posture and required decisions to senior management, the program steer co and the Information Security Leadership Team.
Control enablement, education and continuous improvement
+ Drive stakeholder engagement through education, communication and collaboration to foster a culture of compliance, proactive risk management and adoption of controls.
+ Lead educational initiatives on technology risks, control expectations and external risk trends relevant to the Americas area.
+ Monitor progress and regularly report on risk status, mitigation efforts and program performance to senior leaders and governance forums.
+ Stay informed on emerging threats, technologies, methodologies, regulatory changes and business standards in order to continuously refine strategies, processes and policies.
Skills and attributes for success
+ Insight into the business advantages of good risk management and internal controls beyond compliance purposes.
+ Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment.
+ Skilled in executive-level presentations and briefings.
+ Demonstrated leadership, negotiation and collaboration skills, with the ability to influence both upward and downward across the organization.
+ Strategic mindset and the ability to connect technical risk, business priorities and control outcomes in a way that drives action.
To qualify for the role you must have
+ A minimum of 15 years’ experience in Technology Risk Management and/or a similar field within Information Security.
+ An advanced degree in Computer Science, Information Security or a related discipline, or equivalent work experience.
+ Proficiency in policy and control frameworks such as ISO and COBIT.
+ Strong English language skills, including excellent writing, presentation, interpersonal and communication capabilities.
+ A minimum of 10 years of experience managing senior or managerial staff in Governance, Risk and Compliance (GRC) or related areas.
Ideally, you’ll also have
+ One or more of the following or equivalent certifications: CRISC, CISSP, CISM, CISA, CIA, GIAC in a related area, CIPP, or CIPT.
+ A strong understanding of external risk trends and business standards, and a commitment to staying current on methodologies and external developments that EY should prepare for from a risk perspective.
+ A strong understanding of EY business and Service Line risk priorities.
What we look for
We seek an individual with a strategic mindset and expertise in technology risk management who can proactively identify, assess and mitigate risks while strengthening the organization’s resilience against an evolving threat landscape. The ideal candidate will bring strong leadership skills, the ability to collaborate across departments and geographies, and a clear commitment to maintaining compliance with industry standards and regulatory requirements.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with fu
To view full details and how to apply, please login or create a Job Seeker account