Associate Director- Global Assurance Audit Technologies
EY · Alpharetta, GA · 5 days ago
On-siteBusiness Development$153k–$294k/yrFull-time
About the role
The role involves designing and implementing security architecture to address business requirements. It includes overseeing complex programs or solutions addressing EY's internal and client-facing technology solutions. The Program Manager acts as an intermediary between the business and technical communities, ensuring alignment on security needs.
Responsibilities
- Define and design the security architecture of new and existing systems
- Perform top-down risk assessment activities related to deployments, upgrades, configuration upgrades, and analysis of technologies introduced for supporting technical operations
- Lead and advise teams delivering complex programs or solutions addressing EY business requirements at various levels
- Act as an intermediary between the business and technical community to understand business requirements, define the security architecture, and support development and engineering teams with end-to-end management
- Facilitate compromise to incrementally advance security strategy and objectives
- Translate technical vulnerabilities into business risk terminology for business units and recommend corrective actions to customers and project stakeholders
Requirements
- Application architecture and application security principles and practices
- Define security architectures and provide pragmatic security guidance that balance business benefit and risks
- Evaluate and prescribe security controls at all touchpoints throughout the technology architecture
- Maintain and enhance the Information Security risk assessment methodology
- Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or audits
- Translate technical vulnerabilities into business risk terminology for business units and recommend corrective actions to customers and project stakeholders
Skills
- Cloud technologies (MS Azure specifically)
- Strategic skills to drive secure technology architectures and software solutions, identify security risks and prescribe mitigating security measures in accordance with the firm’s risk tolerance level
- Experience with security architecture, design and assessment of accounting and auditing systems
- Ability to appropriately balance firm security needs with business impact & benefit
- Ability to facilitate compromise to incrementally advance security strategy and objectives
- An overall understanding of the business objectives of EY with an ability to build relationships with business partners and across EY IT
- Experience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromise
- Experience conducting risk assessments, vulnerability assessments, vendor and third-party risk assessments and recommending risk remediation strategies
- Experience working with common security tools and methods to identify security exposures and business risks
- Experience working with common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, COBIT
Qualifications
- Education: Advanced degree in Computer Science or a related discipline, or equivalent work experience
- Experience: Eight (8) or more years of experience in security architecture, application security, networking, data center configuration, cloud technology, Prior experience managing Information Security programsFive (5) years or more experience in an Information Security or Information Technology disciplineExperience in MS Azure Cloud and security related configurations and optionsExperience working with complex projects with global deploymentsFamiliarity with information system attack methods and vulnerabilitiesExcellent ability to analyze and translate business cases, product roadmaps and program goals into information security strategies Experience in the Agile development lifecycle Experience in managing the communication of security findings and recommendations to IT project teams and product owners