Cyber SDC - Operational Technology - Manager
About the role
At EY, you'll have the opportunity to work alongside respected industry professionals, learning about and applying leading practices to better manage cybersecurity people, process, and technology capabilities. You will gain insights into the design and operations of cybersecurity programs and strategies in a variety of industries and learn how to design measurable, sustainable programs to keep up with the ever-changing cybersecurity landscape.
Responsibilities
- Work with a National practice, often including global team members, to assess cybersecurity programs and strategies using our proprietary framework.
- Design solutions to remediate gaps or enhance maturity of specific cybersecurity capabilities.
- Improve cybersecurity measurements and monitoring.
- Develop sustainable processes.
- Apply risk management principles to a cybersecurity environment.
- Leverage cybersecurity frameworks / standards like ISO/IEC 27001:2013, NIST CSF, NIST 800-53, etc.
Requirements
- A bachelor's degree in a related field and approximately 5 years of related work experience; or a graduate degree and approximately 4 years of related work experience.
- Experience in one or more of the following areas: Cybersecurity assessments, IT and cybersecurity policies, standards, procedures and controls, Security strategies and roadmaps, Cybersecurity awareness and training, Cybersecurity metrics and reporting, Cybersecurity organization design and implementation.
- A strong background of the security frameworks and standards such as ISO 27001/2, PCI DSS, NIST 800-53 and the cybersecurity laws and regulations such as HIPAA, FISMA and GLBA.
- A willingness to travel to meet client needs; travel estimated at 40-60%; a valid driver’s license in the US.
Skills and attributes for success
- Knowledge of the current security environment and industry trends to identify engagement and client service issues, communicate this information to the engagement team and client management through written correspondence and verbal presentations.
- Work closely with executives (senior managers and partners) to co-lead, motivate teams and provide leadership in client engagements.
- Foster relationships with client personnel to analyze, evaluate, and enhance information systems to develop and improve security at procedural and governance levels.
- Deliver quality client services. Drive high-quality work products within expected timeframes and on budget.
Qualifications
- A bachelor's degree in a related field and approximately 5 years of related work experience; or a graduate degree and approximately 4 years of related work experience.
- Experience in one or more of the following areas: Cybersecurity assessments, IT and cybersecurity policies, standards, procedures and controls, Security strategies and roadmaps, Cybersecurity awareness and training, Cybersecurity metrics and reporting, Cybersecurity organization design and implementation.
- A strong background of the security frameworks and standards such as ISO 27001/2, PCI DSS, NIST 800-53 and the cybersecurity laws and regulations such as HIPAA, FISMA and GLBA.
- A willingness to travel to meet client needs; travel estimated at 40-60%; a valid driver’s license in the US.
Benefits
- Comprehensive compensation and benefits package including medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Flexible vacation policy allowing you to decide how much vacation time you need based on your own personal circumstances.
- Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Pay
The base salary range for this job in all geographic locations in the US is $144,900 to $265,800. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $173,900 to $302,100. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography.
Schedule
Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.