Technical Specialist - Vulnerability Management
EY
IT
France · India · Israel · Kochi, Kerala, India · Germany · Uxbridge, UK
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
Technical Specialist, Vulnerability Management
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As a Technical Specialist on the Vulnerability Management team, you will play a significant individual contributor role to influence the creation of best-in-class industry relevant governance frameworks, working under the guidance of the Vulnerability Management Service Owner by providing technical guidance in the Vulnerability Management projects. Your responsibilities will include identifying improvement areas in existing methodology and capabilities to ensure that EY's security standards are upheld across all digital assets. Additionally, maintaining the security governance readiness for upcoming technology landscape will be a key responsibility.
Your Key Responsibilities
- Leverage preventive and offensive security skills to assess technology needs and methodologies for effective Vulnerability Management risk assessments across EY’s technology landscape.
- Manage the expansion of Vulnerability Management services in AI, Cloud, Application Security, and emerging business functions.
- Monitor vulnerability trends and emerging threats to proactively mitigate risks.
- Maintain and enhance vulnerability management tools, processes, and reporting mechanisms.
- Generate detailed vulnerability reports and dashboards for management and compliance purposes.
- Support incident response activities related to vulnerabilities and exploits.
- Ensure compliance with security policies, standards, and regulatory requirements.
- Collaborate across multiple functions to execute the Attack Surface Management strategy, protecting EY’s digital assets.
- Serve as the primary point of contact for Vulnerability Management projects related to technology, services, and transformation initiatives.
Skills and Attributes for Success
- Risk Analysis: Ability to assess and prioritize vulnerabilities based on risk impact and exploitability.
- Network and System Security: Strong understanding of network protocols, operating systems (Windows, Linux), firewalls, IDS/IPS, and endpoint security.
- Vulnerability Identification: Hands-on experience in analyzing and developing exploits to identify vulnerabilities in the environment.
- Analytical Thinking: Strong problem-solving skills to analyse complex security data and identify root causes.
- Attention to Detail: Meticulous in identifying vulnerabilities and ensuring accurate documentation.
- Proactive Mindset: Ability to anticipate potential security risks and take preventive measures.
- Communication Skills: Effective in communicating technical information to both technical and non-technical stakeholders.
- Collaboration: Works well with cross-functional teams including IT, security, and business units to drive remediation efforts.
- Adaptability: Comfortable working in a fast-paced, evolving security environment.
- Integrity and Confidentiality: Maintains high ethical standards and handles sensitive information responsibly.
- Continuous Learning: Commitment to staying updated with the latest security trends, tools, and best practices.
- To Qualify for the Role You Must Have
- Minimum 12 years of experience in vulnerability management, red team, or purple team roles.
- Knowledge of industry standards such as NIST, ISO 27001, CIS Controls, and vulnerability management frameworks.
- Hands-on experience deploying and governing information security controls in cloud services, network security, AI/ML, and data protection principles.
- Strong analytical and problem-solving skills with the ability to translate vulnerability information into business impact.
- Demonstrated experience developing detection controls and solutions for infrastructure and application security assessments.
- Strong communication, interpersonal, and influential stakeholder management skills.
- Ability to manage multiple priorities and lead cross-functional teams effectively.
Ideally, You’ll Also Have
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
- Proven leadership experience in a similar role.
- Strong operational, tactical planning, and organizational skills.
What We Look For
We seek an industry-relevant Vulnerability Management Technical Specialist who can influence and contribute to the technology transformation and process maturity of the Vulnerability Management function. The ideal candidate is an experienced cybersecurity technical leader focused on reducing the organization’s attack surface while enabling business objectives. This individual continuously adapts, improves others, and identifies innovative ways to strengthen the organization’s security posture.
What working at EY offers
As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:
- Continuous learning: You will develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way.
- Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.