Talent.com
Portfolio Compliance Enablement Leader
Portfolio Compliance Enablement LeaderEY • Warszawa, Województwo mazowieckie, Polska
Portfolio Compliance Enablement Leader

Portfolio Compliance Enablement Leader

EY • Warszawa, Województwo mazowieckie, Polska
30+ days ago
Job description

Location : Wrocław, Katowice

Hybrid model : 2 days office / 3 days remote

Let us introduce you the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY.

Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 1000 people who collaborate to support the business of EY by protecting EY and client information assets Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

Working closely with our service lines and functions and with our technologists across the world, the Portfolio Compliance Enablement function supports digitally enabled services that take advantage of emerging technologies in concert with EY's broad industry-specific experience and professional services knowledge. The Information Security Portfolio Compliance Enablement Leader leads our EY Portfolio business team to improve their risk posture through compliance enablement with Information Security policies. This lead will partner with requisite SL / Functional leaders and business stakeholders to reinforce policies, control ownership, and compliance responsibilities. They are responsible for and will maintain the overall technology compliance posture for the portfolio leveraging effective governance and oversight. In addition to requiring adequate information security controls, data protection, privacy and software development practices, this role is responsible for helping the organization understand and comply with all laws, rules and regulations governing the company's technology, including third parties and vendor dependencies.

The role involves comprehensive management of the Portfolio and service line of risk with the primary accountability of reducing that risk by engaging directly with key EY Leaders and ensures the company's technical systems and information assets are protected in accordance with compliance requirements by doing pro-active compliance management and compliance hunting. Furthermore, the role focuses end-to-end security compliance enablement and is responsible for identifying, evaluating and reporting on information security risks when technological systems and software are not meeting compliance requirements.

As a Portfolio Compliance Enablement Lead within EY's Global Information Security function, this individual will be a trusted compliance advisor to the organization and serve as a trusted advisor for security compliance. This role will directly engage in managing a team of Compliance Enablement specialists who will drive improvements to the overall risk posture of EY, provide compliance enablement guidance on projects and programs, lead projects aimed at reducing risk, provide insight on top risks impacting the security posture or our businesses, and help define mitigation strategies for strategic compliance risks. The role will directly consult on security vulnerabilities and translation of security compliance risks into business risk terminology for risk-based investment planning. This role is expected to notably enhance the Service Line's abilities to competently manage and reduce a range of security risks. In doing so, it will add value by protecting the company's reputation and stability and accelerate the effective and de-risked use of technology.

Furthermore, this role will closely collaborate with leaders within Information Security to implement the team's strategy, vision, and objectives.

Your Key Responsibilities

This position is a leading role in managing the compliance portfolio for all global, regional, and country-based assets and systems. As a compliance consultant dedicated to the EY Service Line and function, you will be both an individual contributor capable of supporting multiple projects and lead a team of compliance specialists focused on improving the risk posture of the Service Line or function. In other words, it is not just an oversight role, but one that requires detailed understanding of the Service Line, business drivers, key risks and issues, and can help strategize on risk reduction strategies based on analysis of compliance data and trends.

You will lead a team focusing on these pillars :

  • Risk Management and Reduction :  Take ownership of the Portfolio or Service Line of security risk and compliance, engaging directly with key EY leaders to reduce risks by providing insights on top risks impacting the security posture of the businesses. Engage in compliance and risk-based investment planning to mitigate these risks effectively.
  • Trend Identification and Remediation :  Identify security risk trends and themes that require a comprehensive approach to remediation. Lead and spearhead these efforts, ensuring that risks are mitigated in a timely and efficient manner.
  • Proactive Security Initiatives :  Proactively seeking out and identifying security risks, weaknesses, and potential vulnerabilities in systems and processes before they can be exploited and independently stand-up initiatives to address them. Improve compliance with security standards and policies though continuous improvement and innovation in security practices.
  • Governance, Risk, and Compliance (GRC) Management :  Manage the end-to-end workflow of security compliance of risk findings in our Governance, Risk, and Compliance (GRC) tool to ensure continuity and compliance with security policies, standards and regulations.

And focus on the following responsibilities :

  • Define compliance strategies and remediation recommendations that provide pragmatic security guidance that balance business benefit and risks.
  • Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or audits.
  • Translate technical vulnerabilities into business risk terminology for the business.
  • Maintain compliance framework assessment toolkits used in testing and validation procedures.
  • Be accountable for and lead assessments for technology infrastructure, applications and third-party dependencies, aligning to regulations, best practices and corporate governance.
  • Skills And Attributes For Success

    Significant working security experience and knowledge in the management of compliance with company security policies in the following areas :

  • Strong leadership and organizational skills
  • Strategic skills to assist with the development of a long-term vision for EY's risk management security framework & approach
  • Ability to appropriately balance firm security needs with business impact & benefit
  • Ability to facilitate compromise to incrementally advance security strategy and objectives
  • An overall understanding of the business objectives of EY with an ability to build relationships across EY
  • Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
  • Experience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromise
  • Execute top-down assessment of risk based on policy compliance data and risks
  • Experience conducting risk assessments, vulnerability assessments, vendor and third-party risk assessments and recommending risk remediation strategies
  • Looks for ways to continually improve our compliance with Information Security policies
  • Create, promote, and oversee enforcement protocols, enabling consistency across diverse internal stakeholders
  • Investigate any violations of policies and recommend corrective action.
  • Develop training materials and conduct training sessions to educate on policies and enforcement protocols
  • Develop metrics to evaluate the effectiveness of policy enforcement, and generate regular reports
  • Identify policy and enforcement gaps and propose improvements.
  • Projects advanced consultative skills to conduct effective questioning to break down complex issues into core elements, formulate appropriate ideas or planning and negotiate those ideas and plans clearly and concisely to advance a cooperative engagement by all levels of the organization including senior and / or executive management
  • Proficient understanding of business focus and processes and the ability to inject cybersecurity compliance into the business through teamwork and influence
  • Ability to maintain a high level of integrity, trustworthiness and confidence to represent the company and security leadership with the highest level of professionalism
  • Ability to remain credible with the team and external constituents through sustained industry knowledge
  • Proven project leadership with both legacy and emerging technologies to assess and manage business risk and enforce security controls
  • Wide-ranging knowledge in technical infrastructure and applications, from legacy through next generation
  • To qualify for the role, you must have

  • A minimum of 10 years' experience in the field of Cyber Security, Information Security, or related discipline
  • At least 5 years' experience in a leadership role managing a distributed team and workforce
  • Advanced degree in Cyber Security, Information Security, Computer Science or a related discipline; or equivalent work experience
  • One or more of the following or equivalent certifications : Certified Risk and Information Systems Control (CRISC), Certified Information Systems Security Processional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), Certified Internal Auditor (CIA), Global Information Assurance Certification (GIAC) in related area, CIPP, CIPT
  • Experience working with common information security standards, such as : ISO 27001 / 27002, NIST, PCI DSS, ITIL, COBIT
  • Demonstrated leadership experience and thorough understanding of various regulatory requirements and laws such as, but not limited to, PCI, SOX, HIPAA, HITRUST, GDPR and GLBA.
  • Experience in policy enforcement and security compliance, awareness and learning at a publicly traded company
  • Strong understanding of governance, risk, and compliance (GRC) frameworks and tools
  • Proven competence in communicating confidently and effectively with clients, vendors, and all levels of management
  • Experience in managing the communication of security findings and recommendations to IT project teams and management
  • Skilled in executive level presentations and briefings
  • Proven ability to identify and mitigate security risks proactively
  • Insight into the business advantages of good risk management and internal controls beyond compliance purposes
  • Demonstrated leadership, negotiation and collaboration skills, and ability to influence up and down
  • Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment
  • Demonstrated experience in managing end-to-end security compliance enablement projects
  • Extensive experience with security compliance regulations
  • Strong English language skills : excellent writing, presentation, interpersonal, and communication skills are required
  • Capable of working with diverse teams and promoting an enterprise-wide, collaborative security culture
  • Ability to work flexibly and adapt to changing environments
  • Ideally, you'll also have

  • Exceptional judgment, tact, and decision-making ability
  • Familiarity with local and regional regulatory requirements and how they impact IT policies
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change
  • Outstanding management, interpersonal, communication, organizational, and decision-making skills
  • Experience with RSA Archer and / or IBM Open Pages
  • An ability to utilize core risk and controls skills in a broad range of projects both in a traditional internal audit and in advisory projects aimed at assisting in the implementation of controls / improvements
  • What We Look For

    We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.

    What We Offer

    EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across ten locations – Argentina, China, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We'll introduce you to an ever-expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.

  • Continuous learning : You'll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you : We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership : We'll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture : You'll be embraced for who you are and empowered to use your voice to help others find theirs.
  • About EY

    EY | Building a better working world

    EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

    Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

    Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

    If you can demonstrate that you meet the criteria above, please contact us as soon as possible.

    The Exceptional EY Experience. It's Yours To Build.

    In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.

    Create a job alert for this search

    Portfolio Compliance Enablement Leader • Warszawa, Województwo mazowieckie, Polska

    Related jobs
    Platform Lead Portfolio Management

    Platform Lead Portfolio Management

    Merck Healthcare • Warszawa, Województwo mazowieckie, Polska
    Ready to explore, break barriers, and discover more? We know you've got big plans – so do we Our colleagues across the globe love innovating with science and technology to enrich people's lives wit...Show more
    Last updated: 30+ days ago • Promoted
    Analityk Ecommerce

    Analityk Ecommerce

    Wittchen S.A. • Palmiry (pow. nowodworski), mazowieckie, Polska
    Tworzenie i automatyzacja raportowania z oceną efektywności kanałów marketingowych pod kątem realizacji KPI.Analizowanie źródeł ruchu i zachowania użytkowników w sklepie, wyciąganie wniosków i reko...Show more
    Last updated: 30+ days ago • Promoted
    Portfolio Manager

    Portfolio Manager

    KPMG • Warszawa, Województwo mazowieckie, Polska
    We are currently seeking a CEE OneIT Portfolio Manager with a high standard of communication and excellent coordination and analytics skills. High attention to details and strong Project Management ...Show more
    Last updated: 1 day ago • Promoted
    CRM Operations & MarTech Enablement Lead @ Welltech

    CRM Operations & MarTech Enablement Lead @ Welltech

    Welltech • Warszawa, Poland
    Our mission? To improve the health of millions of people through intuitive nutrition trackers, powerful fitness solutions, and personalized wellness journeys—all powered by a diverse team of over ....Show more
    Last updated: 15 days ago • Promoted
    Specjalista ds. Realizacji Zamówień i Rozliczeń

    Specjalista ds. Realizacji Zamówień i Rozliczeń

    MAKRO Cash & Carry Polska S.A. • Moszna-Parcela (pow. pruszkowski), mazowieckie, Polska
    Realizacji Zamówień i Rozliczeń.Miejsce pracy : Moszna-Parcela (pow.Analiza informacji o statusie płatności klientów z udzielonym kredytem. Wystawianie faktur i korekt, rozliczanie utargów.Rozliczani...Show more
    Last updated: 5 hours ago • Promoted • New!
    EIB Trainee - Group Risk & Compliance Directorate - Counterparty Credit Risk Unit - based in Lu[...]

    EIB Trainee - Group Risk & Compliance Directorate - Counterparty Credit Risk Unit - based in Lu[...]

    European Investment Bank (EIB) • Warszawa, Województwo mazowieckie, Polska
    EIB Trainee – Group Risk & Compliance Directorate – Counterparty Credit Risk Unit – Luxembourg.Position is based at our Luxembourg headquarters and requires regular office presence.The EIB offers a...Show more
    Last updated: 6 days ago • Promoted
    Specjalista ds. cyberbezpieczeństwa (k / m)

    Specjalista ds. cyberbezpieczeństwa (k / m)

    Polskie Sieci Elektroenergetyczne S.A. • Konstancin-Jeziorna, mazowieckie, Polska
    IT- Operator SOC (Security Operations Center).Show more
    Last updated: 30+ days ago • Promoted
    Embedded Software Engineer

    Embedded Software Engineer

    Solaris Laser sp. z o. o. • Kajetany (pow. pruszkowski), Masovian, Poland
    Develop quality firmware for the new product line of the laser marking systems.Work within a Test-Driven Development(TDD) environment. Develop quality software using Object Oriented Design Methodolo...Show more
    Last updated: 21 days ago • Promoted
    Team Lead (Software Engineering) - Cash & Investments

    Team Lead (Software Engineering) - Cash & Investments

    EIS Ltd • Warszawa, Województwo mazowieckie, Polska
    Team Lead (Software Engineering) - Cash & Investments.Team Lead (Software Engineering) - Cash & Investments.EIS delivers a cloud-native, event-driven coretech platform that lets ambitious insurers ...Show more
    Last updated: 1 day ago • Promoted
    Credit Portfolio Officer - Vice President

    Credit Portfolio Officer - Vice President

    Citi • Województwo mazowieckie, Polska
    Are you looking for a career move that will put you at the heart of a global financial institution? Then bring your skills and experience in credit portfolio management to Citi’s Portfolio Credit R...Show more
    Last updated: 2 days ago • Promoted
    Manager, Portfolio Reporting

    Manager, Portfolio Reporting

    Moderna • Warszawa, Województwo mazowieckie, Polska
    Joining Moderna offers the unique opportunity to be part of a pioneering team that's revolutionizing medicine through mRNA technology, with a diverse pipeline of development programs across various...Show more
    Last updated: 30+ days ago • Promoted
    Team Lead (Software Engineering) - Cash & Investments

    Team Lead (Software Engineering) - Cash & Investments

    EIS Group • Warszawa, Województwo mazowieckie, Polska
    Team Lead (Software Engineering) - Cash & Investments.EIS delivers a cloud-native, event-driven coretech platform that lets ambitious insurers modernize at speed. The Cash & Investments team owns th...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Readiness Manager

    Cybersecurity Readiness Manager

    AkzoNobel • Warszawa, Województwo mazowieckie, Polska
    Select how often (in days) to receive an alert : .Cybersecurity Readiness Manager.Since 1792, we’ve been supplying the innovative paints and coatings that help to color people’s lives and protect wha...Show more
    Last updated: 30+ days ago • Promoted
    Senior Credit Risk Expert

    Senior Credit Risk Expert

    Worldline • Warszawa, Województwo mazowieckie, Polska
    Credit Risk Centre of Excellence within our global Credit Risk department, which consists of several globally spread teams with end-to-end credit risk management responsibility at merchant and port...Show more
    Last updated: 30+ days ago • Promoted
    Credit Risk Modeling Lead

    Credit Risk Modeling Lead

    Antal SSC / BPO • mazowieckie, mazowieckie, Polska
    Develop and enhance AIRB credit risk models.Work on IFRS9 and stress testing models (accepted but less preferred).Create new credit risk models (most desirable). Validate and monitor models (accepta...Show more
    Last updated: 7 hours ago • Promoted • New!
    Financial Crime Prevention Lead | SME Lending & Credit Fraud Risk

    Financial Crime Prevention Lead | SME Lending & Credit Fraud Risk

    Aion Bank (UniCredit Group) • Warszawa, Województwo mazowieckie, Polska
    Financial Crime Prevention Lead | SME Lending & Credit Fraud Risk.Financial Crime Prevention Lead | SME Lending & Credit Fraud Risk. Aion Bank is a fully regulated European bank and credit instituti...Show more
    Last updated: 30+ days ago • Promoted
    Portfolio Manager​ - CEE OneIT

    Portfolio Manager​ - CEE OneIT

    KPMG • Warszawa, Warszawa, Polska
    KPMG with a strong impact across the Central and Eastern Europe region.In an ever-changing market, we stay agile, collaborative, and focused on delivering real value. At KPMG, our people come first....Show more
    Last updated: 13 hours ago • Promoted • New!
    Cyber Platform Engineering Lead

    Cyber Platform Engineering Lead

    Standard Chartered • Województwo mazowieckie, Polska
    The Cyber Platform Engineering Lead will be a senior technical and strategic leader responsible for delivering the bank’s unified cyber and financial crime monitoring platform.Working under the Hea...Show more
    Last updated: 1 day ago • Promoted