At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Job Summary:
The DPS Compliance SME supports the Stay in Compliance Lead by managing compliance, risk and control activities for the organisation’s enterprise data protection services. The role covers Veeam Data Platform, Dell PowerProtect Data Domain, Infinidat InfiniGuard, Azure-based backup services, physical backup infrastructure, tape technologies and the associated Windows, Linux, virtualisation, network and SAN dependencies. The role helps maintain secure, supported and recoverable backup services through vulnerability management, patch and version currency, configuration assurance, immutable protection, encryption, capacity oversight, lifecycle management and recovery control validation.
Working with DPS Engineering, DPS Operations, Information Security, Service Management, infrastructure teams, application owners, managed-service providers and vendors, the role identifies and assesses alerts and vulnerabilities, supports risk-based prioritisation and remediation, monitors backup and recovery control performance, and produces traceable governance and audit reporting. The position provides product-specific subject-matter expertise and clear escalation to the Stay in Compliance Lead, without owning the broader infrastructure compliance programme.
Job Description
- Serve as the product-specific compliance SME for enterprise Data Protection Services, including Veeam Data Platform, Dell PowerProtect Data Domain, Infinidat InfiniGuard, Azure backup services, backup servers, repositories, appliances and tape infrastructure.
- Monitor backup application, appliance, operating-system, security and vendor alerts; identify vulnerabilities, unsupported versions, configuration weaknesses and compliance gaps affecting DPS platforms and dependencies.
- Assess technical impact, affected versions, exploitability, backup-window and restore dependencies, data criticality and business risk, and support risk-based prioritisation in line with agreed standards and SLAs.
- Coordinate remediation of DPS vulnerabilities, missing patches, unsupported software or firmware, insecure configurations and hardware lifecycle risks with Engineering, Operations, infrastructure teams and vendors.
- Maintain compliance visibility across Veeam backup servers, proxies, repositories, scale-out repositories, hardened repositories, cloud repositories, orchestration components and protected workloads.
- Maintain compliance visibility across Data Domain and InfiniGuard appliances, covering operating software, firmware, capacity, replication, deduplication, encryption, retention lock, immutable snapshots, access controls and support lifecycle.
- Validate the design and operation of immutability, encryption, off-site or isolated backup copies, role separation, privileged access and other ransomware-resilience controls.
- Review vendor security advisories, CVEs, release notes, known issues, compatibility matrices and prerequisites, and translate findings into clear remediation actions.
- Track remediation actions, ageing, exceptions, dependencies and closure evidence, escalating material risk, unsupported components or delivery delays to the Stay in Compliance Lead.
- Support patching, upgrade and maintenance activities by validating readiness, service safeguards, rollback plans, change evidence, controlled restart requirements and post-remediation compliance status.
- Monitor backup success, consecutive failures, restore-point availability, policy compliance, recovery testing, capacity, utilisation and inventory data to identify control failures and emerging operational risk.
- Maintain DPS compliance records covering asset inventory, software and firmware currency, support lifecycle, protection status, security findings, approved exceptions, ownership and control evidence.
- Analyse estate, backup, vulnerability, capacity and remediation data using Power BI, SQL, spreadsheets, scripts and APIs to produce dashboards, trend analysis, SLA metrics and management reporting.
- Prepare regular governance and compliance reports for the Stay in Compliance Lead, highlighting exposure, backup-control performance, remediation progress, lifecycle risk, exceptions and recovery readiness.
- Support internal and external audits, disaster-recovery exercises and restore tests by providing timely, complete and traceable evidence and coordinating remediation of observations.
- Identify opportunities to improve vulnerability assessment, patch planning, alert handling, inventory accuracy, evidence collection, reporting and control automation across DPS.
- Build effective working relationships across DPS Engineering, DPS Operations, Information Security, Service Management, infrastructure teams, application teams and vendors while operating within the governance direction set by the Stay in Compliance Lead.
Knowledge & Competencies Required:
- Advanced knowledge of enterprise backup and recovery operations, including policy design, scheduling, repositories, copy jobs, retention, restore validation, capacity planning, high availability and disaster recovery.
- Profound knowledge of Veeam Data Platform and its core backup, replication, repository, reporting and recovery capabilities in complex enterprise environments.
- Profound knowledge of Dell PowerProtect Data Domain and Infinidat InfiniGuard backup appliances, including capacity, deduplication, replication, performance, security, immutability and lifecycle considerations.
- Advanced knowledge of Azure and hybrid-cloud data protection, including Azure Backup, vaults, policy governance, encryption, immutable storage, access control, monitoring and recovery concepts.
- Profound knowledge of encryption, immutability, hardened repositories, retention lock, logical isolation, role separation and cyber-recovery controls.
- Advanced knowledge of tape libraries, tape drives, media handling, off-site retention and audit controls.
- Understanding of vulnerability management, security alert handling, risk assessment, remediation SLAs, patch currency, configuration compliance, inventory and product lifecycle controls.
- Ability to interpret vendor advisories, CVEs, severity scores, release notes, compatibility matrices and scan findings and translate them into prioritised technical actions.
- Working knowledge of backup infrastructure dependencies including Windows and Linux servers, virtualisation platforms, databases, networks, SAN, storage and identity services.
- Proficiency with Power BI, SQL, spreadsheets, scripting languages and APIs for estate analysis, control automation, remediation tracking and compliance reporting.
- Awareness of AI-enabled monitoring, anomaly detection and automation opportunities in data protection, with the ability to apply appropriate security and governance controls.
- Strong analytical and problem-solving skills, with attention to data accuracy, evidence quality, service recoverability and control traceability.
- Experience improving backup compliance processes through standardisation, automation and measurable controls.
- Clear written and verbal communication skills, with the ability to explain data-protection risk, control performance and remediation status to technical and non-technical stakeholders.
- Ability to work independently as an SME, coordinate across geographically dispersed and multicultural teams, manage priorities and escalate appropriately within established governance.
Job Requirements:
Education:
- Bachelor’s degree in Computer Science, Information Technology, Engineering or a related technical discipline, or equivalent relevant experience.
Experience:
Five to seven years of experience in infrastructure engineering or information technology, including three to five years supporting enterprise data protection technologies. Demonstrated involvement in vulnerability remediation, patch and upgrade coordination, backup and recovery controls, cyber resilience, capacity or lifecycle management, compliance reporting or audit support is required.
Certification Requirements:
Veeam certifications are advantageous. Microsoft Azure, Dell Technologies, Infinidat, information security, ITIL, Power BI, automation or AI-related certifications are also beneficial but not mandatory.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.