At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Risk Consulting - Protect Tech – Associate Director (IT and Cyber Compliance)

The opportunity: your next adventure awaits.

Are you a tech-savvy professional with a risk mindset who is passionate about building a better working world through the power of people, technology, and innovation? We have an incredible opportunity for you to join our dynamic Protech Tech team and make a real impact in the rapidly evolving world we live in. Within Risk Consulting, you will focus in the areas of areas of IT Risk Management, IT SOX, IT Regulatory Compliance, IT Audits, IT and Digital Transformations (including ERP and Cloud transformations), while enabling technology to better manage risk. As a member of our team, you will have the chance to work with industry leaders and help transform businesses by tackling the most complex challenges with our clients.


This is client-facing role in a rapidly growing practice, where you’ll build client relationships with key stakeholders, including management executives for some of the most globally recognized brands. It makes this the perfect place to gain a deeper understanding of complex businesses transactions, all the while recommending solutions to some of the most pressing business challenges and process inefficiencies. You will also team up with our global professionals in multidisciplinary engagements, helping major global clients transform and sustain business performance. You will be leveraging emerging technologies like AI, ML, to build and enhance new solutions and actively work in building multiple tools and assets for efficient and effective client delivery. By plugging into our market-leading global network, you'll gain the experience you need to become an exceptional IT Risk Advisor
Your Key Roles and Responsibilities

Market Leadership and client management

  • Executive-level skills in client relationship management and the hold conversations with senior executives.
  • Partnering with onshore teams to understand client’s business & related industry issues / trends for global clients.
  • Contribute to new solution development basis the industry trends and client’s problem statement in the areas of IT Risk Management
  • Conduct knowledge sharing discussions & contribute to EY thought leadership.
  • Participate in go to market, create proposals and respond to RFPs, client orals etc. Identify opportunities for cross-selling to current clients/introduce colleagues from other service lines.
  • Identify buyers, influencers & stakeholders in existing client engagements and build strong relationships.
  • Identify opportunities for cross-selling to current clients/introduce colleagues from other service lines.
  • Assist Partners/Directors in driving the account management agenda by focusing on high impact opportunities.
  • Create innovative insights for clients, adapts methods & practices to fit operational team needs & contributes to thought leadership documents.

Delivery and Team management

  • Understanding our clients’ overall technology strategy to effectively manage risk while transforming their business.
  • Plan & schedule client engagements. Determine and deploy the right team with adequate skill sets for executing engagements and periodically review status of engagements and work products.
  • Lead large engagements in the areas of IT Risk Management, IT SOX, IT Regulatory Compliance, IT Audits
  • Actively contribute to improving operational efficiency on projects & internal initiatives by leveraging on lessons learned from other projects.
  • Monitor engagement economics & ensure timely billing of invoices & actively follow-up on collections by managers/seniors.
  • Manage a team of Managers and Seniors (across locations) to manage delivery of engagements for multiple processes across clients and conduct comprehensive risk assessments to identify and prioritize potential IT risks against technology strategies, business applications and platforms, and digital transformations.
  • Maintain a strong client focus by effectively serving client needs and developing productive working relationships with client personnel. Stay abreast of current business and economic developments and new pronouncements/standards relevant to the client's business.
  • Demonstrate subject matter & industry expertise (deep understanding of the industry, emerging trends, issues/challenges, key players & leading practices).
  • Stay up to date with emerging industry trends and technologies, suggest innovative solutions to engagement teams and provide recommendations to clients on potential risks and opportunities.

Operational Excellence

  • Suggest ideas on improving engagement productivity and identify opportunities for improving client service.
  • Manage engagement budgets and ensure compliance with engagement plans and internal quality & risk management procedures.

People related

  • Display teamwork, integrity and leadership. Work with team members to set goals and responsibilities for specific engagements. Foster teamwork and innovation.
  • Utilize technology & tools to continually learn and innovate, share knowledge with team members and enhance service delivery.
  • Understand EY and its service lines. Actively encourage team members to contribute ideas.
  • Conduct workshops and technical training sessions for team members. Contribute to the learning & development agenda and knowledge harnessing initiatives.

To qualify for the role, you must have

  • Chartered accountant (CA) or Master's degree in Management, Information Systems/ Technology, Computer Science, Business Analytics, Cybersecurity, or a related discipline
  • Passion for technology and an ardent desire to work in risk management.
  • Minimum 12 years of a “Big 4” or professional firm or professional industry experience in risks & controls, with more than 10 years of experience in IT Risk Management, IT & Cyber Compliance areas such as
    • Risk Assessment – Assessment of internal processes to identify security findings, vulnerabilities, and control gaps/deviations identified on applications and infrastructure. Develop risk control matrix in line with COBIT, ISO, NIST and ITIL Best Practice and recommendations.
    • Control Monitoring- Understanding of Cyber and compliance standards like PCI, ISO27001, perform test the design and operational effectiveness of the controls.
    • Control Automation – Identify controls automation opportunities through analytics platform to monitor the operational effectiveness on the regular basis.
    • Defect / Gap Identification: Identify the confidentiality, integrity and the availability related deficiencies in the client environment and evaluate against industry standards.
    • IT Risk and Controls assessment with exposure of any of the technologies such as SAP, Oracle, Workday, MS Dynamics or emerging technologies such as Cloud, RPA, AI/ML
    • Knowledge of IT risk, information security or cyber security frameworks such as COSO, COBIT, ISO, NIST etc.
  • Strong exposure working in client facing roles, collaborate with cross functional teams including internal audits, IT security and business stakeholders to assess control effectiveness and facilitate remediation activities.
  • Good to have relevant industry certifications such as CISA, CISM, CISSP, ISO 27001, and others (as relevant)
  • Cognitive problem-solving capabilities, quick decision-making skills and ability to handle complex situations with a calm demeanor
  • Exceptional interpersonal, written, and verbal communication skills
  • Effective organization and time management skills with the ability to work under pressure and adhere to project deadlines.
  • Globally mobile and flexible to travel to onsite locations.
  • Team player with strong interpersonal skills
  • Ability to think differently and innovate

Ideally, you’ll also have

  • Responsible for the performance and appraisal of direct reports, including training and developing necessary skill sets to enable them to grow in their careers.
  • Mentor and coach junior team members, enabling them to meet their performance goals and successfully grow their careers.


EY | Building a better working world


EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.


Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.


Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.


Risk Consulting-Protect Tech-Associate Director

今すぐ適用する
Back to search page