At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Job Title: Windows & Linux Compliance SME
Job Summary:
The MSFT Windows Compliance SME supports the Stay in Compliance Lead by managing compliance, risk and control activities across the global on-premises Windows Server estate. The role provides deep technical expertise for Microsoft Windows Server 2019, 2022 and 2025, Active Directory, Group Policy, Microsoft Configuration Manager, PowerShell Desired State Configuration, server hardware, virtualisation and associated hybrid-cloud management capabilities. The role helps maintain a secure, supported and consistently configured estate through vulnerability remediation, security hardening, patch and version currency, configuration baselines, identity and access controls, automation, hardware lifecycle management and audit assurance.
Working with On-Prem Hosting Engineering and Operations, Information Security, Active Directory, Service Management, hardware, virtualisation, cloud and application teams, the role assesses security findings and configuration drift, engineers and coordinates large-scale remediation, and produces traceable governance and audit reporting. The position provides Windows-specific subject-matter expertise and clear escalation to the Stay in Compliance Lead, while coordinating cross-platform dependencies where Windows services interact with Linux, Azure, AWS, VMware, Nutanix AHV or Hyper-V environments.
Job Description
- Serve as the compliance SME for the global on-premises Microsoft Windows Server estate, supporting environments at enterprise scale, including estates exceeding 10,000 servers.
- Monitor Microsoft security advisories, vulnerability findings, operating-system alerts, configuration data and vendor notifications to identify exposure affecting Windows Server 2019, 2022 and 2025.
- Assess technical impact, affected versions, exploitability, business criticality, service dependencies and compensating controls, and support risk-based prioritisation in line with agreed standards and remediation SLAs.
- Engineer, package, test and coordinate large-scale remediation for security vulnerabilities, configuration changes and software updates using Microsoft Configuration Manager, PowerShell, Desired State Configuration and Ansible.
- Design, implement and maintain Group Policy Objects and verify consistent application across relevant Active Directory forests and domains.
- Create and maintain security configuration items, baselines, compliance rules and automated corrective controls using PowerShell DSC and approved enterprise tooling.
- Plan and schedule deployment waves for patches, security configurations, GPO changes, software packages, firmware and drivers, balancing remediation urgency with production stability.
- Maintain compliance visibility across physical and virtual Windows servers hosted on VMware ESXi, Nutanix AHV and Hyper-V, including hardware, firmware, drivers, operating-system versions and support lifecycle.
- Support secure account and access management for Windows servers, including privileged access, service accounts, local administrator controls, authentication policy and role separation.
- Perform security and performance analysis and recommend hardening, tuning and configuration changes for mission-critical production systems in data-centre environments.
- Support hybrid management of on-premises servers through Microsoft Azure capabilities, including Azure Arc-enabled servers, Azure Policy, machine configuration, monitoring and update-management concepts where adopted.
- Coordinate cross-platform remediation dependencies with Linux teams using Red Hat Satellite and Ansible Automation Platform when shared services, automation or controls span Windows and Linux environments.
- Prepare implementation plans, technical procedures, validation steps, rollback plans, change records and stakeholder communications for compliance deployments.
- Track remediation actions, ageing, exceptions, deployment failures, dependencies and closure evidence, escalating material risk or delivery delays to the Stay in Compliance Lead.
- Maintain accurate compliance records covering server inventory, patch and configuration status, GPO application, software and firmware currency, lifecycle, vulnerabilities, ownership, approved exceptions and evidence.
- Use ServiceNow, Microsoft Configuration Manager, Power BI, Dell OpenManage Enterprise, monitoring platforms, SharePoint, scripts and APIs to analyse compliance, automate recurring tasks and produce dashboards and reports.
- Support internal and external audits by providing timely, complete and traceable Windows Server configuration, access, patching, lifecycle and remediation evidence.
- Identify opportunities to standardise and automate vulnerability assessment, packaging, deployment, compliance validation, evidence collection and reporting using DevOps and infrastructure-as-code practices.
- Build effective working relationships across Engineering, Operations, Information Security, Service Management, Active Directory, Linux, cloud, virtualisation, hardware and application teams while operating within the governance direction set by the Stay in Compliance Lead.
Knowledge & Competencies Required:
- Advanced hands-on administration and compliance experience with Microsoft Windows Server 2019, 2022 and 2025 in large, globally distributed production environments.
- Expert knowledge of Active Directory, Group Policy design and management, domain and forest structures, authentication, service accounts and privileged-access controls.
- Proven experience assessing security risk, remediating Windows Server vulnerabilities, applying security baselines and tuning systems securely without compromising service availability.
- Deep scripting and automation capability in PowerShell, WMI and Python; experience with Ansible is required, while VBS and Perl knowledge is beneficial for legacy environments.
- Strong experience administering Microsoft Configuration Manager and packaging and deploying software, scripts, updates and remediation controls at enterprise scale.
- Experience creating configuration items, security baselines and desired-state controls using PowerShell DSC or equivalent configuration-as-code capabilities.
- Ability to interpret Microsoft security advisories, CVEs, severity scores, vulnerability scan findings, support lifecycle information and technical prerequisites and translate them into deployment actions.
- Strong knowledge of Windows Server hardware management, firmware and driver currency, remote management and lifecycle controls; Dell OpenManage Enterprise experience is advantageous.
- Good knowledge of VMware ESXi, Nutanix AHV and Hyper-V virtualisation and the operational dependencies between guest operating systems and hosting platforms.
- Working knowledge of Microsoft Azure and hybrid-cloud management, including Azure Arc-enabled servers, Azure Policy, machine configuration, monitoring and update-management concepts; AWS familiarity is beneficial.
- Working knowledge of Linux security and administration, Red Hat Satellite and Ansible Automation Platform sufficient to coordinate shared compliance and automation dependencies.
- Experience with ServiceNow, Power BI, SharePoint, monitoring and systems-management platforms for remediation tracking, data analysis, dashboarding and audit reporting.
- Strong working knowledge of ITIL, Agile, Kanban, Scrum and DevOps practices, particularly Change, Incident, Problem, Risk and Release Management.
- Ability to create clear technical documentation, procedures, implementation plans, rollback instructions, validation evidence and management reporting.
- Strong analytical and problem-solving skills with a disciplined approach to risk, data quality, control traceability and production stability.
- Clear communication, stakeholder coordination and influencing skills, with the ability to work independently and effectively across global, geographically dispersed teams.
Job Requirements:
Education:
Bachelor’s degree in Computer Science, Information Technology, Engineering or a related technical discipline, or equivalent relevant experience.
Experience:
Seven to eight years of relevant experience in enterprise Windows Server engineering, systems administration, infrastructure security or compliance, including substantial hands-on experience with Active Directory and GPO, Microsoft Configuration Manager, PowerShell automation, vulnerability remediation, configuration management, hardware lifecycle and mission-critical data-centre systems. Experience operating at large scale and coordinating complex global deployments is required.
Certification Requirements:
ITIL Foundation certification is required. Current Microsoft Windows Server, Azure Administrator, Azure Fundamentals or Microsoft security certifications are preferred. Red Hat, Linux Foundation, Ansible, VMware, Nutanix or CISSP certifications are beneficial. Legacy MCSA or MCSE Windows Server certification will be recognised where held.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.