Ernst & Young

Global Lead Security Compliance & Enforcement - Director

Ernst & Young$212K — $443K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 12 years of experience in security compliance, technology risk, or GRC operations.
  • Demonstrated leadership experience in global and matrixed organizations.
  • Strong knowledge of compliance frameworks like ISO 27001/27002 and COBIT.
  • Ability to translate technical risks into business impact for executive audiences.
  • Proven track record in managing enforcement, escalation, and remediation processes.

Responsibilities

  • Define and implement the global Security Compliance strategy and multi-year roadmap.
  • Lead a distributed organization to address high-risk exposures and ensure business continuity.
  • Manage policy compliance and the Non-Compliance Consequence Framework.
  • Develop data-driven risk intelligence and assurance metrics for informed decision-making.
  • Establish governance for emerging technologies like AI and DataGuard.

Benefits

  • Comprehensive medical and dental coverage.
  • Flexible vacation policy allowing for personal circumstances.
  • Participation in pension and 401(k) plans.
  • Hybrid work model emphasizing team collaboration.
  • Support for physical, financial, and emotional well-being through designated time off.
Full Job Description
The opportunity

The Global Lead Security Compliance & Enforcement owns the strategy, operating model, and outcomes for the global Security Compliance function within Technology Assurance, Risk & Policy. The role transforms Security Compliance into a proactive, intelligence-driven, and enforcement-capable organization that reduces risk debt, sustains critical governance, risk, and compliance operations and provides defensible, audit-ready governance.

The Director creates clear global accountability for security compliance and converts fragmented or ambiguous risk situations into prioritized action. Using policy, compliance-posture data, risk appetite, escalation protocols, and executive decision forums, the role addresses situations in which ownership, remediation capacity, enforcement authority, or risk tolerance are unclear. This includes clearing persistent enforcement backlogs, sequencing scarce specialist capacity across concurrent initiatives, expanding control monitoring, resolving technology-lifecycle exposure, and establishing governance for frontier AI and DataGuard obligations.

Working with CTOs, Service Line Quality Leaders, Technology Risk & Compliance, Information Security leadership, risk and control owners, technology teams, and audit and governance stakeholders, the Director balances policy requirements with business impact, technology delivery, client confidence, and documented risk acceptance. The role sets the multi-year roadmap, leads a globally distributed organization, and provides senior leaders with decision-quality information on compliance posture, risk trends, enforcement, and remediation.

Key Responsibilities
  • Strategic Leadership
    • Define and execute the global Security Compliance strategy, target operating model, multi-year roadmap, priorities, performance measures, and resource plan in alignment with risk appetite and business objectives.
    • Lead and develop a globally distributed, capability-led organization that proactively addresses the highest-risk exposures while sustaining business-as-usual GRC operations and talent succession.
  • Compliance Governance & Enforcement
    • Own global policy compliance and the Non-Compliance Consequence Framework, including consistent enforcement, escalation, investigation, corrective action, backlog reduction, and documented risk acceptance.
  • Risk Intelligence & Remediation
    • Build data-driven risk intelligence and expand control monitoring and assurance through clear evidence, metrics, trends, dashboards, executive reporting, and risk burn-down tracking.
    • Direct remediation and technology-lifecycle governance, including out-of-SLA vulnerability triage, End-of-Life exposure, exceptions, and emerging AI and DataGuard obligations.
  • AI Governance & Emerging Technologies
    • Establish compliance governance, monitoring, accountability, and reporting for frontier AI, DataGuard, and other emerging-technology obligations.
  • Stakeholder & Executive Engagement
    • Partner with CTOs, Service Line Quality Leaders, risk, security, audit, governance, and technology teams to balance policy, business impact, client confidence, and delivery, while advancing automation and continuous improvement.


Supervision Responsibilities

The Director reports to the Global Leader, Technology Assurance, Risk & Policy within Information Security and leads the global Security Compliance function.

Knowledge and Skills Requirements
  • Deep knowledge of cyber security, technology and data risk, policy compliance, control assurance, GRC operations, enterprise remediation, exception governance, and risk acceptance.
  • Practical understanding of ISO 27001/27002, ISO 31000, COBIT, unified compliance frameworks, audit expectations, and enterprise control obligations.
  • Ability to translate technical exposure and compliance data into business risk, executive action, documented decisions, and measurable risk reduction.
  • Proven capability to design and lead global operating models, portfolio governance, monitoring, evidence, metrics, dashboards, executive reporting, and automation enablement.
  • Strong judgment in enforcement, escalation, corrective action, remediation prioritization, business continuity, and allocation of scarce specialist capacity in a matrixed organization.
  • Executive communication and stakeholder partnership skills across senior leaders, client-serving teams, technology delivery, risk and control owners, audit, and governance forums.


Job Requirements
  • Demonstrated ability to lead a global security compliance, technology risk, control assurance, or GRC function of comparable complexity and strategic scope.
  • Demonstrated experience resolving complex cross-functional issues through data, policy, risk appetite, escalation protocols, and executive decision forums.
  • Experience establishing priorities and measurable outcomes, managing a portfolio of concurrent initiatives, and allocating specialist capacity while continuous operations remain active.
  • Experience directing policy-compliance enforcement, non-compliance remediation, control monitoring, technology-lifecycle risk, exception governance, and risk-acceptance processes.
  • Ability to engage directly with executive technology, quality, risk, security, service-line, audit, and governance stakeholders and present compliance posture, trends, and remediation progress.
  • Ability to lead distributed teams, coach leaders and staff, align responsibilities and objectives to capability, and develop succession and talent strategies.


Education and Certification Requirements

A relevant educational background in cyber security, information security, technology risk, IT or data risk management, governance, compliance, or a related discipline is expected. Relevant professional certifications in information security, technology risk, governance, audit, or compliance are preferred, particularly credentials aligned with ISO 27001/27002, ISO 31000, COBIT, or unified compliance frameworks.

Experience Requirements

A minimum of 12 years of professional experience is required in complex, enterprise-scale security compliance, technology risk, policy, control assurance, GRC operations, or remediation environments. Candidates should demonstrate experience leading distributed teams and capability leaders, operating in a matrixed global organization, advising senior executives, transforming operating models, managing enforcement and escalation, expanding monitoring and assurance, and converting ambiguous cross-functional risks into prioritized remediation or documented risk acceptance.

What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
  • We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $212,400 to $443,900. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $254,900 to $504,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Global Lead Security Compliance & Enforcement - Director jobs: