Stay In Compliance Lead - DWES (Kochi)

Stay In Compliance Lead - DWES (Kochi)

19 Sep
|
EY
|
Kochi

19 Sep

EY

Kochi

Job Title

Stay in Compliance Lead - DWES

Job Summary

The Stay In Compliance Lead within Digital Workplace & Experience Services (DWES) is responsible for defining, governing, and driving the digital workplace compliance strategy to ensure endpoints, collaboration platforms, and Microsoft 365 services remain current, secure, and aligned with supported hardware and software standards. The role is responsible for maintaining the software and hardware currency of the digital workplace estate across Windows and macOS endpoints, mobile devices, virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and related M365 platforms by leading regular software upgrades, security patching, hardware refresh governance, and configuration remediation activities.

Responsibilities

- Own and lead the Digital Workplace & Experience Services (DWES) vulnerability management program, ensuring identification, assessment, prioritisation, remediation, and reporting of security vulnerabilities across the entire DWES product portfolio.
- Develop and maintain a comprehensive vulnerability remediation and risk management roadmap, leveraging data-driven insights, analytics, and risk-based prioritisation to reduce overall security exposure.
- Establish and execute Global Vulnerability Management compliance plans across Windows and macOS endpoints, mobile devices, virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and associated Microsoft 365 platforms.
- Drive end-to-end remediation governance for critical, high, and medium-risk vulnerabilities, ensuring timely closure or approved risk exceptions in accordance with business and security requirements.
- Maintain accountability for compliance against remediation SLAs and security standards established by Information Security, tracking progress, ageing, and compliance performance across the DWES estate.
- Partner with Information Security, Product Owners, Endpoint Management, Collaboration & Platforms, Ops & Engineering, Service Management, OSTS, BRMs, and other stakeholders to ensure effective execution of security remediation activities.
- Define, implement, and continuously enhance policies, standards, processes, and procedures governing vulnerability management, software currency, hardware lifecycle compliance, and security remediation activities.
- Establish and maintain a robust controls framework that ensures effective governance, auditability, compliance monitoring,



and risk management across DWES services.
- Collaborate closely with Information Security and Enterprise Technology stakeholders to lead DWES participation in Critical Vulnerability Response Plan (CVRP) exercises and enterprise-wide cyber response activities.
- Continuously monitor OEM advisories, MSRC and vulnerability intelligence feeds, security bulletins, and threat intelligence platforms to identify risks impacting DWES infrastructure and services.
- Partner with vendors and OEMs to assess the impact of emerging security threats, recommended mitigations, software defects, and lifecycle-related risks.
- Drive execution of critical security patching, emergency remediation activities, and infrastructure upgrades to reduce organisational risk exposure.
- Act as the primary DWES representative within the Intelligent Operations Center (IOC) for security vulnerability management, remediation coordination, and risk response activities.
- Review, challenge, and validate risk exception requests, ensuring technical justification, compensating controls, and business impact assessments are appropriately documented before approval.
- Provide technical guidance and risk advisory support to leadership teams, product owners, and business stakeholders regarding vulnerability remediation strategies and compliance obligations.
- Develop, maintain, and publish executive dashboards, scorecards, and management reports covering vulnerability exposure, remediation progress, security compliance, software currency, hardware currency, and risk posture across DWES.
- Define and monitor key performance indicators (KPIs), risk indicators (KRIs), remediation targets, and compliance metrics to measure programme effectiveness.
- Drive automation and continuous process improvement initiatives across vulnerability assessment, remediation tracking, software upgrades, patch management, compliance reporting, and IOC operational activities.
- Partner with Service Management teams to ensure all security remediation activities adhere to established governance, change management, ITSM,



and operational compliance requirements.
- Own stakeholder communications related to security vulnerabilities, remediation plans, compliance risks, maintenance activities, and risk mitigation strategies.
- Lead incident-related vulnerability remediation activities, ensuring effective coordination across technical teams and timely communication to stakeholders.
- Lead and manage the DWES Stay In Compliance team, ensuring clear accountability, ownership, and execution of vulnerability management and remediation activities.

Knowledge & Competencies Required

- Deep understanding of digital workplace technologies including Windows and macOS endpoint management, mobile device management (Intune), virtual solutions, Exchange, SharePoint, OneDrive, Teams, Power Platform, and Microsoft 365 security platforms.
- Strong expertise in vulnerability management, digital workplace security compliance, patch management, and endpoint/platform lifecycle governance.
- Experience working with OEM security advisory tools and vulnerability management platforms such as Microsoft MSRC, Microsoft Defender for Endpoint, Microsoft Intune, SCCM, ServiceNow Vulnerability Response, Tenable, Qualys, or similar technologies.
- Solid knowledge of security frameworks, risk management methodologies, and endpoint and platform hardening principles.
- Proven experience managing software upgrades, OS and application lifecycle programs, and security remediation initiatives.
- Strong analytical skills with the ability to assess business risk, prioritize remediation activities, and drive measurable outcomes.
- Experience developing compliance dashboards, executive reporting, and operational metrics.
- Strong stakeholder management skills with the ability to influence and coordinate across technology, security, vendor, and business teams.
- Knowledge of infrastructure lifecycle management, EOL/EOS governance, and technology refresh planning.
- Experience leveraging automation and AI-driven capabilities to enhance compliance monitoring and remediation processes.
- Strong communication and presentation skills with the ability to explain technical risks to both technical and non-technical audiences.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Stay In Compliance Lead - DWES (Kochi)
🏢 EY
📍 Kochi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: stay in compliance lead - dwes (kochi) / kochi