Job Summary
In a plan to strengthen and extend our footprint in EY Enterprise Technology we are looking for an experienced and authoritative Patching and Vulnerability Compliance Lead to own and drive patching compliance, vulnerability management and security posture reporting across EYs entire I&O; Platform Infrastructure estate. This is a senior cross-tower leadership role with accountability that spans every platform discipline - Windows, Linux, Storage, Hyperconverged Infrastructure (HCI), Backup, Network, Facilities and associated managed services.
The role sits at the intersection of infrastructure operations, cybersecurity and executive reporting, and is a key leadership position within EYs Infrastructure Operations Centre (IOC). The successful candidate will serve as the firms primary authority on infrastructure patching compliance, frontier AI risk response as it applies to infrastructure, and cross-tower SPI and SLA performance - providing the visibility, governance and operational leadership needed to maintain a secure, compliant and well-managed global infrastructure estate.
Your key responsibilities
The I&O; Platform Infrastructure Patching and Vulnerability Compliance Lead owns the end-to-end patching governance framework across all I&O; platform towers, ensuring that vulnerability remediation commitments are met, compliance positions are accurately reported and exceptions are managed through a rigorous, risk-based process. This professional serves as the single point of accountability for patching SLA performance across Windows, Linux, Storage, HCI, Backup, Network and Facilities infrastructure domains.
Operating as a lead member of the Infrastructure Operations Centre (IOC), this role drives the weekly, monthly and quarterly compliance reporting cycle, chairs cross-tower patching forums, manages escalations from security and audit stakeholders, and leads the firms response to frontier AI-related infrastructure risks - ensuring that emerging AI-driven threat vectors are assessed, prioritized and remediated within agreed timelines. The Lead partners with tower engineering leads, security operations, risk and compliance teams, and senior I&O; leadership to deliver a consistent,
transparent and defensible compliance posture.
Skills and attributes for success
- Broad knowledge of I&O; Platform Infrastructure technologies across all towers, including:
- Windows Server patching - WSUS, SCCM/MECM, Windows Update for Business
- Linux patching - Red Hat Satellite, Ansible, YUM/DNF, APT-based tooling
- Storage platform firmware and software lifecycle management
- Hyperconverged Infrastructure (HCI) patching - Azure Stack HCI, Nutanix, VMware
- Backup platform patching - Commvault, Veeam, Veritas or equivalent
- Network device patching - routers, switches, firewalls, load balancers
- Facilities and data center infrastructure - UPS, PDU, DCIM and environmental systems
- Strong vulnerability management lifecycle experience - from scan to remediation to compliance attestation (exclusionary).
- Deep experience with vulnerability scanning tooling - Qualys, Tenable Nessus, Rapid7, Microsoft Defender for Endpoint or equivalent (exclusionary).
- Experience leading patching governance forums and cross-tower compliance reviews.
- Strong understanding of frontier AI infrastructure risks and the ability to assess, prioritize and respond to AI-driven vulnerability and threat intelligence.
- Experience operating in and leading from within an Infrastructure Operations Centre (IOC) or equivalent 24x7 operations environment.
- Robust SPI and SLA management capability - ability to define, track, report and drive remediation of patching and compliance KPIs across multiple platform towers.
- Experience producing executive-level compliance dashboards and vulnerability posture reporting.
- Strong knowledge of security and compliance frameworks relevant to infrastructure patching:
- CIS Benchmarks
- NIST SP 800-40
- ISO 27001
- SOC 2
- CVSSv3/v4 scoring and prioritization
- Experience managing patching exceptions, risk acceptances and compensating control documentation.
- Ability to engage and influence tower engineering leads, security operations and senior leadership stakeholders.
- Experience working with ITSM platforms (ServiceNow or equivalent) for change management, patch scheduling and compliance tracking.
- Strong PowerShell or Python scripting capability for compliance reporting automation.
- Strong working knowledge of DevOps, Agile, Kanban, SCRUM and ITIL frameworks.
- Ability to work effectively across global engineering teams and time zones.
To qualify for the role, you must have experience with
- Cross-platform patching governance and compliance program leadership - 7+ years.
- Vulnerability management lifecycle - scan, triage, remediation, attestation - 7+ years.
- Windows Server patching at enterprise scale (WSUS, MECM, MDE) - 7+ years.
- Linux patching at enterprise scale (Satellite, Ansible, YUM/APT) - 5-7 years.
- HCI platform patching (Azure Stack HCI, Nutanix or VMware) - 3-5 years.
- Storage and backup platform firmware and software lifecycle management - 3-5 years.
- Network device patching governance across multi-vendor environments - 3-5 years.
- Vulnerability scanning tool administration (Qualys, Tenable, Rapid7 or equivalent) - 5-7 years.
- CVSSv3/v4 scoring, vulnerability prioritization and risk-based remediation planning.
- SPI and SLA reporting for patching compliance across multiple infrastructure towers.
- Executive compliance dashboard and posture reporting - monthly and quarterly cycles.
- Patching exception management - risk acceptance, compensating controls and audit evidence.
- Change management and patch scheduling through ServiceNow or equivalent ITSM.
- IOC or NOC leadership presence - cross-tower incident and compliance escalation management.
- Frontier AI risk assessment as applied.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Platform Infrastructure Patching and Vulnerability Compliance Lead (Kochi)
🏢 EY
📍 Kochi