NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Compliance Officer in India
4 days ago
Apply with autofill
Apply with autofill
EY·4 days ago
4 days ago

Kochi Platform Infrastructure Patching and Vulnerability Compliance Lead KL 682303

Kochi, IndiaSenior · 6-10 yearsCompliance Officer

Sign up free to see how well your resume matches this role.

Boost your chances at EY

How you compare FREE

?
Your scoreYour score: not yet known
→
66
Top 10%Top 10%: 66 out of 100

Top 10% of NextRaise users matched against Compliance Officer roles in India.

Must-have skills for this role

  • windows server
  • linux
  • qualys
  • tenable nessus

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Owns the end-to-end patching governance framework across all I&O platform towers, ensuring that vulnerability remediation commitments are met, compliance positions are accurately reported and exceptions are managed through a rigorous, risk-based process.
  • Serves as the single point of accountability for patching SLA performance across Windows, Linux, Storage, HCI, Backup, Network and Facilities infrastructure domains.
  • Drives the weekly, monthly and quarterly compliance reporting cycle, chairs cross-tower patching forums, manages escalations from security and audit stakeholders, and leads the firm's response to frontier AI-related infrastructure risks.
  • Partners with tower engineering leads, security operations, risk and compliance teams, and senior I&O leadership to deliver a consistent, transparent and defensible compliance posture.

What they're looking for

  • Cross-platform patching governance and compliance program leadership — 7+ years.
  • Vulnerability management lifecycle — scan, triage, remediation, attestation — 7+ years.
  • Windows Server patching at enterprise scale (WSUS, MECM, MDE) — 7+ years.
  • Linux patching at enterprise scale (Satellite, Ansible, YUM/APT) — 5–7 years.
  • HCI platform patching (Azure Stack HCI, Nutanix or VMware) — 3–5 years.
  • Storage and backup platform firmware and software lifecycle management — 3–5 years.
  • Network device patching governance across multi-vendor environments — 3–5 years.
  • Vulnerability scanning tool administration (Qualys, Tenable, Rapid7 or equivalent) — 5–7 years.
  • CVSSv3/v4 scoring, vulnerability prioritization and risk-based remediation planning.
  • SPI and SLA reporting for patching compliance across multiple infrastructure towers.
  • Executive compliance dashboard and posture reporting — monthly and quarterly cycles.
  • Patching exception management — risk acceptance, compensating controls and audit evidence.

Nice to have

  • Frontier AI risk assessment as applied to infrastructure security posture (preferred).
  • Security framework alignment — CIS, NIST, ISO 27001, SOC 2 (preferred).
  • ITIL v4 Foundation certification (exclusionary).
  • Certified Information Systems Security Professional (CISSP) or equivalent (desired).
  • CompTIA Security+ or equivalent baseline security certification (desired).
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (better to have).
  • Qualys Certified Specialist or Tenable Certified Security Engineer (better to have).
  • Experience with Microsoft Defender Vulnerability Management at enterprise scale.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Job Description

I&O Platform Infrastructure Patching & Vulnerability Compliance Lead

 

The opportunity

In a plan to strengthen and extend our footprint in EY Enterprise Technology we are looking for an experienced and authoritative Patching and Vulnerability Compliance Lead to own and drive patching compliance, vulnerability management and security posture reporting across EY's entire I&O Platform Infrastructure estate. This is a senior cross-tower leadership role with accountability that spans every platform discipline — Windows, Linux, Storage, Hyperconverged Infrastructure (HCI), Backup, Network, Facilities and associated managed services.

 

The role sits at the intersection of infrastructure operations, cybersecurity and executive reporting, and is a key leadership position within EY's Infrastructure Operations Centre (IOC). The successful candidate will serve as the firm's primary authority on infrastructure patching compliance, frontier AI risk response as it applies to infrastructure, and cross-tower SPI and SLA performance — providing the visibility, governance and operational leadership needed to maintain a secure, compliant and well-managed global infrastructure estate.

 

Your key responsibilities

The I&O Platform Infrastructure Patching and Vulnerability Compliance Lead owns the end-to-end patching governance framework across all I&O platform towers, ensuring that vulnerability remediation commitments are met, compliance positions are accurately reported and exceptions are managed through a rigorous, risk-based process. This professional serves as the single point of accountability for patching SLA performance across Windows, Linux, Storage, HCI, Backup, Network and Facilities infrastructure domains.

 

Operating as a lead member of the Infrastructure Operations Centre (IOC), this role drives the weekly, monthly and quarterly compliance reporting cycle, chairs cross-tower patching forums, manages escalations from security and audit stakeholders, and leads the firm's response to frontier AI-related infrastructure risks — ensuring that emerging AI-driven threat vectors are assessed, prioritized and remediated within agreed timelines. The Lead partners with tower engineering leads, security operations, risk and compliance teams, and senior I&O leadership to deliver a consistent, transparent and defensible compliance posture.

 

Skills and attributes for success

  • Broad knowledge of I&O Platform Infrastructure technologies across all towers, including:
    • Windows Server patching — WSUS, SCCM/MECM, Windows Update for Business
    • Linux patching — Red Hat Satellite, Ansible, YUM/DNF, APT-based tooling
    • Storage platform firmware and software lifecycle management
    • Hyperconverged Infrastructure (HCI) patching — Azure Stack HCI, Nutanix, VMware
    • Backup platform patching — Commvault, Veeam, Veritas or equivalent
    • Network device patching — routers, switches, firewalls, load balancers
    • Facilities and data center infrastructure — UPS, PDU, DCIM and environmental systems
  • Strong vulnerability management lifecycle experience — from scan to remediation to compliance attestation (exclusionary).
  • Deep experience with vulnerability scanning tooling — Qualys, Tenable Nessus, Rapid7, Microsoft Defender for Endpoint or equivalent (exclusionary).
  • Experience leading patching governance forums and cross-tower compliance reviews.
  • Strong understanding of frontier AI infrastructure risks and the ability to assess, prioritize and respond to AI-driven vulnerability and threat intelligence.
  • Experience operating in and leading from within an Infrastructure Operations Centre (IOC) or equivalent 24x7 operations environment.
  • Strong SPI and SLA management capability — ability to define, track, report and drive remediation of patching and compliance KPIs across multiple platform towers.
  • Experience producing executive-level compliance dashboards and vulnerability posture reporting.
  • Strong knowledge of security and compliance frameworks relevant to infrastructure patching:
    • CIS Benchmarks
    • NIST SP 800-40
    • ISO 27001
    • SOC 2
    • CVSSv3/v4 scoring and prioritization
  • Experience managing patching exceptions, risk acceptances and compensating control documentation.
  • Ability to engage and influence tower engineering leads, security operations and senior leadership stakeholders.
  • Experience working with ITSM platforms (ServiceNow or equivalent) for change management, patch scheduling and compliance tracking.
  • Strong PowerShell or Python scripting capability for compliance reporting automation.
  • Strong working knowledge of DevOps, Agile, Kanban, SCRUM and ITIL frameworks.
  • Ability to work effectively across global engineering teams and time zones.

 

To qualify for the role, you must have experience with

  • Cross-platform patching governance and compliance program leadership — 7+ years.
  • Vulnerability management lifecycle — scan, triage, remediation, attestation — 7+ years.
  • Windows Server patching at enterprise scale (WSUS, MECM, MDE) — 7+ years.
  • Linux patching at enterprise scale (Satellite, Ansible, YUM/APT) — 5–7 years.
  • HCI platform patching (Azure Stack HCI, Nutanix or VMware) — 3–5 years.
  • Storage and backup platform firmware and software lifecycle management — 3–5 years.
  • Network device patching governance across multi-vendor environments — 3–5 years.
  • Vulnerability scanning tool administration (Qualys, Tenable, Rapid7 or equivalent) — 5–7 years.
  • CVSSv3/v4 scoring, vulnerability prioritization and risk-based remediation planning.
  • SPI and SLA reporting for patching compliance across multiple infrastructure towers.
  • Executive compliance dashboard and posture reporting — monthly and quarterly cycles.
  • Patching exception management — risk acceptance, compensating controls and audit evidence.
  • Change management and patch scheduling through ServiceNow or equivalent ITSM.
  • IOC or NOC leadership presence — cross-tower incident and compliance escalation management.
  • Frontier AI risk assessment as applied to infrastructure security posture (preferred).
  • Security framework alignment — CIS, NIST, ISO 27001, SOC 2 (preferred).
  • PowerShell or Python automation for compliance reporting pipelines — 3–5 years.

 

Ideally, you'll also have

  • ITIL v4 Foundation certification (exclusionary).
  • Certified Information Systems Security Professional (CISSP) or equivalent (desired).
  • CompTIA Security+ or equivalent baseline security certification (desired).
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (better to have).
  • Qualys Certified Specialist or Tenable Certified Security Engineer (better to have).
  • Experience with Microsoft Defender Vulnerability Management at enterprise scale.
  • Experience with AI-augmented security tooling for vulnerability intelligence and patch prioritization.
  • Experience with CMDB-driven patching compliance reporting — reconciling asset inventory against patch state.
  • Familiarity with data center facilities patching — DCIM, environmental monitoring systems and smart PDU firmware lifecycles.

 

What we look for

An experienced, credible and operationally authoritative compliance leader who can hold the line across every platform tower simultaneously. We are looking for an individual who brings deep technical breadth across Windows, Linux, HCI, Storage, Backup, Networking and Facilities, combined with the governance experience to run a rigorous cross-tower patching programme, the analytical capability to produce compelling compliance reporting, and the leadership presence to drive accountability across engineering teams and present confidently to senior stakeholders and audit functions. The ideal candidate understands the evolving frontier AI threat landscape and can translate emerging risks into actionable infrastructure remediation priorities.

 

What we offer

We offer a competitive remuneration package where you'll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development. Plus, we offer:

  • Continuous learning: You'll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs.

 

EY | Building a better working world 

 

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

 

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

 

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Company

EY
Kochi, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from EY's careers site·first seen 17 Sept 2026·last verified 17 Sept 2026·How we source jobs

Similar jobs

  • eCompliance Manager at sandozTelangana (Sandoz), India–match not yet calculated
  • Labour Compliance Executive at Johnson ControlsMumbai, India–match not yet calculated
  • KYC Operations Team Lead - Specialised Markets at WiseHyderabad, India–match not yet calculated
  • Senior Compliance Analyst at ameripriseDelhi NCR, India–match not yet calculated
  • PM - Compliance at Weekday AIPune, India–match not yet calculated

Browse more jobs

  • Compliance Officer jobs in India
  • Risk Analyst jobs in India
  • Insurance Agent jobs in India
  • Insurance Claims Adjuster jobs in India
  • Compliance Officer jobs in United States
  • Compliance Officer jobs in United Kingdom