Global Lead Security Compliance & Enforcement - Director
Listed on 2026-09-13
-
IT/Tech
Information Security & Data Protection, Cybersecurity, Security Management & Operations
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunityThe Global Lead Security Compliance & Enforcement owns the strategy, operating model, and outcomes for the global Security Compliance function within Technology Assurance, Risk & Policy. The role transforms Security Compliance into a proactive, intelligence-driven, and enforcement-capable organization that reduces risk debt, sustains critical governance, risk, and compliance operations and provides defensible, audit-ready governance.
The Director creates clear global accountability for security compliance and converts fragmented or ambiguous risk situations into prioritized action. Using policy, compliance-posture data, risk appetite, escalation protocols, and executive decision forums, the role addresses situations in which ownership, remediation capacity, enforcement authority, or risk tolerance are unclear. This includes clearing persistent enforcement backlogs, sequencing scarce specialist capacity across concurrent initiatives, expanding control monitoring, resolving technology-lifecycle exposure, and establishing governance for frontier AI and Data Guard obligations.
Working with CTOs, Service Line Quality Leaders, Technology Risk & Compliance, Information Security leadership, risk and control owners, technology teams, and audit and governance stakeholders, the Director balances policy requirements with business impact, technology delivery, client confidence, and documented risk acceptance. The role sets the multi-year roadmap, leads a globally distributed organization, and provides senior leaders with decision-quality information on compliance posture, risk trends, enforcement, and remediation.
Key Responsibilities- Strategic Leadership
- Define and execute the global Security Compliance strategy, target operating model, multi-year roadmap, priorities, performance measures, and resource plan in alignment with risk appetite and business objectives.
- Lead and develop a globally distributed, capability-led organization that proactively addresses the highest-risk exposures while sustaining business-as-usual GRC operations and talent succession.
- Compliance Governance & Enforcement
- Own global policy compliance and the Non-Compliance Consequence Framework, including consistent enforcement, escalation, investigation, corrective action, backlog reduction, and documented risk acceptance.
- Risk Intelligence & Remediation
- Build data-driven risk intelligence and expand control monitoring and assurance through clear evidence, metrics, trends, dashboards, executive reporting, and risk burn-down tracking.
- Direct remediation and technology-lifecycle governance, including out-of-SLA vulnerability triage, End-of-Life exposure, exceptions, and emerging AI and Data Guard obligations.
- AI Governance & Emerging Technologies
- Establish compliance governance, monitoring, accountability, and reporting for frontier AI, Data Guard, and other emerging-technology obligations.
- Stakeholder & Executive Engagement
- Partner with CTOs, Service Line Quality Leaders, risk, security, audit, governance, and technology teams to balance policy, business impact, client confidence, and delivery, while advancing automation and continuous improvement.
The Director reports to the Global Leader, Technology Assurance, Risk & Policy within Information Security and leads the global Security Compliance function.
Knowledge And Skills Requirements- Deep knowledge of cyber security, technology and data risk, policy compliance, control assurance, GRC operations, enterprise remediation,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).