Ernst & Young - San Antonio, TX
posted 5 months ago
The Government & Public Sector practice of Ernst & Young LLP is dedicated to providing a comprehensive range of consulting and audit services aimed at assisting Federal, State, Local, and Education clients in implementing innovative ideas to achieve their mission outcomes. This role is situated within the Cybersecurity - Strategy, Risk, Compliance & Resiliency (SRC&R) team of the Service Delivery Center, which is composed of high-performing, US-based resources collaborating closely with experienced professionals to deliver project-based work and managed services to federal clients. The SRC&R team plays a crucial role in aligning security management strategies with business goals by assessing, designing, training, implementing, and operating cybersecurity processes and solutions. This function is bolstered by strategic alliances with third-party vendors and the application of established cybersecurity frameworks such as NIST CSF, NIST 800-53, and NIST 800-37. In this position, you will support the technology consulting engagement team analysts in the SRC&R service operations and delivery. Your responsibilities will include assisting on-site GPS SRC&R consultants in identifying process improvements, enhancing existing SRC&R solutions, and operating SRC&R processes as required. You will engage in various activities such as assessing cybersecurity controls, programs, and strategies using proprietary and industry frameworks, operating SRC&R solutions based on defined policies and procedures, and developing and implementing cybersecurity measurements and monitoring. Additionally, you will contribute to the development and execution of cybersecurity strategies and roadmaps, enhance NIST Risk Management Framework operations, and manage cybersecurity-focused supply chain and third-party risk management operations. This role requires a proactive approach to cybersecurity process design and re-engineering, ensuring that our clients can effectively protect their operations and meet compliance requirements.