Platform Infrastructure Patching and Vulnerability Compliance Lead

Location
Bengaluru
Workplace
Hybrid

About this role

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Job Description

I&O Platform Infrastructure Patching & Vulnerability Compliance Lead

 

The opportunity

In a plan to strengthen and extend our footprint in EY Enterprise Technology we are looking for an experienced and authoritative Patching and Vulnerability Compliance Lead to own and drive patching compliance, vulnerability management and security posture reporting across EY's entire I&O Platform Infrastructure estate. This is a senior cross-tower leadership role with accountability that spans every platform discipline — Windows, Linux, Storage, Hyperconverged Infrastructure (HCI), Backup, Network, Facilities and associated managed services.

 

The role sits at the intersection of infrastructure operations, cybersecurity and executive reporting, and is a key leadership position within EY's Infrastructure Operations Centre (IOC). The successful candidate will serve as the firm's primary authority on infrastructure patching compliance, frontier AI risk response as it applies to infrastructure, and cross-tower SPI and SLA performance — providing the visibility, governance and operational leadership needed to maintain a secure, compliant and well-managed global infrastructure estate.

 

Your key responsibilities

The I&O Platform Infrastructure Patching and Vulnerability Compliance Lead owns the end-to-end patching governance framework across all I&O platform towers, ensuring that vulnerability remediation commitments are met, compliance positions are accurately reported and exceptions are managed through a rigorous, risk-based process. This professional serves as the single point of accountability for patching SLA performance across Windows, Linux, Storage, HCI, Backup, Network and Facilities infrastructure domains.

 

Operating as a lead member of the Infrastructure Operations Centre (IOC), this role drives the weekly, monthly and quarterly compliance reporting cycle, chairs cross-tower patching forums, manages escalations from security and audit stakeholders, and leads the firm's response to frontier AI-related infrastructure risks — ensuring that emerging AI-driven threat vectors are assessed, prioritized and remediated within agreed timelines. The Lead partners with tower engineering leads, security operations, risk and compliance teams, and senior I&O leadership to deliver a consistent, transparent and defensible compliance posture.

 

Skills and attributes for success

  • Broad knowledge of I&O Platform Infrastructure technologies across all towers, including:
    • Windows Server patching — WSUS, SCCM/MECM, Windows Update for Business
    • Linux patching — Red Hat Satellite, Ansible, YUM/DNF, APT-based tooling
    • Storage platform firmware and software lifecycle management
    • Hyperconverged Infrastructure (HCI) patching — Azure Stack HCI, Nutanix, VMware
    • Backup platform patching — Commvault, Veeam, Veritas or equivalent
    • Network device patching — routers, switches, firewalls, load balancers
    • Facilities and data center infrastructure — UPS, PDU, DCIM and environmental systems
  • Strong vulnerability management lifecycle experience — from scan to remediation to compliance attestation (exclusionary).
  • Deep experience with vulnerability scanning tooling — Qualys, Tenable Nessus, Rapid7, Microsoft Defender for Endpoint or equivalent (exclusionary).
  • Experience leading patching governance forums and cross-tower compliance reviews.
  • Strong understanding of frontier AI infrastructure risks and the ability to assess, prioritize and respond to AI-driven vulnerability and threat intelligence.
  • Experience operating in and leading from within an Infrastructure Operations Centre (IOC) or equivalent 24x7 operations environment.
  • Strong SPI and SLA management capability — ability to define, track, report and drive remediation of patching and compliance KPIs across multiple platform towers.
  • Experience producing executive-level compliance dashboards and vulnerability posture reporting.
  • Strong knowledge of security and compliance frameworks relevant to infrastructure patching:
    • CIS Benchmarks
    • NIST SP 800-40
    • ISO 27001
    • SOC 2
    • CVSSv3/v4 scoring and prioritization
  • Experience managing patching exceptions, risk acceptances and compensating control documentation.
  • Ability to engage and influence tower engineering leads, security operations and senior leadership stakeholders.
  • Experience working with ITSM platforms (ServiceNow or equivalent) for change management, patch scheduling and compliance tracking.
  • Strong PowerShell or Python scripting capability for compliance reporting automation.
  • Strong working knowledge of DevOps, Agile, Kanban, SCRUM and ITIL frameworks.
  • Ability to work effectively across global engineering teams and time zones.

 

To qualify for the role, you must have experience with

  • Cross-platform patching governance and compliance program leadership — 7+ years.
  • Vulnerability management lifecycle — scan, triage, remediation, attestation — 7+ years.
  • Windows Server patching at enterprise scale (WSUS, MECM, MDE) — 7+ years.
  • Linux patching at enterprise scale (Satellite, Ansible, YUM/APT) — 5–7 years.
  • HCI platform patching (Azure Stack HCI, Nutanix or VMware) — 3–5 years.
  • Storage and backup platform firmware and software lifecycle management — 3–5 years.
  • Network device patching governance across multi-vendor environments — 3–5 years.
  • Vulnerability scanning tool administration (Qualys, Tenable, Rapid7 or equivalent) — 5–7 years.
  • CVSSv3/v4 scoring, vulnerability prioritization and risk-based remediation planning.
  • SPI and SLA reporting for patching compliance across multiple infrastructure towers.
  • Executive compliance dashboard and posture reporting — monthly and quarterly cycles.
  • Patching exception management — risk acceptance, compensating controls and audit evidence.
  • Change management and patch scheduling through ServiceNow or equivalent ITSM.
  • IOC or NOC leadership presence — cross-tower incident and compliance escalation management.
  • Frontier AI risk assessment as applied to infrastructure security posture (preferred).
  • Security framework alignment — CIS, NIST, ISO 27001, SOC 2 (preferred).
  • PowerShell or Python automation for compliance reporting pipelines — 3–5 years.

 

Ideally, you'll also have

  • ITIL v4 Foundation certification (exclusionary).
  • Certified Information Systems Security Professional (CISSP) or equivalent (desired).
  • CompTIA Security+ or equivalent baseline security certification (desired).
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (better to have).
  • Qualys Certified Specialist or Tenable Certified Security Engineer (better to have).
  • Experience with Microsoft Defender Vulnerability Management at enterprise scale.
  • Experience with AI-augmented security tooling for vulnerability intelligence and patch prioritization.
  • Experience with CMDB-driven patching compliance reporting — reconciling asset inventory against patch state.
  • Familiarity with data center facilities patching — DCIM, environmental monitoring systems and smart PDU firmware lifecycles.

 

What we look for

An experienced, credible and operationally authoritative compliance leader who can hold the line across every platform tower simultaneously. We are looking for an individual who brings deep technical breadth across Windows, Linux, HCI, Storage, Backup, Networking and Facilities, combined with the governance experience to run a rigorous cross-tower patching programme, the analytical capability to produce compelling compliance reporting, and the leadership presence to drive accountability across engineering teams and present confidently to senior stakeholders and audit functions. The ideal candidate understands the evolving frontier AI threat landscape and can translate emerging risks into actionable infrastructure remediation priorities.

 

What we offer

We offer a competitive remuneration package where you'll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development. Plus, we offer:

  • Continuous learning: You'll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs.

 

EY | Building a better working world 

 

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

 

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

 

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?

Top Benefits

  • Flexible working
  • Career development
  • Continuous learning
  • Transformative leadership coaching