Platform Infrastructure Patching and Vulnerability Compliance Lead
- Location
- Kochi
- Other locations
- Anywhere in Country
- Salary
- Competitive
- Date
- 16 Sept 2026
Job description
- Requisition ID
- 1744153
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Job Description
I&O Platform Infrastructure Patching & Vulnerability Compliance Lead
The opportunity
In a plan to strengthen and extend our footprint in EY Enterprise Technology we are looking for an experienced and authoritative Patching and Vulnerability Compliance Lead to own and drive patching compliance, vulnerability management and security posture reporting across EY's entire I&O Platform Infrastructure estate. This is a senior cross-tower leadership role with accountability that spans every platform discipline — Windows, Linux, Storage, Hyperconverged Infrastructure (HCI), Backup, Network, Facilities and associated managed services.
The role sits at the intersection of infrastructure operations, cybersecurity and executive reporting, and is a key leadership position within EY's Infrastructure Operations Centre (IOC). The successful candidate will serve as the firm's primary authority on infrastructure patching compliance, frontier AI risk response as it applies to infrastructure, and cross-tower SPI and SLA performance — providing the visibility, governance and operational leadership needed to maintain a secure, compliant and well-managed global infrastructure estate.
Your key responsibilities
The I&O Platform Infrastructure Patching and Vulnerability Compliance Lead owns the end-to-end patching governance framework across all I&O platform towers, ensuring that vulnerability remediation commitments are met, compliance positions are accurately reported and exceptions are managed through a rigorous, risk-based process. This professional serves as the single point of accountability for patching SLA performance across Windows, Linux, Storage, HCI, Backup, Network and Facilities infrastructure domains.
Operating as a lead member of the Infrastructure Operations Centre (IOC), this role drives the weekly, monthly and quarterly compliance reporting cycle, chairs cross-tower patching forums, manages escalations from security and audit stakeholders, and leads the firm's response to frontier AI-related infrastructure risks — ensuring that emerging AI-driven threat vectors are assessed, prioritized and remediated within agreed timelines. The Lead partners with tower engineering leads, security operations, risk and compliance teams, and senior I&O leadership to deliver a consistent, transparent and defensible compliance posture.
Skills and attributes for success
Broad knowledge of I&O Platform Infrastructure technologies across all towers, including
Windows Server patching — WSUS, SCCM/MECM, Windows Update for Business
Linux patching — Red Hat Satellite, Ansible, YUM/DNF, APT-based tooling
Storage platform firmware and software lifecycle management
Hyperconverged Infrastructure (HCI) patching — Azure Stack HCI, Nutanix, VMware
Backup platform patching — Commvault, Veeam, Veritas or equivalent
Network device patching — routers, switches, firewalls, load balancers
Facilities and data center infrastructure — UPS, PDU, DCIM and environmental systems
Strong vulnerability management lifecycle experience — from scan to remediation to compliance attestation (exclusionary).
Deep experience with vulnerability scanning tooling — Qualys, Tenable Nessus, Rapid7, Microsoft Defender for Endpoint or equivalent (exclusionary).
Experience leading patching governance forums and cross-tower compliance reviews.
Strong understanding of frontier AI infrastructure risks and the ability to assess, prioritize and respond to AI-driven vulnerability and threat intelligence.
Experience operating in and leading from within an Infrastructure Operations Centre (IOC) or equivalent 24x7 operations environment.
Strong SPI and SLA management capability — ability to define, track, report and drive remediation of patching and compliance KPIs across multiple platform towers.
Experience producing executive-level compliance dashboards and vulnerability posture reporting.
Strong knowledge of security and compliance frameworks relevant to infrastructure patching
CIS Benchmarks
NIST SP 800-40
ISO 27001
SOC 2
CVSSv3/v4 scoring and prioritization
Experience managing patching exceptions, risk acceptances and compensating control documentation.
Ability to engage and influence tower engineering leads, security operations and senior leadership stakeholders.
Experience working with ITSM platforms (ServiceNow or equivalent) for change management, patch scheduling and compliance tracking.
Strong PowerShell or Python scripting capability for compliance reporting automation.
Strong working knowledge of DevOps, Agile, Kanban, SCRUM and ITIL frameworks.
Ability to work effectively across global engineering teams and time zones.
To qualify for the role, you must have experience with
Cross-platform patching governance and compliance program leadership — 7+ years.
Vulnerability management lifecycle — scan, triage, remediation, attestation — 7+ years.
Windows Server patching at enterprise scale (WSUS, MECM, MDE) — 7+ years.
Linux patching at enterprise scale (Satellite, Ansible, YUM/APT) — 5–7 years.
HCI platform patching (Azure Stack HCI, Nutanix or VMware) — 3–5 years.
Storage and backup platform firmware and software lifecycle management — 3–5 years.
Network device patching governance across multi-vendor environments — 3–5 years.
Vulnerability scanning tool administration (Qualys, Tenable, Rapid7 or equivalent) — 5–7 years.
CVSSv3/v4 scoring, vulnerability prioritization and risk-based remediation planning.
SPI and SLA
काम पाने के लिए कभी पैसे मत दो। Fee माँगे तो scam है। दस निशान →