EY-Cybersecurity-Vulnerability Management And Cybersecurity Asset Management-Manager
- Location
- Kochi
- Other locations
- Anywhere in Country
- Salary
- Competitive
- Date
- Sep 28, 2026
Job description
- Requisition ID
- 1746189
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
EY – Cybersecurity Manager, Vulnerability Management & Cybersecurity Asset Management
Overview
As a Manager in EY’s Cybersecurity practice, you will play a key role in delivering Enterprise Vulnerability Management, Security Exposure Management, Cybersecurity Asset Management, Policy Compliance, and Security Awareness services across multiple client environments. We are seeking cybersecurity professionals with expertise in vulnerability identification, risk assessment, remediation governance, asset discovery, compliance monitoring, human risk reduction, and security posture management using industry-leading platforms.
The role involves administration, optimization, and operation of vulnerability and exposure management platforms such as Qualys VMDR, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, CrowdStrike Falcon Exposure Management, Wiz, Orca Security, and Greenbone/OpenVAS. It also includes leading security awareness and phishing-simulation programs using platforms such as Proofpoint Security Awareness Training, KnowBe4, Microsoft Attack Simulation Training, Mimecast Awareness Training, and SANS Security Awareness. The successful candidate will work closely with security, infrastructure, cloud, application, teams to drive risk reduction and improve cyber resilience.
The Opportunity
We are seeking cybersecurity professionals with 12+ years of experience in Vulnerability Management, Cybersecurity Asset Management, Security Operations, Exposure Management, or Cybersecurity Consulting.
The ideal candidate will possess strong experience in vulnerability lifecycle management, security risk analysis, asset inventory management, compliance reporting, and stakeholder engagement while supporting enterprise-wide security improvement initiatives.
Key Responsibilities
Vulnerability Management Operations
Administer and manage enterprise vulnerability and exposure management solutions, such us Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, CrowdStrike Falcon Exposure Management, Wiz, Orca Security, and Greenbone/OpenVAS, across multiple client environments.
Perform internal, external, authenticated, and unauthenticated vulnerability assessments.
Configure and manage vulnerability scanning schedules, scan profiles, and scanning appliances.
Analyze vulnerability findings and assess potential business and security risks.
Perform vulnerability validation, prioritization, and risk-based remediation recommendations.
Track remediation activities and validate vulnerability closure.
Support vulnerability exception and risk acceptance processes.
Develop and maintain vulnerability management dashboards, reports, and metrics.
Collaborate with infrastructure, cloud, and application teams to drive timely remediation activities.
Support major vulnerability response efforts related to critical CVEs and emerging threats.
Cybersecurity Asset Management (CSAM)
Administer Qualys CyberSecurity Asset Management capabilities.
Maintain accurate visibility of enterprise assets across on-premises, cloud, and hybrid environments.
Monitor asset discovery activities and improve inventory completeness.
Identify unmanaged, unauthorized, and unknown assets.
Perform asset classification and criticality assessments.
Support asset ownership validation and governance processes.
Generate asset inventory reports and security posture metrics.
Collaborate with asset owners and technology teams to improve inventory accuracy.
Policy Compliance Management
Administer Qualys Policy Compliance modules and compliance controls.
Configure compliance policies aligned with regulatory, industry, and organizational requirements.
Conduct compliance assessments for servers, endpoints, databases, and network devices.
Analyze compliance gaps and provide actionable remediation recommendations.
Support security baseline validation and configuration assessments.
Produce compliance scorecards and executive reporting.
Assist clients in maintaining continuous compliance monitoring programs.
Vulnerability Governance & Risk Management
Support enterprise vulnerability management governance frameworks.
Facilitate remediation review meetings with technology stakeholders.
Monitor SLA compliance and remediation performance metrics.
Develop risk-based prioritization models for vulnerabilities and assets.
Track Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs).
Support audit activities and regulatory compliance requirements.
Maintain vulnerability management documentation, procedures, and operational runbooks.
Contribute to continuous improvement initiatives within the vulnerability management program.
Security Operations & Stakeholder Engagement
Perform vulnerability trend analysis and reporting.
Support security assessments and cyber risk reviews.
Engage with IT, security, cloud, and application teams to facilitate risk remediation.
Assist in responding to security incidents involving vulnerable assets.
Support executive reporting and management presentations.
Participate in service reviews and performance reporting activities.
Contribute to automation and process optimization initiatives.
Security Awareness & Human Risk Management
Design, operate, and continuously improve enterprise security awareness and human risk management programs.
Administer platforms such as Proofpoint Security Awareness Training, KnowBe4, Microsoft Attack Simulation Training, Mimec
काम पाने के लिए कभी पैसे मत दो। Fee माँगे तो scam है। दस निशान →