Jobs›Platform Infrastructure, Kochi

Platform Infrastructure Patching and Vulnerability Compliance Lead

EY · Kochi
PayPay not listed
WhereKochiKerala
TypeFull time
Posted17 Sep20 days ago, via SimplyHired
Skills they list27 named
Microsoft Windows ServerITIL CertificationAzureSCCMAnsibleKanbanDevOpsCISSPFirmwareWindowsNessusNIST standardsITILEmbedded softwareScrumISO 27002ServiceNowAgileISO 27001VMWareLinuxThreat intelligenceAICompTIA Security+PythonPowerShellSenior leadership
About this job
Location
Kochi
Other locations
Anywhere in Country
Salary
Competitive
Date
16 Sept 2026

Job description

Requisition ID
1744153

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Job Description

I&O Platform Infrastructure Patching & Vulnerability Compliance Lead

The opportunity

In a plan to strengthen and extend our footprint in EY Enterprise Technology we are looking for an experienced and authoritative Patching and Vulnerability Compliance Lead to own and drive patching compliance, vulnerability management and security posture reporting across EY's entire I&O Platform Infrastructure estate. This is a senior cross-tower leadership role with accountability that spans every platform discipline — Windows, Linux, Storage, Hyperconverged Infrastructure (HCI), Backup, Network, Facilities and associated managed services.

The role sits at the intersection of infrastructure operations, cybersecurity and executive reporting, and is a key leadership position within EY's Infrastructure Operations Centre (IOC). The successful candidate will serve as the firm's primary authority on infrastructure patching compliance, frontier AI risk response as it applies to infrastructure, and cross-tower SPI and SLA performance — providing the visibility, governance and operational leadership needed to maintain a secure, compliant and well-managed global infrastructure estate.

Your key responsibilities

The I&O Platform Infrastructure Patching and Vulnerability Compliance Lead owns the end-to-end patching governance framework across all I&O platform towers, ensuring that vulnerability remediation commitments are met, compliance positions are accurately reported and exceptions are managed through a rigorous, risk-based process. This professional serves as the single point of accountability for patching SLA performance across Windows, Linux, Storage, HCI, Backup, Network and Facilities infrastructure domains.

Operating as a lead member of the Infrastructure Operations Centre (IOC), this role drives the weekly, monthly and quarterly compliance reporting cycle, chairs cross-tower patching forums, manages escalations from security and audit stakeholders, and leads the firm's response to frontier AI-related infrastructure risks — ensuring that emerging AI-driven threat vectors are assessed, prioritized and remediated within agreed timelines. The Lead partners with tower engineering leads, security operations, risk and compliance teams, and senior I&O leadership to deliver a consistent, transparent and defensible compliance posture.

Skills and attributes for success

Broad knowledge of I&O Platform Infrastructure technologies across all towers, including

Windows Server patching — WSUS, SCCM/MECM, Windows Update for Business

Linux patching — Red Hat Satellite, Ansible, YUM/DNF, APT-based tooling

Storage platform firmware and software lifecycle management

Hyperconverged Infrastructure (HCI) patching — Azure Stack HCI, Nutanix, VMware

Backup platform patching — Commvault, Veeam, Veritas or equivalent

Network device patching — routers, switches, firewalls, load balancers

Facilities and data center infrastructure — UPS, PDU, DCIM and environmental systems

Strong vulnerability management lifecycle experience — from scan to remediation to compliance attestation (exclusionary).

Deep experience with vulnerability scanning tooling — Qualys, Tenable Nessus, Rapid7, Microsoft Defender for Endpoint or equivalent (exclusionary).

Experience leading patching governance forums and cross-tower compliance reviews.

Strong understanding of frontier AI infrastructure risks and the ability to assess, prioritize and respond to AI-driven vulnerability and threat intelligence.

Experience operating in and leading from within an Infrastructure Operations Centre (IOC) or equivalent 24x7 operations environment.

Strong SPI and SLA management capability — ability to define, track, report and drive remediation of patching and compliance KPIs across multiple platform towers.

Experience producing executive-level compliance dashboards and vulnerability posture reporting.

Strong knowledge of security and compliance frameworks relevant to infrastructure patching

CIS Benchmarks

NIST SP 800-40

ISO 27001

SOC 2

CVSSv3/v4 scoring and prioritization

Experience managing patching exceptions, risk acceptances and compensating control documentation.

Ability to engage and influence tower engineering leads, security operations and senior leadership stakeholders.

Experience working with ITSM platforms (ServiceNow or equivalent) for change management, patch scheduling and compliance tracking.

Strong PowerShell or Python scripting capability for compliance reporting automation.

Strong working knowledge of DevOps, Agile, Kanban, SCRUM and ITIL frameworks.

Ability to work effectively across global engineering teams and time zones.

To qualify for the role, you must have experience with

Cross-platform patching governance and compliance program leadership — 7+ years.

Vulnerability management lifecycle — scan, triage, remediation, attestation — 7+ years.

Windows Server patching at enterprise scale (WSUS, MECM, MDE) — 7+ years.

Linux patching at enterprise scale (Satellite, Ansible, YUM/APT) — 5–7 years.

HCI platform patching (Azure Stack HCI, Nutanix or VMware) — 3–5 years.

Storage and backup platform firmware and software lifecycle management — 3–5 years.

Network device patching governance across multi-vendor environments — 3–5 years.

Vulnerability scanning tool administration (Qualys, Tenable, Rapid7 or equivalent) — 5–7 years.

CVSSv3/v4 scoring, vulnerability prioritization and risk-based remediation planning.

SPI and SLA

Never pay to get work. If a listing asks for a fee, it is a scam. The ten signs →

Apply on SimplyHired
Opens simplyhired.co.in in a new tab