EY GDS Risk Advisory - Cyber Transformation Manager in All, Philippines

Title: GDS Risk Advisory - Cyber Transformation Manager

Location: PH-All-Taguig City

Job Number: TAG0001U

As many organizations have learned, sometimes the hard way, cyber attacks are no longer a matter of if, but when.

For EY Advisory a better working world means solving big, complex industry issues and capitalizing on opportunities to help deliver outcomes that grow, optimize and protect our clients' businesses.

Our global mindset and collaborative culture across our diverse team of consultants and industry professionals inspire us to ask better questions about the cybersecurity challenges you face. We then team with you to co-create more innovative answers – to activate a foundation that protects the business as it is today, adapt that foundation as the organization and threats change, and anticipate attacks that may be coming.

Together, we help you deliver better outcomes and long-lasting results, from strategy to execution.


Job purpose:

  • Manager in the Risk Advisory team to work on various Cyber Transformation projects for our customers across the globe.

  • You will be responsible for overall client service quality delivery in accordance with EY quality guidelines & methodologies. You will need to manage accounts and relationships on a day-to-day basis and explore new business opportunities for the firm. Establishing, strengthening and nurturing relationships with clients (functional heads & key influencers) and internally across service lines and proactively will also be a part of your day-to-day activities. You will assist in developing new methodologies and internal initiatives, and help in creating a positive learning culture by coaching, counselling and developing junior team members.

  • In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards, by reviewing the work provided by junior members.

Your client responsibilities:

  • Provide guidance and share knowledge with team members and participate in performing procedures focusing on complex, judgmental and/or specialized issues. Work with the team and the client to create plans for accomplishing engagement objectives and a strategy that complies with professional standards and addresses the risks inherent in the engagement

  • Brief the engagement team on the client's environment and industry trends. Maintain relationships with client management to manage expectations of service, including work products, timing, and deliverables. Demonstrate a thorough understanding of complex information systems and apply it to client situations

  • Use extensive knowledge of the client's business/industry to identify technological developments and evaluate impacts on the client's business. Demonstrate excellent project management skills, inspire teamwork and responsibility with engagement team members, and use current technology/tools to enhance the effectiveness of deliverables and services. Understand EY and its service lines and actively assess what the firm can deliver to serve clients

  • Assist Partners & Senior Managers in driving the business development process on existing client engagements by gathering appropriate resources, gaining access to key contacts & supervising proposal preparation.

  • Create innovative insights for clients, adapts methods & practices to fit operational team needs & contributes to thought leadership documents.

  • Practice secondment for developing new methodologies.

  • Facilitate discussions / knowledge sharing with key client personnel and contribute to EY thought leadership.

  • Plan & schedule client engagements. Determine and deploy the right team with adequate skill sets for executing engagements and periodically review status of engagements and work products.

  • Demonstrate strong project management skills

  • Maintain a strong client focus by effectively serving client needs and developing productive working relationships with client personnel. Stay abreast of current business and economic developments and new pronouncements/standards relevant to the client's business.

  • Demonstrate industry expertise (deep understanding of the industry, emerging trends, issues/challenges, key players & leading practices)

  • Review status updates and prepare management presentations/audit committee presentations etc.

  • Actively contribute to improving operational efficiency on projects & internal initiatives.

Your people responsibilities:

  • Identify buyers, influencers & stakeholders in existing client engagements and build strong relationships.

  • Display teamwork, integrity and leadership. Work with team members to set goals and responsibilities for specific engagements. Foster teamwork and innovation.

  • Drive performance management for self and team.

  • Driving the quality culture agenda at GTH

  • Manage the performance management for the direct reportees, as per the organization policies

  • Training and mentoring of project resources

  • Participating in the organization-wide people initiatives

Mandatory Skills:

  • Strong knowledge of cyber / information security concepts, risk and controls concepts

  • Strong knowledge of standards such as ISO 27001/2, ISO 22301, ISO 27018, PCI – DSS, NIST standards on Cyber Security, HITRUST, etc.

  • Strong knowledge of regulations such as FISMA, HIPAA, Reg SCI, MAS, etc.

  • Good knowledge of TCP/IP, concepts of OSI layer and protocols, networking and security concepts

  • Strong knowledge of OS (Windows / Linux) security, Database security

  • Strong knowledge on tools like Nessus, BackTrack, NMAP, BurpSuite, etc. is a definite plus

  • Sound familiarity with OWASP and Secure SDLC standards / frameworks

  • Strong knowledge of IT infrastructure (switches, routers, firewalls, IDS, IPS, etc.)

  • Strong knowledge of Security architecture design and review

  • Knowledge Security operations (SOC, SIEM) skills in assessment, design, architecture, management and reporting

  • Knowledge on reviewing firewall rulesets

  • Sound experience in LAN/WAN architectures and reviews

  • Good knowledge on Privacy, Governance and Reporting

  • Good knowledge of cyber threats and vulnerabilities related to platform and infrastructure

  • Sound knowledge of vulnerability management

  • Sound knowledge of anti-virus solutions (e.g. Symantec, McAfee, etc.)

  • Knowledge of incident management

  • Good Knowledge of creation of cyber policies and procedures

  • CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer

  • BE/BTech/MCA with a sound industry experience of 7 to 10 years


  • Bachelor's Degree

  • Must be amenable to work in McKinley Hill, Taguig and/or Makati and/or Ortigas