Client Security Consulting & Assurance Legal Specialist
EYAbout the role
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently. We have over 400,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. At EY, safeguarding client data is a foundational priority embedded in every aspect of our operations. We are deeply committed to implementing robust information security measures that not only protect sensitive information but also foster trust and confidence with our clients. Our approach goes beyond simply meeting minimum compliance standards—EY continually invests in advanced technologies, comprehensive risk management strategies, and ongoing staff training to ensure that the confidentiality, integrity, and availability of client data are uncompromised. By maintaining rigorous controls and a proactive security posture, we enable our clients to pursue their business objectives with assurance that their valuable information is protected at every stage of our engagement.
EY Technology supports our technological needs.
Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information management systems.
The opportunity
The Client Security Consulting & Assurance (CSCA) team within EY Information Security is seeking a USA based, full time candidate that will be responsible for reviewing and negotiating information security contract requests initiated by our clients.
As a CSCA Assistant Director, you will be responsible for managing all information security aspects of a client contract from reviewing, redlining, and negotiating terms with clients. You will be expected to interact with senior level leaders within the EY account team, internal stakeholders including but not limited to General Counsel’s Office, Data Privacy and EY Technology.
You will be part of a highly collaborative environment, working with a team committed to delivering accurate and consistent responses to client inquiries. A genuine understanding of information security and technical disciplines is essential, along with the ability to build strong relationships with team members.
This role requires exceptional proficiency in spoken and written English and strong communication skills tailored to audiences at all tiers of the organization.
No travel is anticipated for this position.
Your key responsibilities
- Review and assess contracts for compliance ensuring adherence to relevant information security frameworks, standards such as ISO27001, NIST, and GDPR while aligning with EY organizational policies and regulatory standards. Identify potential risks associated with contract terms related to data protection and information security, providing recommendations for mitigation.
- Work closely with legal teams, engagement teams, and clients to negotiate contract terms that safeguard client information while meeting business objectives.
- Provide training and support to internal teams on information security requirements related to contracts, fostering a culture of compliance and awareness.
- Work independently with minimal supervision from management.
Skills and attributes for success
- Excellent verbal and written communication skills, with the ability to convey complex information clearly and effectively to diverse audiences.
- Strong analytical and problem-solving abilities, with attention to detail and the capacity to assess risks and recommend solutions.
- Demonstrated ability to manage time effectively, prioritize tasks, and balance multiple workloads in a fast-paced environment while maintaining high standards of quality and compliance.
- Bachelor’s degree in information security, Law, Business Administration, or a related field.
- CISM, CRISC, CISSP, or similar industry-recognized certifications are preferred.
- Proven experience in contract review and information security, preferably within a large corporate environment.Strong understanding of information security principles, dat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s