Cyber Defense Incident Responder
At EY, we’re committed to shaping your future with confidence by providing opportunities within a globally connected, diverse organization. Join us to help build a better working world through technology.
About the role
EY Technology supports our organization’s technology needs through three business units: Client Technology (CT), Enterprise Workplace Technology (EWT), and Information Security (InfoSec). The Cyber & Investigative Services (CIS) Junior Incident Coordinator will use strong incident management techniques to coordinate security incident response to cybersecurity events or incidents stemming from suspected threats.
This role requires a strong comprehension of incident response plans, coordination of activities, diplomacy, and decision-making skills to handle the fast-paced world of incident management. Foundational skills in incident response, chain of custody, forensics, event analysis, and hands-on cybersecurity are essential.
Responsibilities
- Coordinate response efforts to cyber incidents caused by external threats, which may involve nontraditional working hours.
- Serve as a liaison to different businesses and interface with fellow team members and colleagues on other security teams.
- Manage relationships with business partners, management, vendors, and external parties as needed.
- Drive integration with other corporate incident management programs to ensure consistency and alignment with peer support teams within IT.
- Help lead small to medium-sized projects as directed by leadership.
- Champion process and documentation, developing scalable response operations and ensuring continuous improvement to the company’s incident response plan.
- Develop and deliver metrics to leadership as requested.
- Create ready-to-go draft communications and ensure timely reports/updates to leadership during and after an event.
- Own and manage the team’s internal action playbooks and knowledgebase.
- Be willing to be on-call off hours in rotation with other team members.
Requirements
- Bachelor’s or Master’s Degree in Computer Science, Information Systems, Engineering, a related field, or equivalent experience.
- 5+ years’ experience in at least two of the following roles:
- Member of a Security Operations Center (SOC).
- Security Incident Response Analyst or supporting function (2 years minimum).
- eDiscovery or related role performing forensic functions.
- Deep understanding of security threats, vulnerabilities, and incident response.
- Understanding of electronic investigation, forensic tools, and methodologies, including:
- Log correlation and analysis.
- Forensically handling electronic data.
- Knowledge of computer security investigative processes.
- Malware identification and analysis.
- Basic understanding of legalities surrounding electronic discovery and analysis.
- Understanding of regulatory stipulations regarding security incidents.
- Experience with SIEM technologies (e.g., Splunk).
- Deep understanding of both Windows and Unix/Linux-based operating systems.
- Must hold or be willing to pursue related professional certifications such as GCFE, GCFA, GCIH, CISA, CISM, CISSP, or CCIM.
Skills
- Resolution of security incidents by validating root cause and solutions.
- Analyze findings in investigative matters and develop fact-based reports.
- Identify and articulate opportunities for improvement while driving lessons learned activities.
- Demonstrated integrity and judgment within a professional environment.
- Inquisitive approach to analysis and peer review.
- Application of emotional intelligence and calm under pressure.
- Ability to appropriately balance work/personal priorities.
- Global mindset for working with different cultures and backgrounds.
- Knowledgeable in business industry-standard security incident response processes, procedures, and lifecycle.
- Excellent organizational skills and strong attention to detail.
- Excellent teaming, social, communication, and writing skills.
- Excellent customer service skills.
Benefits
- Comprehensive compensation and benefits package, with rewards based on performance and recognition for the value you bring to the business.
- Medical and dental coverage.
- Pension and 401(k) plans.
- Flexible vacation policy, allowing you to decide how much vacation time you need based on personal circumstances.
- Designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence to support your well-being.
Pay
The base salary range for this job in all geographic locations in the US is $91,100 to $170,400. The base salary range for New York City Metro Area, Washington State, and California (excluding Sacramento) is $109,300 to $193,600. Individual salaries are determined by factors including education, experience, knowledge, skills, and geography.
Schedule
- Hybrid model with an expectation to work in person 40-60% of the time over the course of an engagement, project, or year.
- On-call rotation during off hours.