Cyber Defense Incident Responder
At EY, we’re committed to shaping your future with confidence. Join us and help build a better working world through technology that keeps our global organization running efficiently. With 250,000 people across more than 140 countries, EY Technology ensures secure, innovative solutions—from laptops and mobile devices to internal tools and client-facing services—are integrated into the services we deliver.
About the role
The Cyber & Investigative Services (CIS) Junior Incident Coordinator will use strong incident management techniques to coordinate security incident response for cybersecurity events or threats. This role requires a solid understanding of incident response plans, coordination skills, diplomacy, and the ability to make decisions in a fast-paced environment. Foundational skills in incident response, forensics, event analysis, and hands-on cybersecurity are essential.
Responsibilities
- Coordinate response efforts to cyber incidents, including nontraditional working hours as needed.
- Serve as a liaison between different business units and interface with security teams, business partners, management, vendors, and external parties.
- Drive integration with other corporate incident management programs to ensure consistency and alignment with peer support teams.
- Lead small to medium-sized projects as directed by leadership.
- Champion process and documentation improvements to ensure scalable and consistent response operations.
- Develop and deliver metrics to leadership.
- Create draft communications and provide timely reports/updates to leadership during and after incidents.
- Own and manage the team’s internal action playbooks and knowledge base.
- Participate in on-call rotations for off-hours support (required).
Skills
- Resolution of security incidents by validating root cause and solutions.
- Analyze investigative findings and develop fact-based reports.
- Identify and articulate opportunities for improvement and drive lessons-learned activities.
- Demonstrated integrity and judgment in a professional environment.
- Inquisitive approach to analysis and peer review.
- Emotional intelligence and ability to remain calm under pressure.
- Ability to balance work and personal priorities effectively.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Information Systems, Engineering, a related field, or equivalent experience.
- 5+ years of experience in at least two of the following roles:
- Member of a Security Operations Center (SOC).
- Security Incident Response Analyst or supporting function (2 years minimum).
- eDiscovery or related role performing forensic functions.
- Deep understanding of security threats, vulnerabilities, and incident response.
- Understanding of electronic investigation, forensic tools, and methodologies, including:
- Log correlation and analysis.
- Forensic handling of electronic data.
- Computer security investigative processes.
- Malware identification and analysis.
- Basic understanding of legalities surrounding electronic discovery and analysis.
- Understanding of regulatory stipulations regarding security incidents.
- Experience with SIEM technologies (e.g., Splunk).
- Deep understanding of both Windows and Unix/Linux-based operating systems.
- Must hold or be willing to pursue related professional certifications such as GCFE, GCFA, GCIH, CISA, CISM, CISSP, or CCIM.
Qualifications
- Demonstrated integrity in a professional environment.
- Ability to work independently with a global mind-set for diverse cultures and backgrounds.
- Knowledge of business industry-standard security incident response processes, procedures, and life-cycle.
- Excellent organizational skills and strong attention to detail.
- Excellent teaming, social, communication, and writing skills.
- Strong customer service skills.
Pay
The base salary range for this role in the U.S. is $91,100 to $170,400. For New York City Metro Area, Washington State, and California (excluding Sacramento), the range is $109,300 to $193,600. Individual salaries are determined by factors including education, experience, knowledge, skills, and geography.
Benefits
- Comprehensive medical and dental coverage.
- Pension and 401(k) plans.
- Flexible vacation policy, allowing you to decide how much time you need based on personal circumstances.
- Designated EY Paid Holidays, Winter/Summer breaks, and Personal/Family Care leave.
Schedule
This role follows a team-led and leader-enabled hybrid model. Most people in external, client-serving roles are expected to work in person 40-60% of the time over the course of an engagement, project, or year.