Cyber Strategy - Manager - Consulting
The Opportunity
Organizations are navigating an increasingly complex cyber risk landscape driven by digital transformation, evolving threats, regulatory requirements, and emerging technologies. As a Manager within EY's Cyber Strategy practice, you will help clients strengthen cybersecurity programs, align security investments to business objectives, and enhance enterprise resilience. This role offers the opportunity to lead client engagements, solve complex business challenges, and deliver meaningful outcomes across cybersecurity strategy, governance, risk, and operating model transformation.
Your Key Responsibilities
- Lead and support cybersecurity strategy, governance, and transformation engagements across a range of industries.
- Assess cybersecurity programs, operating models, governance structures, policies, standards, and control environments to identify risks, capability gaps, and improvement opportunities.
- Work closely with client leadership to conduct cybersecurity assessments, facilitate workshops, and evaluate capabilities against industry frameworks and leading practices.
- Develop cybersecurity strategies, target operating models, governance frameworks, transformation roadmaps, and executive-level recommendations that align cybersecurity priorities with business objectives.
- Manage engagement workstreams, lead teams, and deliver high-quality client service within established timelines and budgets.
- Monitor emerging threats, industry trends, and regulatory developments, translating insights into actionable recommendations for clients.
- Contribute to business development activities, proposal efforts, account growth initiatives, and thought leadership.
- Collaborate with professionals across EY's Cybersecurity and broader capabilities to deliver integrated client solutions.
Skills and Attributes for Success
- Knowledge of the cybersecurity landscape, industry trends, and leading practices to identify client challenges and opportunities.
- Ability to work closely with Senior Managers, Partners, and client executives to deliver successful engagement outcomes.
- Experience advising organizations on cybersecurity program improvement, governance, and transformation initiatives.
- Ability to deliver high-quality work products within budget and established deadlines.
- Strong analytical, problem-solving, and critical-thinking skills.
- Ability to communicate complex cybersecurity concepts to technical and executive audiences.
- Strong presentation, facilitation, and stakeholder management skills.
- Experience leading teams in a collaborative, fast-paced consulting environment.
- Commitment to quality, continuous learning, and professional development.
Qualifications
- A bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field and approximately 5+ years of relevant experience; or a graduate degree and approximately 4+ years of relevant experience.
- Experience in one or more of the following areas:
- Cybersecurity assessments and maturity evaluations
- Cybersecurity governance and risk management
- Security strategy and roadmap development
- Cybersecurity operating model and organizational design
- IT and cybersecurity policies, standards, procedures, and controls
- Cybersecurity metrics and executive reporting
- Cyber transformation and program improvement initiatives
- Knowledge of cybersecurity frameworks and standards, including NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls, and PCI DSS.
- Familiarity with cybersecurity laws and regulations such as HIPAA, FISMA, and GLBA.
- Experience supporting or leading client-facing cybersecurity engagements.
- Strong written, verbal, and presentation skills.
- Willingness to travel based on client and business needs; travel estimated at 25-50%.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, CRISC, CISA, CGEIT, CCSP, or Security+.
- Experience conducting cybersecurity maturity assessments and benchmarking engagements.
- Experience supporting cyber transformation, governance, or CISO advisory initiatives.
- Knowledge of regulated industries, such as healthcare, financial services, government, life sciences, power and utilities.
- Experience facilitating executive workshops and strategic planning sessions.
- Consulting experience within a professional services environment.
What We Look For
We seek professionals who combine cybersecurity knowledge with strong consulting and leadership skills. The ideal candidate can build trusted relationships, solve complex business challenges, communicate effectively with executives, and deliver practical recommendations that help organizations strengthen cybersecurity and achieve strategic objectives.
Pay
- Base salary range for all geographic locations in the US: $144,900 to $265,800.
- Base salary range for New York City Metro Area, Washington State and California (excluding Sacramento): $173,900 to $302,100.
- Individual salaries determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography.
Benefits
- Medical and dental coverage.
- Pension and 401(k) plans.
- Wide range of paid time off options.
- Flexible vacation policy – you decide how much vacation time you need based on your personal circumstances.
- Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support physical, financial, and emotional well-being.
Schedule
- Team-led and leader-enabled hybrid model.
- For most people in external, client serving roles, expectation to work together in person 40-60% of the time over the course of an engagement, project or year.