EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager
EY
Remote
EY – Cybersecurity Manager (SOC, Incident Response & Threat Intelligence)
Overview
As a Manager in EY’s Cybersecurity practice, you will play a pivotal role in delivering advanced Security Operations, Incident Response, Security Orchestration, and Threat Intelligence services across diverse client environments. We are seeking a Security Operations Manager to support MSSP and multi-tenant Security Operations Centers (SOC), administering, deploying, and overseeing IBM QRadar SIEM, Splunk Enterprise, ELK Stack, IBM SOAR Resilient, and CTM360 Threat Management Platform.
The role supports multiple client environments across IT and OT ecosystems, ensuring effective threat detection, incident response, security orchestration, and threat intelligence operations. Candidates may have expertise in one or more platforms, with opportunities for cross-training and growth across the security operations technology stack.
The Opportunity
We are seeking cybersecurity professionals with 12+ years of experience in Security Operations, Incident Response, Threat Intelligence, Cyber Defence, or cybersecurity consulting. The ideal candidate will possess deep expertise in SIEM, SOAR, and Threat Intelligence platforms while demonstrating the ability to lead client engagements, manage security operations teams, and contribute to the growth of EY's managed security services capabilities.
High-performing individuals who demonstrate leadership, innovation, and alignment with EY's values and talent policies may be considered for accelerated career progression and leadership opportunities within the cybersecurity practice.
Key Responsibilities
SIEM Administration - IBM QRadar, Splunk & ELK Stack (IT & OT Security Monitoring)
- Deploy, configure, and administer IBM QRadar, Splunk, and ELK Stack SIEM platforms across multiple client environments.
- Design and implement SIEM use cases, correlation rules, dashboards, and reporting mechanisms.
- Integrate log sources from network, endpoint, cloud, application, and OT environments.
- Monitor and optimize SIEM performance, health, and event processing capabilities.
- Perform tuning of offense rules to minimize false positives and improve detection efficiency.
- Support onboarding of new customers, assets, and log sources into the managed SOC environment.
- Lead investigations of security alerts, incidents, and suspicious activities identified through IBM QRadar, Splunk, and ELK Stack.
- Develop and maintain detection content aligned to evolving threat landscapes and industry best practices.
- Support incident response activities, forensic investigations, and root cause analysis.
- Collaborate with stakeholders to improve security visibility across IT and OT environments.
- Communicate complex technical concepts to senior stakeholders and business leaders.
- Mentor junior consultants and SOC analysts, fostering a culture of continuous learning and operational excellence.
- Deploy and configure SOAR platforms such as Phantom, XSOAR, Resilient supporting multi-tenant MSSP operations.
- Design and implement automated incident response workflows and response playbooks.
- Develop integrations between SOAR, SIEM, endpoint security, ticketing systems, and threat intelligence platforms.
- Configure incident types, workflows, tasks, and escalation processes for client environments.
- Maintain and enhance security orchestration workflows to improve SOC efficiency and response times.
- Troubleshoot integration, automation, and workflow performance issues.
- Collaborate with SOC teams to identify automation opportunities across incident handling processes.
- Lead customer onboarding, migration, and expansion activities within SOAR platforms.
- Develop custom scripts and automation use cases using supported APIs and integration frameworks.
- Ensure governance, auditability, and operational effectiveness of automated response actions.
- Support SOC analysts during complex incident investigations and escalations.
- Communicate complex technical concepts to senior stakeholders and business leaders.
- Mentor junior consultants and engineers in automation best practices.
- Deploy, configure, and manage Threat Management Platform such as CTM360, CyberArk, BitSight, RecordedFuture capabilities across client environments.
- Monitor external threat exposure and digital attack surfaces for multiple clients.
- Perform threat intelligence analysis to identify emerging threats, adversary activities, and indicators of compromise (IOCs).
- Correlate threat intelligence findings with SIEM and SOAR platforms to enhance detection capabilities.
- Develop threat intelligence reports, executive briefings, and strategic risk assessments.
- Monitor brand exposure, domain threats, credential leaks, phishing campaigns, and digital risks.
- Support proactive threat hunting activities using intelligence-driven methodologies.
- Create and maintain threat detection use cases based on intelligence findings.
- Collaborate with incident response teams during active cyber incidents.
- Provide actionable recommendations to clients for risk mitigation and exposure reduction.
- Support intelligence sharing and threat-informed defines initiatives.
- Lead security monitoring, threat detection, incident response, and threat intelligence activities across multiple client environments.
- Manage MSSP service delivery, ensuring adherence to SLAs, KPIs, and operational objectives.
- Support major incident management, cyber crisis response, and post-incident reviews.
- Coordinate across security, infrastructure, cloud, and application teams during investigations.
- Conduct regular service reviews and provide recommendations for security posture improvement.
- Drive operational excellence through process improvement, automation, and innovation.
- Support business development efforts, solution design, and customer presentations.
- Contribute to the development of SOC service offerings, methodologies, and intellectual property.
- Deep understanding of cybersecurity technologies including SIEM, SOAR, EDR, XDR, NDR, MDR, and Threat Intelligence Platforms
- Strong knowledge of Security Operations Center (SOC) processes and incident response methodologies
- Experience supporting both IT and Operational Technology (OT) security environments.
- Understanding of threat actor tactics, techniques, and procedures (TTPs)
- Strong analytical, investigation, and problem-solving skills
- Excellent stakeholder management and customer-facing consulting capabilities
- Ability to manage multiple clients and engagements simultaneously.
- Strong leadership and team management skills
- Experience delivering services in a Managed Security Services (MSSP) environment.
- Business acumen and client-focused mindset
- B. Tech or M. Tech in Cybersecurity, Computer Science, Electronics, Information Security, or related disciplines
- 12+ years of relevant cybersecurity experience
- Hands-on experience administering and managing SIEM platforms, including IBM QRadar, Splunk, and/or ELK Stack
- Hands-on experience with IBM SOAR Resilient and security automation technologies
- Experience in Threat Intelligence Operations and exposure management platforms
- Experience supporting SOC operations, incident response, and threat hunting activities.
- Strong understanding of IT security monitoring, detection engineering, and incident handling
- Strong command of verbal and written English
- Experience with scripting or programming languages such as Python, PowerShell, SQL, or similar
- Experience working within multi-client or MSSP environments is preferred.
- Professionals who are enthusiastic about cybersecurity operations, threat detection, incident response, and threat intelligence. Individuals who demonstrate leadership, innovation, operational excellence, and the ability to deliver impactful outcomes within a consulting and managed security services environment. A strong sense of ownership, continuous learning, customer focus, and alignment with EY's values will be critical to success in this role.
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.