Cyber Threat Detection - Active Defense Analyst
$128.1k - $239.6kErnst & Young
At EY, we're all in to shape your future with confidence.
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
EY Technology:
Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently. We have 250,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. Everything from the laptops we use, to the ability to work remotely on our mobile devices and connecting our people and our clients, to enabling hundreds of internal tools and external solutions delivered to our clients. Technology solutions are integrated in the client services we deliver and is key to us being more innovative as an organization.
EY Technology supports our technology needs through three business units:
Client Technology (CT) - focuses on developing new technology services for our clients. It enables EY to identify new technology-based opportunities faster, and pursue those opportunities more rapidly.
Enterprise Workplace Technology (EWT) - EWT supports our Core Business Services functions and will deliver fit-for-purpose technology infrastructure at the cheapest possible cost for quality services. EWT will also support our internal technology needs by focusing on a better user experience.
Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information management systems.
The opportunity
The Active Defense team is responsible for four core areas: Network Reconnaissance, Proactive Penetration Testing (Purple Team), Anomaly Analysis, and Trapping and Coercion. This function allows the Cyber Defense Team to fortify and mature the firm's enterprise security.
In an Active Defense Analyst, we are looking for someone who has experience in Information Security and wants to take the next step in the adventure. In its purple team capacity, candidates will be expected to emulate attacker behaviors and devise strategies to disrupt the actions of an attacker, thus enhancing the abilities of defensive teams. In the threat hunting capacity, the analyst will identify security vulnerabilities through analysis of event data from SIEM and other relevant tools.
You will report findings to technical and non-technical audiences, and collaborate with other teams identify and remediate vulnerabilities. The position requires attention to detail and the ability to work, both as part of a team and independently.
Skills and attributes for success
Essential Functions of the job:
Perform research and analysis of attacker techniques and methodologies, and emulate those attacks in a collaborative and controlled environment
Identify security breaches through 'Hunting' operations within a SIEM, full packet capture, EDR, and other tools and treat intelligence
Identify patterns consistent with sophisticated attacker methodologies, and report on security concerns as they are escalated or identified.
Analyze artifacts collected during a security test or passive investigation.
Communicate with server owners, system custodians, and IT contacts to pursue security testing activities, including: obtaining access to systems, digital artifact collection, and containment and/or remediation actions
Create presentations in MS Word, PowerPoint, and/or Excel that support findings
Maintain, manage, improve and update security testing process and protocol documentation
Assist in analyzing findings, and develop fact based reports
Identify means to disrupt attacker actions, and enhance defender response capabilities.
To qualify for the role, you must have:
6+ years of relevant experience in one or more of the following areas: threat intelligence, intrusion analysis, incident response, malware analysis, security and network operations, penetration tester, or similar roles.
Demonstrated understanding of the threat intelligence life cycle, network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
Knowledgeable in security incident response process, procedures, and life-cycle, including performing security audits as part of red team
Good understanding of both Windows and Unix/Linux based operating systems
Understanding of IP networking concepts, to include addressing, routing, common protocol usage, use of proxies, load balancers, firewalls, routers, and switches in network architecture.
Global mind-set for working with different cultures and backgrounds
Demonstrated integrity and judgment within a professional environment
Ability to appropriately balance work/personal priorities
Teaming skills as well as ability to work independently on taskings
Good social, communication, and writing skills
Qualifications, Certifications and Education requirements:
Associates Degree and/or any of the following certifications: GPEN, CISSP, Security+, GCIH, OSCP, GCFE, CFCE, other relevant GIAC certs.
Familiarity with EDR, SIEM, Scripting, Malware Analysis.
Preferred:
Some hands-on experience as an administrator configuring one or more of SIEM, Endpoint Protection, Vulnerability Scanners, or Data Loss Prevention
Proficient with one or more scripting languages such as Perl, Python, PowerShell etc. in a threat intelligence or incident response environment
Supervising Responsibilities:
However, the role requires mentoring, collaboration, and training of more junior associates.
On rare occasions, may be required to work nights or weekends in support of incident response or penetration audits.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $128,100 to $239,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $153,800 to $272,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.?
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
$87.7k - $164k
...services, as well as detect and quickly respond to... ...strategy, digital identity, cyber defense, application security... ...(CTF) Incident Analyst will work as a senior... ...security incident response activities, including: obtaining... ...on perceived security threats Maintain, manage, improve...CyberSummer holidayLocal areaFlexible hours- ...SOC Analyst Onsite in Levittown, NY *Must be local to Long Island, NY 6+ months... ...their network against external threats. SOC analyst will be detecting, evaluating, and responding to cybersecurity... ...knowledge or proven experience in Cyber or Network security Threat and...CyberLocal area
$86.4k - $105.6k
...You’ll Do At LIPA The IT Analyst, Operational Technology (OT) and Cyber is responsible for the... ...technology assets from cyber threats. This role focuses on... ..., and suspicious activity using security tools and... ...SIEM platforms, intrusion detection systems, vulnerability management...CyberTemporary workImmediate startRemote workFlexible hours$170k - $190k
...Cybersecurity will lead API's global cyber defense program, reporting to the... ...for security operations, threat detection, and incident response —... ..., recovery, and postmortem activities for security incidents.... ...Development: Empower and develop SOC analysts and team members, fostering...CyberWork at officeLocal areaRemote work$79.54k - $129.18k
...Technology Risk Management Analyst Location: Hicksville, NY 11801 As a key member of the second line of defense Technology, Cyber, Third Party Risk Management & Resilience Risk Management team, the Technology Risk Analyst will support the Technology Risk team to...CyberWork at officeLocal area$86.58k - $147.19k
...Systems is a leading global defense, security, and... ...technology solutions, and cyber security. We are experiencing... ...Systems: Systems for detecting, jamming, and protecting against electronic threats; Precision Navigation... ...posting will remain active until the position is filled...CyberFull timeWork at officeLocal area- ...Sr. Cyber Security & Threat Analyst Location: New Hyde Park, NY (Hybrid Onsite) Duration: 12+ months contract Visa: USC and GC only Hot... .../Go AWS Cloud Security OR Azure EDR – End Point Detection and Response SIEM – Security Information and Event Management...CyberContract workWork experience placement
$121.2k - $199.2k
...7464 External Description: Cyber Security Lead -OT Date: Mar 11, 2026... ...protection, asset visibility, endpoint security, and threat detection. The position also supports essential governance activities, ensuring alignment with NIST frameworks and...CyberFor contractorsFlexible hours$107.2k - $160.8k
...reducing organizational risk by detecting, analyzing, and responding to... ...and external security threats. This role conducts threat analysis... ...and threat intelligence activities, supports incident response,... ...posture. What You'll Do: Cyber Intelligence & Incident Response...CyberWork experience placement- ...responds to internal and external security threats. Oversees, responds to, and... ...commodity threats. Performs threat hunting activities to identify compromised resources.... ...research and intelligence gathering to improve detection and response capabilities. Proposes...Cyber
$28.99 - $34.06 per hour
...First Line of Defense (FLOD) Corporate Risk and Compliance Specialist Job Category: Learning Development Requisition Number: FIRST... ...product stakeholders to ensure all key First Line of Defense activities are completed accurately and on time. Core Contributions...Hourly payFlexible hours- ...technologies such as antivirus, IDS/IPS, endpoint detection & response, DLP, data encryption, proxies... ...IT management and staff in cybersecurity threat risk assessments, development, testing... ..., minimize or quickly recover from cyber-attacks or other serious events. Job Responsibilities...CyberLive inRemote workFlexible hours
$71k - $95k
...Title: Cyber Engineer II Department: Infosec Revision Date: 5/29... ...tools to support security incident detection, investigation, and response activities. Participate in Incident Response... ...with knowledge of emerging threats, vulnerabilities, and mitigation strategies...CyberRemote work$106.8k - $194.8k
...Firewall (WAF) solutions to protect client applications from cyber threats. You will work within a team of cybersecurity professionals to... ...to uphold the integrity of web applications. You will actively monitor application traffic, analyze security events, and respond...CyberSummer holidayFlexible hours- ...purposes. Perform a detailed cyber risk assessment that includes... ...to assess potential threats or attacks; and Evaluating... ...related roles such as security analyst, network administrator, or similar... ...experience in threat detection, vulnerability/risk assessments...CyberFull timeContract workFor contractorsRemote work
$77.5k - $140.9k
...growingly intricate risks and vulnerabilities. As part of our Cyber Threat and Vulnerability Management (TVM) team you will play a... ...familiarity with frameworks like MITRE ATT&CK to enhance threat detection and response capabilities. To qualify for the role you must...CyberWork experience placementSummer holidayFlexible hours$67.2k - $106.4k
...the requirements and adhere to the related software guidelines. May collaborate with IT Management, Legal, Safety and Security, Cyber Security and Law Enforcement agencies to address identified security vulnerabilities. Create, manage and maintain user security...CyberWork experience placementFlexible hours$102.3k - $185k
...and contribute to the latest cyber standards (NIST, ISO, IEC, and... ...risk assessments, threat modeling, and vulnerability evaluations... ...baselining, and network visibility activities to improve cybersecurity... ...used to support monitoring, detection, and incident response. Preferred...CyberWork at officeLocal areaRemote work$90.3k - $153.52k
...International Trade Compliance Import/Export Analyst You don't see it, but it's there. Our... ...providing innovative solutions in defense electronics. This position offers a motivated... ...range of International Trade Compliance activities that supports the enterprise within BAE...Full timeTemporary workWork at officeLocal areaRelocationFlexible hours$86.5k - $166k
...potential business impact, and help strengthen PwCs ability to prevent, detect, contain, and remediate cyber threats. Those in the Red Team at PwC will focus on simulating realistic adversary activity through full-scope operations, purple teaming, and security...CyberH1bVisa sponsorshipWork visaFlexible hours- ...of contact for employees seeking IT security assistance • Threat detection and incident responses • Performing remote troubleshooting... ...security awareness training and testing Experience: • Compensation : at least 4 years in Cyber security and 8 years in ITCyberRemote work
- ...-on Identity and Access Management (IAM) analyst focused on Privileged Access Management (... ...technologies. Provide technical expertise in threat/risk assessments related to privileged... ...Community / Marketing Title: 9943L Cyber Security Analyst -PAM...Cyber
$93.6k - $148.2k
...Job Number: 7460 External Description: Cyber Security Analyst -IGA Date: Feb 20, 2026 Location: Bethpage, NY,... ...tool technical configurations. Consolidate auditing and activity reporting to address compliance. IGA is a subset of identity...CyberFlexible hours$106.5k - $197.5k
...L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs... ...the space, air, land, sea and cyber domains in the interest of national security... ...and standards. Supports all proposal activities during proposal planning, preparation and...CyberFor subcontractorLocal areaFlexible hours$83.3k - $100.27k
This Senior Analyst position within the Surveillance and Market Intelligence section of Market... ...reviews to identify unusual market activity for evidence of violations of applicable... ...analytics, surveillance tools or processes that detect and deter fraudulent activity,...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start$100.25k - $164.69k
...Optimum! Job Summary As a Senior Cyber Security Analyst, you will play a critical role in... ...support. Stay current on emerging threats, vulnerabilities, and industry trends... ...technologies to enhance the organization's defense mechanisms. Develop and implement...CyberLocal area- ...related to Configuration Management with in IT Infrastructure and Cyber Security. These tasks include but not limited to creating and... ...systems, configurations, identities and databases. • Actively manage (inventory, track and correct) software and hardware assets...Cyber
$127.2k - $246.9k
...KPMG is currently seeking a Manager, Cyber Assessment (Penetration Testing) to join... ...Perform red teaming exercises to assess the detection capabilities of our security operations... ...Experience with common and emerging security threats, scanning tools, and assessment methodologies...CyberH1bLocal area$104.6k - $186k
...Identifies and negotiates schedules, milestones and resources required to meet objectives, primarily through coordinating the activities with other IT departments and Vendors (e.g., database, telecommunications, operations, technical support, etc.). Escalates unresolved...Work experience placementFlexible hours$36.05 - $66.82 per hour
...excellence in everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always in mind, our... ...technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title:...CyberLocal areaRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Detection - Active Defense Analyst. Be the first to apply!
- document review analyst Jericho, NY
- disaster recovery analyst Jericho, NY
- consulting analyst Jericho, NY
- import analyst Jericho, NY
- innovation analyst Jericho, NY
- medicare analyst Jericho, NY
- research and development analyst Jericho, NY
- technology analyst Jericho, NY
- merchandising analyst Jericho, NY
- health analyst Jericho, NY

