Cyber Defense Incident Responder
Ernst & Young
Cyber Defense Incident Responder
Location: Diegem Other locations: Anywhere in Country Salary: Competitive Date: Aug 19, 2026
Job Description
Requisition ID: 1732686 At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently. We have 250,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. Everything from the laptops we use, to the ability to work remotely on our mobile devices and connecting our people and our clients, to enabling hundreds of internal tools and external solutions delivered to our clients. Technology solutions are integrated in the client services we deliver and is key to us being more innovative as an organization. EY Technology supports our technology needs through three business units: Client Technology (CT) - focuses on developing new technology services for our clients. It enables EY to identify new technology-based opportunities faster and pursue those opportunities more rapidly. Enterprise Workplace Technology (EWT) – EWT supports our Core Business Services functions and will deliver fit-for-purpose technology infrastructure at the cheapest possible cost for quality services. EWT will also support our internal technology needs by focusing on a better user experience. Information Security (InfoSec) - InfoSec prevents, detects, responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems.
The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability to anticipate obstacles, and decision-making skills to handle the fast-paced world of cybersecurity incident management. Advanced skills in cybersecurity incident response, incident management, chain-of-custody, forensics, cybersecurity event analysis, and hands-on cybersecurity/digital-forensics skills are required.
Your key responsibilities:
- Coordinate response efforts to cybersecurity incidents caused by external threats that may involve nontraditional working hours
- Serve as a liaison and relationship manager to different businesses and interface with fellow team members and colleagues on other Information Security teams, as well as manage relationships with business partners, management, vendors, and external parties
- Establish, foster, and maintain relationships with General Counsel, Data Privacy/Protection, and Risk Management key contacts
- Drive and manage integration with other corporate incident management programs to ensure consistency and alignment with peer support teams within IT
- Lead process and documentation development and improvements by the Cyber & Investigative Services team
- Develop and document processes to ensure consistent and scalable response operations, and ensure continuous improvement to the firm's global cybersecurity incident response plan
- Collaborate with Cyber Incident Response lead to review team performance and deficiencies in order to identify areas for improvement, as well as institute programs for correction or enhancement
- Draft communications and ensure timely reports/updates to leadership for their own cases and the cases of those reporting to them during and after an event/incident
- Own and manage the team's internal action playbooks and knowledgebase
- Must be willing to be on-call off hours in rotation with other team members (Required)
Skills and attributes for success:
- An very good comprehension of the incident response lifecycle in theory and practice
- The ability to coordinate complex, global cybersecurity incidents from the point of incident declaration through resolution
- Drive cybersecurity incident gap identification and post incident lesson's learned efforts to resolution
- Have comprehensive knowledge in all domains of Information Security and associated technologies in the support of collaboration with partnering teams, eradication, and remediation efforts in support of cybersecurity incidents, and appropriate identification and assignment of gaps identified during response efforts
- Comfortable managing through ambiguity, making thoughtful and sound judgments during stressful environments
- Analyze findings in investigative matters, and develop fact-based reports
- Ability to identify and articulate opportunities for improvement while driving lessons learned activities
- Demonstrate integrity and judgment within a professional environment
- Inquisitive approach to analysis and peer review
- Application of emotional intelligence and calm under pressure
- Ability to appropriately balance work/personal priorities
To qualify for the role, you must have:
- Education: Bachelor's or Master's Degree in Computer Science, Information Systems, Engineering, a related field, or equivalent experience
- Experience: 7+ years' experience in at least two of the following roles: Security Operations Center (SOC) Analyst/Manager (3 years minimum) Cybersecurity Incident Coordinator Cybersecurity Threat Intelligence Cybersecurity Detection Engineering Other relevant Cyber Defense functions Attack & Penetration Testing (Active Defense) eDiscovery or related role performing forensic functions Deep understanding of security threats, vulnerabilities, and incident response Understanding of electronic investigation, forensic tools, and methodologies, including: log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware identification and analysis Be familiar with a basic understanding of legalities surrounding electronic discovery and analysis Understanding of regulatory stipulations regarding security incidents Experience with SIEM technologies (i.e. Splunk, Sentinel) Understanding of both Windows and Unix/Linux based operating systems
- Candidates must hold or be willing to pursue related professional certifications such as GCFE, GCFA, GCIH, CISA, CISM, CISSP, or CCIM
What we look for:
- Demonstrated high level of integrity in a professional environment
- Ability and experienced in working independently
- Have a global mind-set for working with different cultures and backgrounds, while fostering and building lasting relationships
- Knowledgeable in business industry standard security incident response process, procedures, and life-cycle
- Excellent organizational skills and strong attention to detail
- Excellent teaming and management skills
- Excellent social, communication, and writing skills
- Excellent customer service skills required
What we offer you:
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more . Are you ready to shape your future with confidence? Apply today. To help create an equitable and inclusive experience during the recruitment process, please inform us as soon as possible about any disability-related adjustments or accommodations you may need.
- Leidos is seeking an Incident Responder (3rd Shift) to join a mission-focused cybersecurity team supporting the Office of Naval Intelligence at HGCC in Suitland, MD. You will defend Navy networks, respond to incidents, contain systems, and analyze artifacts to aid recovery...CyberWork at officeNight shift
- Leidos is seeking an Incident Responder (2nd Shift) to defend Navy maritime networks. You will handle incident detection, analysis, containment... ...with IC partners to protect TS/SCI environments from cyber threats. The role requires 2nd shift hours (1530-2330) in Suitland...CyberAfternoon shift
- Leidos is seeking an Incident Responder for the Weekend Day Shift to help defend Navy networks from cyber threats at the Hopper Global Communications Center in Suitland, MD. You will handle the full incident response lifecycle across TS/SCI environments and coordinate...CyberShift workWeekend workDay shift
- Resource Management Concepts, Inc. seeks a Cyber Defense Incident Responder (Tier 2) to provide 24/7/365 monitoring and rapid response for government networks. You will conduct in-depth investigations, triage incidents, and manage responses end-to-end in a DoD environment...CyberNight shift
$150k - $297k
...InfoSec) - InfoSec prevents, detects, responds, and mitigates cybersecurity... .... The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will... ...Engineering ~ Other relevant Cyber Defense functions ~ Attack &...CyberSummer holidayLocal areaRemote workFlexible hours$120k - $130k
...protection and preservation of the people and environment of the United States of America. RMC is hiring a dedicated Cyber Defense Incident Responder (Tier 2) to join our team and provide 24/7/365 cybersecurity monitoring and detection for the government enterprise...CyberContract workShift workNight shift- ...Davidson has distinguished itself in the aerospace and missile defense industry with an outstanding reputation for excellence.... ...in defense of our Nation. Davidson is seeking a Cyber Defense Incident Responder (CDIR) in Fort Greely, Alaska. As a CDIR Operator, the...CyberPermanent employmentAll shiftsShift workNight shift
$90k - $125k
...Senior Cybersecurity Incident Response Administrator Entarian is... ...best practices Review Army Cyber Tasking Orders (CTOs),... ...practices Ability to review and respond to Army Cyber Tasking Orders... ...technology leader. From deep space to defense and civilian missions,...Cyber$107.9k - $195.05k
...Description Incident Responder Location: Suitland, MD Clearance: Active TS/SCI... ...maritime intelligence networks against cyber threats. You will respond to and investigate... ...experience in the Computer Network Defense (CND) discipline. Significant professional...CyberWork at officeLocal areaImmediate startShift workDay shift- ...2026 at 5:00 AM STS Systems Defense, LLC (SSD) is a government consulting... ...the U.S. We are seeking an Incident Response Officer (... ...activities. (CDRL A002) Conduct cyber investigations in order to determine... ...Commander. Call emergency responders (Security Forces/Fire...CyberTemporary workWork at officeFlexible hours
$87k - $95k
...Job Description Job Description Incident Responder / Malware Analyst (CSOC Tier 3) Cyber Security Operations Specialist III - CSOC Tier 3 Location: Springfield... ...-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more...CyberFull timeContract work- ...Perks: As recognized members of the Cyber Elite, we work together in partnership... ...are seeking a highly capable Senior Incident Responder / Threat Hunter for a potential opportunity... ...the ability to translate findings into defensive action. The Sr. Incident Responder /...CyberContract workWork experience placement
$125.1k - $225.2k
...is looking for an experienced Incident Response Lead to guide a team performing high-impact cyber investigations and analysis in... ...team’s ability to identify and respond to sophisticated cyber threats... ...for its strong culture of defensive cyber operations, technical excellence...CyberSeasonal workLocal areaWorldwideFlexible hours$107.9k - $195.05k
Incident Responder (Weekend Day Shift) Location: Suitland, MD Clearance: Active TS/SCI Weekend Day... ...maritime intelligence networks against cyber threats. You will respond to and... ...Extensive experience in the Computer Network Defense (CND) discipline. Significant professional...CyberPart timeWork at officeLocal areaImmediate startShift workWeekend workDay shift- Wilson Elser is a leading defense litigation law firm with more than 1400 attorneys in... ...empowered, then we invite you to apply to our Cyber Incident Response Associate Attorney position in... ...breach to individuals and regulators Responding to regulatory investigations arising...CyberWork at officeFlexible hours
$57.2k - $109.4k
...ingenuity for clients across defense, national security, public safety... ...Work The Cybersecurity Incident Response Junior Analyst and... ...lifecycles, common cyber-attacks, and federal incident... ...Actively monitor and respond to cybersecurity incidents related...CyberFull timeWork experience placementLive inWork at officeLocal areaShift work$85k - $95k
Black Kite is the global leader in third‑party cyber risk intelligence, trusted by more than 3,000 organizations worldwide. We give... ...’re in the right place. THE OPPORTUNITY The SOC Analyst / Incident Responder is a mid‑level security operations practitioner who owns...CyberWorldwideFlexible hours- ...Senior Incident Responder As a core member of the Office of Information Security's Detection and Response Team (DaRT), the Senior Incident... ...Responsibilities Serve as the lead responder for validated cyber incidents—prioritizing threats that could impact clinical...CyberPart timeCasual workReliefWork at officeRemote workFlexible hours3 days per week
- ...Operations Center Technical Lead to act as the senior technical authority for SOC watch operations, cyber defense analysis, and threat hunting. The role focuses on incident response leadership and complex investigations to mature DoD-based SOC capabilities. The...Cyber
- ...passionate about leading the frontline defense against today's most sophisticated cyber threats - both known and unknown?... ...then Deloitte's Cyber Detect and Respond team could be the place for you!... ...management, and complex incident investigation, mitigation, and remediation...CyberVisa sponsorship
- G2IT, LLC. is seeking an experienced Incident Responder to join a mission-focused cyber defense team supporting the Office of Naval Intelligence (ONI) at HGCC in Suitland, MD. You will act as a digital first responder to defend maritime intelligence networks and investigate...CyberWork at office
$138k - $209k
AIS (Applied Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats effectively. The candidate will develop strategies, frameworks, and ensure adherence to security protocols, working closely...Cyber- ...Search is seeking a Data, Privacy, and Cybersecurity Associate in Seattle to join a dynamic team handling cyber incident response, crisis management, and regulatory defense. You will advise clients on privacy and cybersecurity regulatory compliance, and represent clients in...Cyber
$94k - $112k
...Title: Incident Manager III SALARY RANGE: $94,000-$112,000 Onsite - 100% Description... ...secure cloud-based engagement kits for cyber incident response and threat hunting... ...threat assessments inform national cyber defense priorities. Eligibility: ~ Must be...CyberContract workLocal area- Staples is seeking a Lead Cyber Security Analyst in Framingham, MA to protect enterprise systems and data. You’ll lead complex threat... ...staff to strengthen our security posture. You will drive incident response, risk assessments, and governance across IT and business...Cyber
- Noblis is seeking a security professional to advance cyber defense programs for federal missions. You will evaluate capabilities, lead improvements, and design incident response playbooks within an agile framework. The role emphasizes cross‑functional collaboration, data...CyberRemote job
- Johnson & Johnson MedTech is seeking a Director, Cyber Defense to lead the global incident response and threat management program. The role is hybrid with locations including Raynham, MA, and alternate hybrid sites. You will own the incident response lifecycle, manage cross...Cyber
- ...yourself: At Bosch, we value values.Shape tomorrow: At Bosch, you change lives.Bosch Cyber Defense has an open position for a passionate, skilled, and experienced cyber forensic and incident response analyst to work as part of the cyber defense team in Pittsburgh, PA, USA....CyberRemote work
$102.5k - $188.9k
Our Deloitte Cyber team understands the unique challenges and opportunities... ...who can identify, analyze, and respond to exploitation activity before... ..., you will support cyber defense efforts by analyzing threat activity, investigating incidents, assessing vulnerabilities, and...CyberWork at office- NewGen Technologies is seeking a Cyber Shift Incident Manager to support a U.S. Government customer onsite in Arlington, VA. You will manage incident data, coordinate triage and resolution, and apply defense in depth principles across enterprise networks. This role requires...CyberShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Defense Incident Responder. Be the first to apply!
- cyber threat intelligence analyst United States
- cyber forensics United States
- cyber sales United States
- cyber insurance United States
- cyber United States
- cyber threat hunter United States
- defense investigator United States
- insurance defense paralegal United States
- defense attorney United States
- defense logistics United States




