Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber SDC - OT - Lead Incident Response Coordinator

$104.8k - $192.2k

Minnesota Jobs

Lead Incident Response Coordinator

At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services.

We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness.

This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.

Incident Command and Coordination

  • Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
  • Establish incident command structure, response rhythm, and clear ownership during active incidents.
  • Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
  • Assign, confirm, and track incident actions through restoration and closure.
  • Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.

Escalation Management

  • Evaluate incident severity, operational impact, and escalation requirements.
  • Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
  • Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
  • Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
  • Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.

Communications Management

  • Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
  • Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
  • Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
  • Support business, site, customer, or leadership communications where required.
  • Ensure incident communications remain factual, concise, and aligned to approved response practices.

Resolution Tracking and Recovery Management

  • Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
  • Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
  • Validate restoration criteria, recovery milestones, and transition back to normal operations.
  • Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
  • Support handoff from active incident response into remediation, problem management, or continuous improvement activities.

Cross-Team Operational Leadership

  • Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
  • Promote consistent incident handling practices across service domains and operational teams.
  • Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
  • Support operational readiness exercises, incident simulations, and tabletop activities as needed.
  • Build familiarity with service dependencies, support models, escalation paths, and response expectations.

Post-Incident Review and Continuous Improvement

  • Coordinate post-incident reviews and lessons-learned discussions for significant incidents.
  • Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
  • Track remediation commitments, action items, and improvement opportunities through completion.
  • Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
  • Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
  • 6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
  • Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
  • Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
  • Ability to coordinate technical teams without directly performing all technical remediation activities.
  • Strong communication, facilitation, documentation, prioritization, and decision-support skills.
  • Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.

Preferred Qualifications

  • Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
  • Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
  • Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
  • Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
  • Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.

Technical Skills

  • Incident Coordination
  • Operational Response
  • Communication & Governance
  • Incident command
  • Service restoration
  • Stakeholder communications
  • Action tracking
  • Escalation management
  • Executive updates
  • Response coordination
  • Cross-domain triage
  • Status reporting
  • Major incident practices
  • Operational dependencies
  • Post-incident reviews
  • Decision logs
  • Support model awareness
  • Playbook improvement

What we offer you

At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.

  • We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today. EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all

Minnesota Jobs
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber SDC - OT - Lead Incident Response Coordinator in Saint Paul, MN vacancy
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined...  ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Saint Paul, MN
    5 days ago
  •  ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions...  ...to route incidents; engage infra/app/cyber/vendor dependencies. Communications...  ...coordination. PIR Support & Improvement: Help lead PIRs; identify recurring patterns;... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Saint Paul, MN
    2 days ago
  • $66.9k - $82.1k

     ...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment...  ...performs detailed technical analysis, coordinates with cross‑functional teams to isolate...  ...platforms integrated with SOC and cyber defense functions. Certifications... 
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Saint Paul, MN
    3 days ago
  •  ...class training facility, and leading market tools, we help our...  ...currently seeking a Manager, Incident Response to join our Advisory practice...  ...ResponsibilitiesLead and manage cyber incident response activities...  ...client incidentsOversee and coordinate incident investigations... 
    Cyber
    Work experience placement
    H1b
    Local area

    KPMG

    Minneapolis, MN
    4 days ago
  • $126.82k - $149.2k

     ...three (3) or more days per week.U.S. Bank is seeking a Cyber Threat Intelligence Lead Analyst to help advance the bank’s cyber defense mission...  ...actions across threat hunting, detection engineering, incident response, vulnerability management, and executive decision-making... 
    Cyber
    Full time
    Local area
    3 days per week

    US Bank

    Minneapolis, MN
    1 day ago
  • $134.5k - $265.1k

    Position Summary Deloitte’s Cyber Services help our clients to...  ...experience in Cyber Incident Response. This role involves supporting...  ...Experience in leading the full lifecycle of Cyber...  ...activities. Review deliverables and coordinate technical sessions to ensure... 
    Cyber
    Local area
    Visa sponsorship

    Deloitte

    Minneapolis, MN
    2 days ago
  •  ...areas of our business, and our global Cyber Investigation and Forensic Response (CIFR) practice is at the heart of...  ...from the most consequential cyber incidents. Within CIFR, our Cyber Recovery...  ...and growing the practice.The Work:Lead enterprise recovery engagements during... 
    Cyber
    Full time
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Minneapolis, MN
    4 days ago
  • $99k - $232k

     ...protecting organisations from cyber threats through advanced technologies...  ...to deliver quality. You are responsible for coaching, leveraging team...  ...our Firm. You are expected to lead with integrity and...  ...Alto PCNSE, CWSP / CWNA- Leading OT/ICS cybersecurity architecture... 
    Cyber
    Full time
    H1b

    PwC

    Minneapolis, MN
    4 days ago
  • $134.5k - $265.1k

     ...Cyber Defense And Resilience Team Member Deloitte's Cyber...  ...extensive experience in Cyber Incident Response. This role involves supporting...  ...: Experience in leading the full lifecycle of Cyber...  ...Review deliverables and coordinate technical sessions to ensure... 
    Cyber
    Visa sponsorship

    Deloitte

    Minneapolis, MN
    4 days ago
  • $102.5k - $210.6k

     .../2026. Work you’ll do As a Lead Cloud Security Analyst, you are...  ...strategic alignment between cyber and infrastructure domains....  ...dynamic business needs. Key Responsibilities Technical Leadership & Advanced...  ...subject matter expert in incident response, vulnerability management... 
    Cyber
    Full time
    Flexible hours
    Shift work

    Deloitte

    Minneapolis, MN
    3 days ago
  • $23 - $26 per hour

     ...Our Passionate Team as a Mental Health Coordinator II (MHC II) - Make a Lasting Impact Every...  ...mission-driven team rooted in respect, response, and choice. Since 1976, we’ve been dedicated...  ...computer skills At least one year of lead staff experience in residential services... 
    Hourly pay
    Full time
    All shifts
    Shift work
    Weekend work

    Socket.dev

    Saint Paul, MN
    2 days ago
  • $200k - $275k

     ...offering property, casualty, professional and cyber insurance coverage for technology companies. Company URL: Responsibilities VP, Field Underwriting serves as the...  ...experience.Travel: FrequentlyDemonstrated success leading underwriting teams at a regional, national,... 
    Cyber
    Full time

    Berkley Technology Services

    Minneapolis, MN
    2 days ago
  •  ...Third‑party or C2C candidates will not be considered Primary Job Function Responsible for investigating, analyzing, and responding to security incidents across the organization’s environment. Leads or executes complex incident response activities, adapts standard... 
    Work experience placement
    Immediate start

    DivIHN Integration Inc

    Saint Paul, MN
    3 days ago
  • $104.8k - $192.2k

     ...External Role Description Role Family OT Field Engineering / Site Implementation...  ...hands‑on field support, infrastructure coordination, troubleshooting, documentation, and support...  ..., and practical OT awareness. Key Responsibilities Site Implementation Support Support site... 
    Cyber
    Summer holiday
    Local area
    Remote work
    Flexible hours

    EY

    Minneapolis, MN
    1 day ago
  •  ...this role:Wells Fargo is seeking a Senior Lead Technology Control Officer to play a...  ...and effectively mitigates operational, cyber, and compliance risks. In this role, you...  ...address regulatory requirementsSpecific responsibilities include:Assessment Strategy & ExecutionDevelop... 
    Cyber
    Full time
    Work experience placement

    Wells Fargo

    Minneapolis, MN
    4 days ago
  • $168.4k - $252.6k

     ...Threat Management is responsible for leading the enterprise detection...  ...Center (SOC), Cyber Threat Intelligence (...  ...Detection Engineering, and Incident Response (IR), and is...  ....Lead major incident coordination, serving as an...  ...operational technology (OT) or industrial control... 
    Cyber
    Hourly pay
    Minimum wage
    Full time
    Local area
    Shift work

    Ecolab

    Saint Paul, MN
    5 days ago
  • $21.63 - $31.25 per hour

     ...Environmental, Health, and Safety (EHS) Coordinator where you will enhance Environmental,...  ...to be an exhaustive list of all responsibilities, duties, and skills required of personnel...  ...such as OSHA/environmental violations, incident rates, employee turnover, workers’ compensation... 
    Hourly pay
    Shift work
    Weekend work

    Smithfield Foods

    Saint Paul, MN
    3 days ago
  • $60k - $93.9k

     ...guidance of more senior staff. Key Responsibilities Administer operating systems, user accounts...  ...compliance with federal and enterprise cyber standards. Configure and manage...  ...issues, escalating complex incidents while working collaboratively toward timely... 
    Cyber
    Contract work
    Work at office
    Remote work

    ASM Research, An Accenture Federal Services Company

    Saint Paul, MN
    5 days ago
  •  ...applications development, infrastructure, Cyber security, and enterprise content/data...  ...as well as a part of this project.Responsibilities included:Deploying Oracle Access Manager...  ...deploys bug fixes.Joining the production incident calls and help the team to resolve the... 
    Cyber

    Comtech

    Minneapolis, MN
    5 days ago
  •  ...are as smart as you are. This role is responsible for designing, implementing, automating,...  ...and public AI and ML/DL systems against cyber threats, adversarial attacks, and data...  ...system activity for anomalies and security incidents. • Develop and enforce policies to... 
    Cyber
    Immediate start
    Remote work
    Flexible hours

    Ford Motor Company

    Saint Paul, MN
    4 days ago
  •  ...Security is a world-leading provider of end-to-end...  ...to digital identity, cyber defense, and response. As part of one of the...  ...the forefront of the incident response and...  ...accuracy Lead and coordinate RFP responses, working...  ...identity, cloud security, OT security, and threat... 
    Cyber

    Minnesota Jobs

    Minneapolis, MN
    5 days ago
  • $100k - $121k

     ...regulatory requirements. Key Responsibilities: Data Classification &...  ...and government contexts. Coordinate and maintain classification...  ...environments. Monitor logs and support Cyber Security use of SIEM tools...  ...compliance violations. Incident Response & Forensics:... 
    Cyber
    Hourly pay
    Contract work

    Minnesota Jobs

    Saint Paul, MN
    1 day ago
  •  ...digital identity, cyber defense, and managed...  ...partnerships with leading technology...  ...expertise across IT and OT environments and the...  ...matter expertise, coordinate project delivery,...  .... Key Responsibilities: Collaborate with...  ...threat modeling, incident response, and recovery... 
    Cyber
    Work experience placement
    Remote work

    Minnesota Jobs

    Minneapolis, MN
    1 day ago
  • $91.1k - $170.4k

     ...detects, responds and mitigates cyber-risk, protecting EY and...  ...Investigative Services (CIS) Junior Incident Coordinator will exercise strong...  ...coordinate security incident response to cybersecurity events or incidents...  ...teams within IT Help lead small to medium sized... 
    Cyber
    Summer holiday
    Remote work
    Flexible hours

    EY

    Minneapolis, MN
    1 day ago
  • $16 - $22 per hour

     ...This position serves as the field team lead and provides functional direction to field...  ...vehicles to vaccination clinics and is responsible for overall performance and operational...  ...difficult customer situations, including pet incidents (bites, reactions and emergency... 
    Hourly pay
    Minimum wage
    Full time
    Work at office
    Local area
    Shift work
    Night shift

    Petco

    Saint Paul, MN
    2 hours ago
  • $79.4k

     ...The Field Office Support Lead manages field IT support operations...  .... The role plans and coordinates technician dispatches, wellness...  ...escalation point for complex incidents. This leader aligns field...  ...customer experience. Key Responsibilities Coordinate field‑support... 
    Contract work
    Work experience placement
    Work at office
    Local area
    Remote work

    ASM Research, An Accenture Federal Services Company

    Saint Paul, MN
    5 days ago
  •  ...Description Description: Position Summary: The Lead Teacher for Academy Adventures is responsible for planning, organizing, and implementing an enriching...  .... Keep accurate records of attendance, incidents, and other necessary documentation Other: Additional... 
    Work at office
    Monday to Friday
    Afternoon shift

    New Life Church of Woodbury

    Saint Paul, MN
    18 days ago
  • $170k - $230k

     ...Networking (Cloud/Network/SASE/OT) security solutions tailored...  ...thought leadership and inspire cyber security solutions powered by...  ...advisor, architect, or engineer responsible for planning, building, and...  ...technical acumen and ability to lead technology focused discussions... 
    Cyber
    Full time
    Work experience placement
    Local area
    Remote work
    Work from home

    Optiv

    Minneapolis, MN
    4 days ago
  • $23.5 - $26 per hour

     ...immersing yourself in creativity and play. Job Responsibilities Our Field Trip Planning team will...  ...details of notable concerns or incidents, and of injuries to campers, staff members...  ...those around you? Are you comfortable leading groups of kids on your own while still... 
    Hourly pay
    Summer work
    Shift work

    Steve & Kate's Camp

    Saint Paul, MN
    3 days ago
  • $112.5k - $187.5k

     ...Information Security Department. The Red Team Leader will primarily be responsible for conducting in-depth threat emulation exercises such as Red...  ...comprehensive threat emulation exercises, actively simulating cyber‑attacks to uncover vulnerabilities in systems, networks, and... 
    Cyber
    Full time
    Temporary work
    Work experience placement
    Local area
    Remote work
    Flexible hours

    TransUnion

    Saint Paul, MN
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber SDC - OT - Lead Incident Response Coordinator. Be the first to apply!