Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber SDC - OT - Lead Incident Response Coordinator

$104.8k - $218.5k
Full-time

Ernst & Young

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Role Description

Role Family

Incident Coordination / Operational Response Leadership

Primary Focus

Incident command, cross-functional coordination, escalation management, communications, and resolution tracking

Seniority

Lead / Senior Individual Contributor

Role Positioning

Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events

PRACTICE DESCRIPTION

Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams.

This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services.

JOB SUMMARY

We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents.

The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness.

Role positioning: This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.

KEY RESPONSIBILITIES

Incident Command and Coordination

  • Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
  • Establish incident command structure, response rhythm, and clear ownership during active incidents.
  • Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
  • Assign, confirm, and track incident actions through restoration and closure.
  • Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.

Escalation Management

  • Evaluate incident severity, operational impact, and escalation requirements.
  • Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
  • Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
  • Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
  • Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.

Communications Management

  • Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
  • Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
  • Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
  • Support business, site, customer, or leadership communications where required.
  • Ensure incident communications remain factual, concise, and aligned to approved response practices.

Resolution Tracking and Recovery Management

  • Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
  • Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
  • Validate restoration criteria, recovery milestones, and transition back to normal operations.
  • Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
  • Support handoff from active incident response into remediation, problem management, or continuous improvement activities.

Cross-Team Operational Leadership

  • Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
  • Promote consistent incident handling practices across service domains and operational teams.
  • Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
  • Support operational readiness exercises, incident simulations, and tabletop activities as needed.
  • Build familiarity with service dependencies, support models, escalation paths, and response expectations.

Post-Incident Review and Continuous Improvement

  • Coordinate post-incident reviews and lessons-learned discussions for significant incidents.
  • Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
  • Track remediation commitments, action items, and improvement opportunities through completion.
  • Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
  • Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.

QUALIFICATIONS

  • Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
  • 6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
  • Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
  • Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
  • Ability to coordinate technical teams without directly performing all technical remediation activities.
  • Strong communication, facilitation, documentation, prioritization, and decision-support skills.
  • Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.

Preferred Qualifications

  • Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
  • Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
  • Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
  • Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
  • Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.

TECHNICAL SKILLS

Incident Coordination

Operational Response

Communication & Governance

Incident command

Service restoration

Stakeholder communications

Action tracking

Escalation management

Executive updates

Response coordination

Cross-domain triage

Status reporting

Major incident practices

Operational dependencies

Post-incident reviews

Decision logs

Support model awareness

Playbook improvement

WHAT WE OFFER

At EY, we are committed to professional development and career growth. This role provides the opportunity to work across cybersecurity, infrastructure, operations, service management, and managed services teams. The role offers exposure to complex operational environments and the opportunity to improve incident response effectiveness, service restoration, stakeholder communication, and operational resilience.

SHORT STAFFING PROFILE VERSION

Lead Incident Response Coordinator: Serves as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. Leads incident command activities, manages cross-functional response coordination, drives escalation and stakeholder communications, tracks restoration actions, and supports post-incident review and continuous improvement. Focuses on coordination, communications, escalation, and accountability rather than deep technical remediation.

What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.


EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber SDC - OT - Lead Incident Response Coordinator in Denver, CO vacancy
  •  ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions...  ...to route incidents; engage infra/app/cyber/vendor dependencies. Communications...  ...coordination. PIR Support & Improvement: Help lead PIRs; identify recurring patterns;... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Denver, CO
    1 day ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined...  ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Denver, CO
    5 days ago
  •  ...seeking an experienced cybersecurity leader to serve as the primary client-facing authority during major incidents. You will oversee multiple concurrent incident response engagements, including ransomware, data breaches, and cloud compromises, while directing forensic... 
    Cyber

    Jobtailor

    Denver, CO
    5 days ago
  •  ...connection. We do this by driving Responsible Growth and delivering for our clients...  ...us! Job Description: The Security Incident Response Orchestration Lead is the senior technical authority...  ...Development Access and Identity Management Cyber Security Information Systems... 
    Cyber
    Work at office
    Flexible hours
    Shift work
    Day shift

    Koitecc Solutions

    Denver, CO
    3 days ago
  •  ...Cybersecurity Team in Denver, CO. The role focuses on advising clients on cybersecurity incidents, regulatory investigations, and risk assessments, with emphasis on incident response and practical business guidance. The position requires 3-6 years of experience in... 
    Cyber

    BCG Attorney Search

    Denver, CO
    1 day ago
  • $169.01k - $370.53k

     ...class training facility, and leading market tools, we help our people...  ...seeking a Director, Incident Response to its Advisory Practice.Responsibilities:Lead enterprise cyber incident response engagements...  ...AWS, GCP), networking, and IT/OT environmentsDemonstrated success... 
    Cyber
    H1b
    Local area

    KPMG

    Denver, CO
    1 day ago
  • $104.8k - $218.5k

     ...advisory Seniority Senior / Lead Architect Role Positioning Senior OT security architecture advisor...  ...governance queue execution. KEY RESPONSIBILITIES Architecture Standards...  ...and switching Stakeholder coordination SHORT STAFFING PROFILE VERSION... 
    Cyber
    Full time
    Summer holiday
    Remote work
    Flexible hours

    EY

    Denver, CO
    3 days ago
  • $66.9k - $82.1k

     ...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment...  ...performs detailed technical analysis, coordinates with cross-functional teams to isolate...  ...platforms integrated with SOC and cyber defense functions. Certifications... 
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Denver, CO
    3 days ago
  •  ...sounds appealing to you, then consider our OT Cybersecurity Engineer - Mid Level...  ...for OT environments, perform cyber assessments, response plans, policies and procedures, cyber...  ...Policies and Procedures for clients.Develop Incident Response Plans, Disaster Recovery Plans... 
    Cyber
    Work at office
    Local area
    Remote work

    Tetra Tech

    Denver, CO
    2 days ago
  • $95.7k - $144.9k

     ...connection. We do this by driving Responsible Growth and delivering for our...  ...is one of the world’s leading financial institutions, serving...  ...only possible with a strong cyber defense, which enables Bank of...  ...candidates with malware analysis and incident response experience. •... 
    Cyber
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Denver, CO
    4 days ago
  •  ...Responsibilities Serve as the primary client-facing leader during major cybersecurity incidents. Lead multiple concurrent incident response engagements...  ..., threat hunting, or cyber defense operations. Demonstrated...  ...technical staff, and coordinating cross-functional... 
    Cyber

    Jobtailor

    Denver, CO
    4 hours ago
  • $85k - $95k

     ...Security Analyst to bolster the security of their global operations. The role requires expertise in Microsoft security platforms, incident response, and collaboration across teams. With a competitive salary between $85,000 and $95,000, this position also offers a 10% annual... 

    Leprino Foods

    Denver, CO
    3 days ago
  •  ...monitor IT systems, perform risk assessments, and respond to cyber threats. Responsible for implementing security controls and maintaining system...  ...salary and the opportunity to be part of an industry-leading team dedicated to safeguarding the community's health and... 
    Cyber

    Metro Water Recovery

    Denver, CO
    2 days ago
  • OmniTRAX, Inc. is seeking a Cyber Security Analyst to operate and improve cybersecurity technologies, policies, and controls. You will monitor security events, investigate incidents, and support vulnerability remediation while collaborating with IT, applications, and business... 
    Cyber

    OmniTRAX, Inc.

    Denver, CO
    4 days ago
  • $110.8k - $226.4k

     ...play a pivotal role in leading teams, guiding...  ...quality delivery. As your responsibilities expand, you take on broader...  .... The Incident Response Manager serves...  ...client deliverables. Coordinate internal and external...  ..., threat hunting, or cyber defense operations.... 
    Cyber
    Local area
    Worldwide

    Crowe

    Denver, CO
    5 days ago
  •  ...Electronics is seeking an Information Technology Manager II to lead complex cyber incident investigations across enterprise, cloud, hybrid, and on‑prem environments. You will perform end-to-end incident response, DFIR activities, threat hunting, and detection engineering,... 
    Cyber
    Remote job

    Arrow ECS

    Englewood, CO
    1 day ago
  • $125.1k - $152.9k

     ...evolving industry. As an Advisor III, OT Cyber Security , you will play a key role...  ...control systems and OT networks. Plan, coordinate, and execute network maintenance and...  ...plans ~ Familiarity with OT/IT Incident Response and Disaster Recovery Plans ~ Familiarity... 
    Cyber
    Permanent employment
    Full time
    Temporary work
    Afternoon shift

    Phillips 66

    Commerce City, CO
    12 days ago
  • $134.5k - $265.1k

    Position Summary Deloitte’s Cyber Services help our clients to...  ...experience in Cyber Incident Response. This role involves supporting...  ...Experience in leading the full lifecycle of Cyber...  ...activities. Review deliverables and coordinate technical sessions to ensure... 
    Cyber
    Local area
    Visa sponsorship

    Deloitte

    Denver, CO
    2 days ago
  • $141.6k - $212.4k

     ...to our growing Detection and Response (D&R) Team. This is a hands-on...  ...efficient querying during incidents.Develop high-fidelity rule-based...  ...to security alerts, cyber threats, and security incidents...  ...and industry events. Travel is coordinated in advance.Get to Know KlaviyoWe... 
    Cyber

    Klaviyo

    Denver, CO
    3 days ago
  • (EDO) Entertainment Data Oracle, Inc. is seeking a motivated Senior Cyber Security Analyst to join our team in Colorado. This role involves monitoring and analyzing systems to identify and respond to cybersecurity threats. The ideal candidate will possess 5+ years in cybersecurity... 
    Cyber
    Flexible hours

    (EDO) Entertainment Data Oracle, Inc.

    Aurora, CO
    1 day ago
  • $55.7k - $82.1k

     ...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives... 
    Contract work
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Denver, CO
    5 days ago
  • $125k - $175k

    The OT Network Project Technical Lead provides technical leadership for the design, implementation, integration...  ...readiness activities.Primary Responsibilities:Lead OT network projects from...  ...Cybersecurity Certificate, Global Industrial Cyber Security Professional (GICSP),... 
    Cyber
    Work at office
    Local area
    Remote work

    Tetra Tech

    Denver, CO
    5 days ago
  • $102.5k - $210.6k

     .../2026. Work you’ll do As a Lead Cloud Security Analyst, you are...  ...strategic alignment between cyber and infrastructure domains....  ...dynamic business needs. Key Responsibilities Technical Leadership & Advanced...  ...subject matter expert in incident response, vulnerability management... 
    Cyber
    Full time
    Flexible hours
    Shift work

    Deloitte

    Denver, CO
    4 days ago
  • $104.8k - $218.5k

     ...External Role Description Role Family OT Field Engineering / Site Implementation...  ...hands-on field support, infrastructure coordination, troubleshooting, documentation, and...  ..., and practical OT awareness. KEY RESPONSIBILITIES Site Implementation Support... 
    Cyber
    Full time
    Summer holiday
    Local area
    Remote work
    Flexible hours

    EY

    Denver, CO
    3 days ago
  • $140k - $200k

     ...connection. We do this by driving Responsible Growth and delivering for...  ...: The Transformation Lead – Response and Recovery is a...  ...maturity across the organization's cyber incident response, cyber resiliency,...  ..., recovery validation, and coordination workflows. Leverage AI,... 
    Cyber
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Denver, CO
    4 days ago
  • $24.9 per hour

     ...So, join us. Work with us. Grow with us. The core responsibilities of the role include: Leading team workload distribution, driving goal achievement,...  ...and long sleeves in the warehouse. * Position: Group Coordinator Lead Shift: 1st Shift Hours: 6:30am-6:30pm... 
    Shift work
    Day shift

    DPDHL

    Aurora, CO
    4 days ago
  • $132.23k - $176.31k

     ...has an opening for a Senior Lead Security Engineer that will leverage...  ...times per month. The Main Responsibilities Research latest threat...  ...detection. Work with cyber operators, when requested, to...  ...Support customer RFIs on incidents and emerging threats. Use... 
    Cyber
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work

    Lumen

    Aurora, CO
    4 days ago
  • $105.79k - $141.05k

     ...Lotus Labs has an opening for a Lead Information Security Engineer...  ...in the US. The Main Responsibilities Research attacker tools, techniques...  ...detection. Work with cyber operators and senior...  ...Support customer RFIs on incidents and emerging threats with guidance... 
    Cyber
    Full time
    Temporary work
    Work experience placement
    Remote work
    Work from home

    Lumen

    Denver, CO
    3 days ago
  • $105k - $145k

    Senior Cyber Security Specialist — Denver, Colorado (Hybrid)Location: Denver, COWork Model...  ...IT and operational technology (OT) environments, including solar infrastructure...  ...identifying vulnerabilities, supporting incident response activities, and ensuring compliance with... 
    Cyber
    Work at office
    Local area
    Remote work
    Monday to Friday

    Lightsource bp

    Denver, CO
    3 days ago
  • $135k - $217.1k

     ...every connection. We do this by driving Responsible Growth and delivering for our clients, teammates...  ...Global Information Security (GIS). Cyber Security Technology (CST) is a globally distributed...  ...Release/Solution Train Engineer Delivery Lead Architect/Senior Architect Senior/... 
    Cyber
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Denver, CO
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber SDC - OT - Lead Incident Response Coordinator. Be the first to apply!