Cyber SDC - OT - Lead Incident Response Coordinator
$104.8k - $218.5kErnst & Young
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Role Description
Role Family
Incident Coordination / Operational Response Leadership
Primary Focus
Incident command, cross-functional coordination, escalation management, communications, and resolution tracking
Seniority
Lead / Senior Individual Contributor
Role Positioning
Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events
PRACTICE DESCRIPTION
Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams.
This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services.
JOB SUMMARY
We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents.
The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness.
Role positioning: This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.
KEY RESPONSIBILITIES
Incident Command and Coordination
- Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
- Establish incident command structure, response rhythm, and clear ownership during active incidents.
- Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
- Assign, confirm, and track incident actions through restoration and closure.
- Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.
Escalation Management
- Evaluate incident severity, operational impact, and escalation requirements.
- Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
- Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
- Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
- Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.
Communications Management
- Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
- Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
- Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
- Support business, site, customer, or leadership communications where required.
- Ensure incident communications remain factual, concise, and aligned to approved response practices.
Resolution Tracking and Recovery Management
- Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
- Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
- Validate restoration criteria, recovery milestones, and transition back to normal operations.
- Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
- Support handoff from active incident response into remediation, problem management, or continuous improvement activities.
Cross-Team Operational Leadership
- Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
- Promote consistent incident handling practices across service domains and operational teams.
- Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
- Support operational readiness exercises, incident simulations, and tabletop activities as needed.
- Build familiarity with service dependencies, support models, escalation paths, and response expectations.
Post-Incident Review and Continuous Improvement
- Coordinate post-incident reviews and lessons-learned discussions for significant incidents.
- Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
- Track remediation commitments, action items, and improvement opportunities through completion.
- Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
- Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.
QUALIFICATIONS
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
- 6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
- Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
- Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
- Ability to coordinate technical teams without directly performing all technical remediation activities.
- Strong communication, facilitation, documentation, prioritization, and decision-support skills.
- Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.
Preferred Qualifications
- Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
- Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
- Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
- Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
- Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.
TECHNICAL SKILLS
| Incident Coordination | Operational Response | Communication & Governance |
| Incident command | Service restoration | Stakeholder communications |
| Action tracking | Escalation management | Executive updates |
| Response coordination | Cross-domain triage | Status reporting |
| Major incident practices | Operational dependencies | Post-incident reviews |
| Decision logs | Support model awareness | Playbook improvement |
WHAT WE OFFER
At EY, we are committed to professional development and career growth. This role provides the opportunity to work across cybersecurity, infrastructure, operations, service management, and managed services teams. The role offers exposure to complex operational environments and the opportunity to improve incident response effectiveness, service restoration, stakeholder communication, and operational resilience.
SHORT STAFFING PROFILE VERSION
Lead Incident Response Coordinator: Serves as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. Leads incident command activities, manages cross-functional response coordination, drives escalation and stakeholder communications, tracks restoration actions, and supports post-incident review and continuous improvement. Focuses on coordination, communications, escalation, and accountability rather than deep technical remediation.
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.
- ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions... ...to route incidents; engage infra/app/cyber/vendor dependencies. Communications... ...coordination. PIR Support & Improvement: Help lead PIRs; identify recurring patterns;...CyberContract workWork experience placementWork at officeShift work
- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined... ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and...CyberContract workWork experience placementWork at officeShift work
- ...seeking an experienced cybersecurity leader to serve as the primary client-facing authority during major incidents. You will oversee multiple concurrent incident response engagements, including ransomware, data breaches, and cloud compromises, while directing forensic...Cyber
- ...connection. We do this by driving Responsible Growth and delivering for our clients... ...us! Job Description: The Security Incident Response Orchestration Lead is the senior technical authority... ...Development Access and Identity Management Cyber Security Information Systems...CyberWork at officeFlexible hoursShift workDay shift
- ...Cybersecurity Team in Denver, CO. The role focuses on advising clients on cybersecurity incidents, regulatory investigations, and risk assessments, with emphasis on incident response and practical business guidance. The position requires 3-6 years of experience in...Cyber
$169.01k - $370.53k
...class training facility, and leading market tools, we help our people... ...seeking a Director, Incident Response to its Advisory Practice.Responsibilities:Lead enterprise cyber incident response engagements... ...AWS, GCP), networking, and IT/OT environmentsDemonstrated success...CyberH1bLocal area$104.8k - $218.5k
...advisory Seniority Senior / Lead Architect Role Positioning Senior OT security architecture advisor... ...governance queue execution. KEY RESPONSIBILITIES Architecture Standards... ...and switching Stakeholder coordination SHORT STAFFING PROFILE VERSION...CyberFull timeSummer holidayRemote workFlexible hours$66.9k - $82.1k
...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment... ...performs detailed technical analysis, coordinates with cross-functional teams to isolate... ...platforms integrated with SOC and cyber defense functions. Certifications...CyberContract workWork experience placementWork at office- ...sounds appealing to you, then consider our OT Cybersecurity Engineer - Mid Level... ...for OT environments, perform cyber assessments, response plans, policies and procedures, cyber... ...Policies and Procedures for clients.Develop Incident Response Plans, Disaster Recovery Plans...CyberWork at officeLocal areaRemote work
$95.7k - $144.9k
...connection. We do this by driving Responsible Growth and delivering for our... ...is one of the world’s leading financial institutions, serving... ...only possible with a strong cyber defense, which enables Bank of... ...candidates with malware analysis and incident response experience. •...CyberFull timeWork at officeFlexible hoursDay shift- ...Responsibilities Serve as the primary client-facing leader during major cybersecurity incidents. Lead multiple concurrent incident response engagements... ..., threat hunting, or cyber defense operations. Demonstrated... ...technical staff, and coordinating cross-functional...Cyber
$85k - $95k
...Security Analyst to bolster the security of their global operations. The role requires expertise in Microsoft security platforms, incident response, and collaboration across teams. With a competitive salary between $85,000 and $95,000, this position also offers a 10% annual...- ...monitor IT systems, perform risk assessments, and respond to cyber threats. Responsible for implementing security controls and maintaining system... ...salary and the opportunity to be part of an industry-leading team dedicated to safeguarding the community's health and...Cyber
- OmniTRAX, Inc. is seeking a Cyber Security Analyst to operate and improve cybersecurity technologies, policies, and controls. You will monitor security events, investigate incidents, and support vulnerability remediation while collaborating with IT, applications, and business...Cyber
$110.8k - $226.4k
...play a pivotal role in leading teams, guiding... ...quality delivery. As your responsibilities expand, you take on broader... .... The Incident Response Manager serves... ...client deliverables. Coordinate internal and external... ..., threat hunting, or cyber defense operations....CyberLocal areaWorldwide- ...Electronics is seeking an Information Technology Manager II to lead complex cyber incident investigations across enterprise, cloud, hybrid, and on‑prem environments. You will perform end-to-end incident response, DFIR activities, threat hunting, and detection engineering,...CyberRemote job
$125.1k - $152.9k
...evolving industry. As an Advisor III, OT Cyber Security , you will play a key role... ...control systems and OT networks. Plan, coordinate, and execute network maintenance and... ...plans ~ Familiarity with OT/IT Incident Response and Disaster Recovery Plans ~ Familiarity...CyberPermanent employmentFull timeTemporary workAfternoon shift$134.5k - $265.1k
Position Summary Deloitte’s Cyber Services help our clients to... ...experience in Cyber Incident Response. This role involves supporting... ...Experience in leading the full lifecycle of Cyber... ...activities. Review deliverables and coordinate technical sessions to ensure...CyberLocal areaVisa sponsorship$141.6k - $212.4k
...to our growing Detection and Response (D&R) Team. This is a hands-on... ...efficient querying during incidents.Develop high-fidelity rule-based... ...to security alerts, cyber threats, and security incidents... ...and industry events. Travel is coordinated in advance.Get to Know KlaviyoWe...Cyber- (EDO) Entertainment Data Oracle, Inc. is seeking a motivated Senior Cyber Security Analyst to join our team in Colorado. This role involves monitoring and analyzing systems to identify and respond to cybersecurity threats. The ideal candidate will possess 5+ years in cybersecurity...CyberFlexible hours
$55.7k - $82.1k
...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives...Contract workWork at officeShift work$125k - $175k
The OT Network Project Technical Lead provides technical leadership for the design, implementation, integration... ...readiness activities.Primary Responsibilities:Lead OT network projects from... ...Cybersecurity Certificate, Global Industrial Cyber Security Professional (GICSP),...CyberWork at officeLocal areaRemote work$102.5k - $210.6k
.../2026. Work you’ll do As a Lead Cloud Security Analyst, you are... ...strategic alignment between cyber and infrastructure domains.... ...dynamic business needs. Key Responsibilities Technical Leadership & Advanced... ...subject matter expert in incident response, vulnerability management...CyberFull timeFlexible hoursShift work$104.8k - $218.5k
...External Role Description Role Family OT Field Engineering / Site Implementation... ...hands-on field support, infrastructure coordination, troubleshooting, documentation, and... ..., and practical OT awareness. KEY RESPONSIBILITIES Site Implementation Support...CyberFull timeSummer holidayLocal areaRemote workFlexible hours$140k - $200k
...connection. We do this by driving Responsible Growth and delivering for... ...: The Transformation Lead – Response and Recovery is a... ...maturity across the organization's cyber incident response, cyber resiliency,... ..., recovery validation, and coordination workflows. Leverage AI,...CyberFull timeWork at officeFlexible hoursShift workDay shift$24.9 per hour
...So, join us. Work with us. Grow with us. The core responsibilities of the role include: Leading team workload distribution, driving goal achievement,... ...and long sleeves in the warehouse. * Position: Group Coordinator Lead Shift: 1st Shift Hours: 6:30am-6:30pm...Shift workDay shift$132.23k - $176.31k
...has an opening for a Senior Lead Security Engineer that will leverage... ...times per month. The Main Responsibilities Research latest threat... ...detection. Work with cyber operators, when requested, to... ...Support customer RFIs on incidents and emerging threats. Use...CyberFull timeTemporary workWork experience placementWork at officeRemote work$105.79k - $141.05k
...Lotus Labs has an opening for a Lead Information Security Engineer... ...in the US. The Main Responsibilities Research attacker tools, techniques... ...detection. Work with cyber operators and senior... ...Support customer RFIs on incidents and emerging threats with guidance...CyberFull timeTemporary workWork experience placementRemote workWork from home$105k - $145k
Senior Cyber Security Specialist — Denver, Colorado (Hybrid)Location: Denver, COWork Model... ...IT and operational technology (OT) environments, including solar infrastructure... ...identifying vulnerabilities, supporting incident response activities, and ensuring compliance with...CyberWork at officeLocal areaRemote workMonday to Friday$135k - $217.1k
...every connection. We do this by driving Responsible Growth and delivering for our clients, teammates... ...Global Information Security (GIS). Cyber Security Technology (CST) is a globally distributed... ...Release/Solution Train Engineer Delivery Lead Architect/Senior Architect Senior/...CyberFull timeWork at officeFlexible hoursShift workDay shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber SDC - OT - Lead Incident Response Coordinator. Be the first to apply!
- cybersecurity manager Denver, CO
- cyber security lead Denver, CO
- director - cyber security Denver, CO
- document control coordinator Denver, CO
- seo coordinator Denver, CO
- mental health coordinator Denver, CO
- wedding coordinator Denver, CO
- travel coordinator Denver, CO
- website coordinator Denver, CO
- work from home travel coordinator Denver, CO



