Government and Public Sector - Cybersecurity Operations & Threat Detection Response - Senior Manager
EYAbout the role
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Government and Public Sector – Cybersecurity – Security Operations & Threat Detection and Response – Senior Manager
From strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government shape the future with confidence.
The opportunity
As a Senior Manager in Security Operations & Threat Detection and Response within EY’s Government & Public Sector (GPS) practice, you will lead the strategy, design, transformation, and operation of mission‑critical Security Operations Centers (SOCs) for federal, state, local, and education clients.
This role blends strategic cybersecurity advisory, operational leadership, and business development ownership in classified and highly regulated environments, up to the Top Secret (TS) level. You will lead large, complex engagements supported by cleared delivery teams, serve as a trusted advisor to senior government stakeholders, and act as a primary driver of revenue growth for EY’s GPS Threat Detection & Response offerings. You will be accountable for originating opportunities, leading pursuits, shaping solutions, and expanding long‑term client relationships—while remaining deeply engaged in delivery excellence and execution.
This role is expected to lead the modernization of government security operations through AI‑enabled analytics, automation‑driven workflows, and XDR‑led telemetry unification across hybrid and multi‑cloud environments. The Senior Manager will be accountable for transforming traditional SOC models into metrics‑driven, outcome‑oriented operations that improve detection fidelity, reduce response time, and operationalize compliance at scale across mission‑critical federal programs.
Your key responsibilities
- Define and drive security operations strategies and target operating models aligned to agency missions, risk tolerance, and regulatory mandates.
- Design and implement SOC operating models that support cleared, U.S.-based delivery in environments up to the TS level, hybrid architectures, and follow‑the‑sun coverage where permissible.
- Own engagement delivery outcomes, ensuring services meet EY quality standards, contractual SLAs, and government client expectations.
- Contribute to the development of EY GPS and global cybersecurity methodologies, assets, and accelerators in Threat Detection & Response.
- Lead the design and operation of AI‑enabled and automation‑driven SOC capabilities, including agent‑based workflows and advanced analytics that accelerate alert triage, enrichment, and response.
- Drive XDR‑led detection strategies, unifying telemetry across EDR, NDR, SIEM, identity, cloud, and SaaS platforms into a coherent and prioritized threat detection model.
- Oversee multi‑cloud and hybrid SOC architectures, integrating Azure, AWS, and on‑prem environments into centralized detection and response operations.
- Own security operations performance metrics, including MTTD, MTTR, dwell time, alert fidelity, and automation coverage, using these KPIs to drive continuous improvement and executive‑level reporting.
- Establish fusion across adjacent operational domains, including vulnerability management, identity security, data protection, and threat intelligence, reflecting how GPS programs are funded, governed, and measured.
- Oversee day‑to‑day SOC operations supporting classified (up to TS) and unclassified environments, including:
- Threat monitoring, alert triage, and escalation
- Incident containment, eradication, and recover
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s