Government and Public Sector - Cybersecurity Defense Responder Manager
EYAbout the role
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
From strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government shape the future with confidence.
The opportunity
Our cybersecurity professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team works together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases operate integrated security operations for our clients.
We will support you with career-long training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with the best of the best in a collaborative environment. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.
Your key responsibilities
Our security professionals possess diverse industry knowledge, unique technical expertise, and specialized skills. The team stays highly relevant by researching and discovering the newest security vulnerabilities, attending and speaking at top security conferences, and sharing knowledge with key industry groups. The team frequently provides thought leadership and information exchanges through traditional and less conventional communication channels, including conference presentations, white papers, and blogs.
As part of our Blue Team, you will focus on proactive cyber defense, threat detection, security monitoring, and intelligence-driven defense to protect enterprise environments. Your work will include real-time security event analysis, security automation, incident response support, forensic investigations, and adversary simulation collaboration with Red and Purple Teams. You will also leverage cyber threat intelligence (CTI) to improve detection engineering, threat hunting methodologies, and defense strategies.
Our professionals work together in planning, executing, and managing engagements to assess, improve, build, and, in some cases, operate integrated security operations for our clients.
Skills and attributes for success
- Conduct real-time security monitoring, log analysis, and threat detection using SIEM tools such as Splunk, Elastic, Microsoft Sentinel, CrowdStrike NG-SIEM, and Palo Alto Cortex.
- Perform threat hunting and anomaly detection by analyzing security event data and network traffic for malicious activity.
- Integrate cyber threat intelligence (CTI) into detection methodologies, correlating indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) to strengthen defenses.
- Respond to cybersecurity incidents, conduct forensic investigations, and provide mitigation recommendations.
- Develop and fine-tune detection rules, alerts, and use cases for monitoring tools to improve incident detection and response.
- Conduct malware analysis, reverse engineering, and threat intelligence correlation to improve defensive strategies.
- Work closely with Red and Purple Teams to simulate adversary tactics, improve detection efficacy, and test security defenses in adversary emulation exercises.
- Provide guidance on security best practices, hardening techniques, and zero-trust architectures.
- Automate security operations and develop playbooks using SOAR platforms to improve response efficiency.
- Conduct security assessments and assist with compliance efforts for industry standards such as MITRE ATT&CK, NIST 800-53, ISO 27001, and CIS Benchmarks.
To qualify for the role you must have
- Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field, and a minimum of 5 years of related work experie
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s