Cyber SDC - OT - Lead Incident Response Coordinator
Job description
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Role Description
|
Role Family |
Incident Coordination / Operational Response Leadership |
|
Primary Focus |
Incident command, cross-functional coordination, escalation management, communications, and resolution tracking |
|
Seniority |
Lead / Senior Individual Contributor |
|
Role Positioning |
Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events |
PRACTICE DESCRIPTION
Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams.
This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services.
JOB SUMMARY
We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents.
The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness.
Role positioning: This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.
KEY RESPONSIBILITIES
Incident Command and Coordination
- Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
- Establish incident command structure, response rhythm, and clear ownership during active incidents.
- Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
- Assign, confirm, and track incident actions through restoration and closure.
- Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.
Escalation Management
- Evaluate incident severity, operational impact, and escalation requirements.
- Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
- Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
- Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
- Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.
Communications Management
- Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
- Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
- Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
- Support business, site, customer, or leadership communications where required.
- Ensure incident communications remain factual, concise, and aligned to approved response practices.
Resolution Tracking and Recovery Management
- Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
- Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
- Validate restoration criteria, recovery milestones, and transition back to normal operations.
- Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
- Support handoff from active incident response into remediation, problem management, or continuous improvement activities.
Cross-Team Operational Leadership
- Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
- Promote consistent incident handling practices across service domains and operational teams.
- Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
- Support operational readiness exercises, incident simulations, and tabletop activities as needed.
- Build familiarity with service dependencies, support models, escalation paths, and response expectations.
Post-Incident Review and Continuous Improvement
- Coordinate post-incident reviews and lessons-learned discussions for significant incidents.
- Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
- Track remediation commitments, action items, and improvement opportunities through completion.
- Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
- Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.
QUALIFICATIONS
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
- 6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
- Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
- Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
- Ability to coordinate technical teams without directly performing all technical remediation activities.
- Strong communication, facilitation, documentation, prioritization, and decision-support skills.
- Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.
Preferred Qualifications
- Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
- Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
- Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
- Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
- Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.
TECHNICAL SKILLS
|
Incident Coordination |
Operational Response |
Communication & Governance |
|
Incident command |
Service restoration |
Stakeholder communications |
|
Action tracking |
Escalation management |
Executive updates |
|
Response coordination |
Cross-domain triage |
Status reporting |
|
Major incident practices |
Operational dependencies |
Post-incident reviews |
|
Decision logs |
Support model awareness |
Playbook improvement |
WHAT WE OFFER
At EY, we are committed to professional development and career growth. This role provides the opportunity to work across cybersecurity, infrastructure, operations, service management, and managed services teams. The role offers exposure to complex operational environments and the opportunity to improve incident response effectiveness, service restoration, stakeholder communication, and operational resilience.
SHORT STAFFING PROFILE VERSION
Lead Incident Response Coordinator: Serves as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. Leads incident command activities, manages cross-functional response coordination, drives escalation and stakeholder communications, tracks restoration actions, and supports post-incident review and continuous improvement. Focuses on coordination, communications, escalation, and accountability rather than deep technical remediation.
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.
Nearest Major Market: Chicago