Cyber Triage And Forensic Junior Analyst
EY
EY
Join EY's global team as a Junior Security Analyst specializing in Cyber Triage and Forensics (CTF). This role offers a unique opportunity to safeguard EY and client information assets in a world driven by data. You'll be part of a dynamic Information Security team, blending risk strategy, digital identity, cyber defense, and technology solutions to protect our business and build client trust.
As a member of the Cyber Defense Response Center, you'll contribute to monitoring and detecting information security events, aligning with incident response and attack lifecycles. This position provides exposure to cutting-edge technologies and security tools, alongside significant career growth opportunities and training to enhance your expertise.
Engage in real-time monitoring and precise analysis of logs and alerts from various security devices, focusing on identifying security incidents. Collaborate with the team to detect and respond to security incidents, develop and maintain alert procedures, and participate in thorough investigations. Competently work at a technical level to identify threats and vectors, and execute defined procedures for mitigation. Respond to network and host-based security events, participate in detecting, investigating, and resolving security incidents, and identify improvement areas within the Cyber Defense Response Center. Provide documentation and project support, acting as an escalation point for complex issues, and potentially serving as a shift lead. Conduct detailed analysis of network traffic and host-based attributes to identify security incidents, and provide feedback on security control gaps based on intrusion trends. Develop and maintain analytical procedures to enhance security incident identification efficiency and drive process improvements.
A foundational understanding of Information Security Principles, Technologies, and Practices is essential. Experience with multiple security event detection platforms and a fair grasp of Linux, TCP/IP, Network Security, and encryption standards are required. Familiarity with attack types (e.g., DoS, DDoS), basic IDS/IPS rules, and security log analysis is expected. Knowledge of penetration testing and application testing methodologies is a plus, as is comfort navigating and troubleshooting Linux and Windows systems. Demonstrated ability to work independently, possess excellent written and verbal communication, presentation, investigative, analytical, and problem-solving skills, alongside the capacity to collaborate effectively within a team using initiative and minimal supervision. Minimum of 1-2 years of experience in a Security Monitoring/SOC environment, investigating security events, threats, or vulnerabilities, with proficiency in intrusion detection platforms and Linux/Windows systems administration (including AD). Experience with scripting or programming languages (Shell, PowerShell, C, C#, Java) is also required. An Undergraduate or Postgraduate Degree in Computer Science, Engineering, or a related domain (MCA/MTech/BTech/BCA /BSc CS or BSc IT) is necessary.
EY Global Delivery Services ( EY GDS)
Accounting