EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager

EY

12+ yrs Kochi Full Time Hybrid (office + remote)
EY logo
Posted : today
Actively hiring

Job description

Join EY's Cybersecurity team as a Manager and play a crucial role in delivering advanced Security Operations, Incident Response, Security Orchestration, and Threat Intelligence services. This role supports MSSP and multi-tenant Security Operations Centers (SOC) utilizing platforms like IBM QRadar SIEM, Splunk Enterprise, ELK Stack, IBM SOAR Resilient, and CTM360 Threat Management Platform.

This position is ideal for experienced cybersecurity professionals seeking to leverage their expertise in a dynamic client-facing environment. You will contribute to threat detection, incident response, and overall security posture enhancement across diverse IT and OT ecosystems. Opportunities for cross-training and career advancement are abundant for high-performing individuals.

We are looking for individuals with a passion for cybersecurity operations, a drive for innovation, and a commitment to operational excellence. Your contributions will help build a better working world for our clients and society.

Responsibilities

Manage and administer SIEM platforms (IBM QRadar, Splunk, ELK Stack) including deployment, configuration, and log source integration for IT & OT environments. Develop and tune SIEM correlation rules and dashboards to optimize threat detection and minimize false positives.

Lead security automation initiatives by deploying and configuring SOAR platforms (e.g., IBM SOAR Resilient), designing automated incident response workflows, and developing integrations with various security tools and ticketing systems.

Oversee Threat Intelligence Operations, managing Threat Management Platforms, monitoring external threat exposure, and conducting analysis to identify emerging threats and indicators of compromise (IOCs).

Lead security monitoring, incident response, and threat intelligence activities across multiple client environments, ensuring adherence to SLAs and operational objectives. Coordinate with cross-functional teams during investigations and major incident management.

Qualifications

Possess 12+ years of relevant cybersecurity experience, with hands-on administration of SIEM platforms like IBM QRadar, Splunk, or ELK Stack. Demonstrated experience with IBM SOAR Resilient and security automation technologies is essential.

Solid background in Threat Intelligence Operations, exposure management platforms, and SOC operations, including incident response and threat hunting activities. A strong understanding of IT security monitoring, detection engineering, and incident handling is required.

Proficiency in scripting or programming languages such as Python, PowerShell, or SQL is necessary. Experience working within multi-client or MSSP environments is highly preferred. A B.Tech or M.Tech degree in a related discipline is required.

Essential Skills

IBM QRadarSplunkELK StackIBM SOAR ResilientCTM360CybersecurityIncident ResponseThreat IntelligenceSecurity OperationsSIEMSOAREDRXDRNDRMDRPythonPowerShellSQL

Good to Have

PhantomXSOARCyberArkBitSightRecordedFuture

Highlights

  • Actively hiring

More Details

RoleEY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager
IndustryManagement Consulting, Information Technology & Services, Cybersecurity
DepartmentOperations
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

Management Consulting

EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager at EY | SkillMX | SkillMX