GDS Cyber - Frontier AI Layered Defense Detection and Response - Manager
EY
EY
Shape the future of security operations by leading enterprise clients in their transition to an intelligent, AI-driven, agent-enabled Security Operations Center (SOC).
This pivotal role integrates SOC strategy, platform engineering, and applied AI leadership. Focus on designing and operationalizing cutting-edge agentic AI use cases across SIEM, SOAR, and XDR platforms.
You will steer comprehensive transformation programs from initial assessment and architecture through implementation and optimization. Effective management of both client stakeholders and internal delivery teams is key. This position is instrumental in merging cybersecurity operations with AI innovation, ensuring solutions are practical, scalable, and directly address real-world SOC challenges.
Lead SOC transformation initiatives, emphasizing Agentic AI adoption and defining AI-enabled SOC operating models encompassing people, process, and technology.
Conduct maturity assessments, develop strategic transformation roadmaps, and collaborate with client leadership (CISOs, SOC heads) to align on strategy, value, and desired outcomes.
Architect agentic AI-driven SOC solutions that seamlessly integrate SIEM, SOAR, XDR, and AI platforms. Design and oversee the implementation of AI agents for critical SOC functions like alert triage, investigation enrichment, incident summarization, and automated response orchestration.
Ensure robust integration of Large Language Models (LLMs), Retrieval-Augmented Generation (RAG) pipelines, and contextual data sources into SOC workflows. Guide teams on platform deployment, migration, and optimization.
Identify and implement high-impact AI use cases to boost SOC efficiency and enhance detection quality. Drive the adoption of agentic workflows and multi-agent orchestration patterns, establishing best practices for prompt engineering, context management, and AI governance.
Lead cross-functional teams of SOC engineers, detection engineers, and AI specialists, providing technical mentorship on AI-integrated SOC workflows. Ensure high-quality project delivery, including adherence to timelines, thorough documentation, and achievement of defined outcomes.
Lead client workshops, demonstrations, and executive presentations, effectively translating technical concepts into business outcomes and ROI-driven narratives. Contribute to thought leadership, develop solution accelerators, and create reusable frameworks.
A minimum of 8-12 years of experience in Cybersecurity, SOC Engineering, or Detection & Response, including demonstrated leadership capabilities.
Possess strong expertise in SIEM, SOAR, and XDR platforms such as Microsoft Sentinel/Defender, CrowdStrike, or Splunk. Proven experience in leading SOC transformations, executing platform implementations, or managing large-scale cybersecurity deployments.
Acquire hands-on or applied understanding of AI/LLM use cases within the cybersecurity domain. Experience integrating automation, APIs, and orchestration workflows within SOC environments is essential.
Demonstrate a strong understanding of threat detection methodologies, incident response procedures, and the MITRE ATT&CK framework. The ability to effectively manage client stakeholders and drive strategic conversations is crucial.
EY Global Delivery Services ( EY GDS)
Cybersecurity