GMS-Manager-Incident Response

EY

8+ yrs Bengaluru Full Time Hybrid (office + remote)
EY logo
Posted : 3 Sept 2026

Job description

Embark on a fulfilling career journey at EY, where global scale, supportive culture, and cutting-edge technology empower you to achieve your full potential. Your unique perspective is invaluable in shaping EY's future and contributing to a better working world.

As part of our dynamic cybersecurity operations team, you'll collaborate with brilliant minds in cyber security, driving impactful solutions for clients. Your contributions will resonate with individuals, businesses, and nations, fostering confidence in an increasingly connected world. This fast-paced environment offers continuous opportunities for learning and professional growth.

Responsibilities

As the Security Operations Center (SOC) Incident Response Manager, you will lead the charge on complex and critical security incidents, leveraging multiple security technologies to enhance team efficiency and collaborative threat response. You will be integral to our 24/7 incident detection and response operations.

Key duties include: - Orchestrating responses to high-severity incidents, ensuring seamless coordination across teams. - Preserving evidence, collecting data, and conducting structured forensic analysis, presenting findings clearly to stakeholders. - Collaborating with IT and security teams to effectively address security incidents. - Conducting in-depth investigations to pinpoint the root cause of incidents. - Analyzing packet captures using tools like Wireshark and TCPdump. - Performing endpoint analysis, live response, and memory collection/analysis. - Proactively identifying threats and vulnerabilities within the environment. - Staying abreast of the latest security trends, threats, and technologies, and analyzing threat intelligence for risk identification. - Developing robust response and recovery strategies for security incidents. - Refining incident response processes and playbooks. - Meticulously documenting incidents, actions taken, and lessons learned. - Preparing comprehensive incident reports and executive summaries. - Leading incident response calls and post-incident reviews to assess effectiveness and identify improvements. - Mentoring and guiding fellow incident responders.

Qualifications

To excel in this role, you should possess demonstrable experience with digital forensics tools and techniques for incident investigation. Proficiency in utilizing SIEM solutions such as Splunk, Microsoft Sentinel, LogScale, Google Chronicle, or IBM QRadar is essential for effective incident analysis.

You should also be experienced with EDR/XDR platforms like CrowdStrike, Microsoft Defender, SentinelOne, Cortex XSIAM, or Carbon Black. A solid understanding of fundamental security principles, techniques, and technologies, including SANS Top 20 Critical Security Controls and OWASP Top 10, is crucial. In-depth knowledge of network protocols, operating systems, and security technologies, coupled with proficiency in incident detection and response tools, is expected.

Familiarity with malware analysis and reverse engineering is advantageous. The ability to automate tasks and processes using scripting languages like Python or PowerShell is a significant plus. We are seeking candidates with over 8 years of security-related experience in areas such as Security Operations, Incident Response, and Forensic Investigation. A keen analytical mindset, the aptitude for rapid learning, strong problem-solving skills for complex incidents, and excellent verbal and written communication abilities are vital.

Essential Skills

Digital ForensicsSIEMSplunkMicrosoft SentinelLogScaleGoogle ChronicleIBM QRadarEDRXDRCrowdStrikeMicrosoft DefenderSentinelOneCortex XSIAMCarbon BlackNetwork ProtocolsOperating SystemsSecurity TechnologiesIncident DetectionIncident ResponseMalware AnalysisReverse EngineeringPythonPowerShellThreat IntelligenceWiresharkTCPdump

Good to Have

CEHCHFISec+ITILv3GCFAECIHGCIHCySA+

More Details

RoleGMS-Manager-Incident Response
IndustryInformation Technology & Services, Cybersecurity
DepartmentInformation Security, Incident Response
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

Information Technology & Services

GMS-Manager-Incident Response at EY | SkillMX | SkillMX