EY

Senior Incident Orchestrator - Cybersecurity

EY

Kochi, Kerala, India · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
منذ 3 ساعات
Work mode
In office
Education
Bachelor's Degree in Information Technology or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

Join a globally recognized professional services firm that offers a supportive, inclusive environment and cutting-edge technology to help you excel. As a Senior Incident Orchestrator within the Security Operations Center (SOC), you will lead the coordination and governance of security incidents, ensuring proper triage, escalation, and resolution as per organizational policies and service level agreements.

Key Responsibilities

  • Manage all stages of security incidents from escalation to containment, mitigation, and closure.
  • Serve as the main coordination point between L1/L2 SOC analysts, threat detection units, IT departments, and incident response teams.
  • Classify and prioritize incidents based on established policies and severity guidelines.
  • Validate alerts and incidents to confirm actual threats and assess business impact before initiating actions.
  • Lead containment efforts by collaborating with relevant teams handling endpoints, networks, identity, and cloud environments.
  • Coordinate incident communications in war rooms or bridges during significant security events, ensuring timely updates and clear responsibilities.
  • Document all incident details meticulously in designated ticketing and management tools.
  • Prepare comprehensive status reports and summaries for SOC leadership and stakeholders.
  • Administer post incident reviews by gathering evidence, response timelines, and effectiveness metrics.
  • Ensure incident handling adheres to predefined playbooks, runbooks, and operational procedures.
  • Identify repetitive issues and inefficiencies in incident response processes and recommend improvements.
  • Act as an escalation contact for complex or unclear incidents requiring expert operational judgment.
  • Continuously review and enhance incident response plans, playbooks, and protocols.
  • Lead or participate actively in incident response conference calls.
  • Mentor and guide junior incident response professionals.

Required Qualifications and Skills

  • Hands-on experience with digital forensics tools and methodologies for incident investigations.
  • Proficient use of SIEM platforms such as Splunk, Microsoft Sentinel, LogScale, Google Chronicle, or IBM QRadar.
  • Experience with EDR/XDR solutions including CrowdStrike, Microsoft Defender, SentinelOne, Cortex XSIAM, or Carbon Black.
  • Strong understanding of security frameworks like SANS Top 20 Controls and OWASP Top 10 vulnerabilities.
  • Knowledge of attack lifecycles and incident response stages: identification, containment, eradication, and recovery.
  • In-depth familiarity with network protocols, operating systems, and security infrastructure technologies.
  • Skillful in incident detection and response tools.
  • Basic knowledge of malware analysis and reverse engineering techniques.
  • Competency in scripting languages such as Python and PowerShell for automation purposes.
  • Minimum five years of experience in cybersecurity roles encompassing security operations, incident response, and forensic analysis.
  • Analytical thinking with the ability to learn rapidly during dynamic conditions.
  • Availability and willingness to work in a 24/7 shift-based operational security center.
  • Strong problem-solving skills coupled with excellent verbal and written communication capabilities.

Preferred Additional Qualifications

  • Bachelor’s degree in Information Technology or related field.
  • Relevant certifications such as CEH, CHFI, Security+, ITIL v3, GCFA, ECIH, GCIH, or CySA+.

Work Environment and Benefits

This role offers engaging projects across various organizations, encompassing startup ventures to global Fortune 500 corporations. Employees receive robust support including coaching and constructive feedback, empowering them to develop new skills and advance their careers. A flexible working style is encouraged to best suit individual preferences. Collaboration within a multidisciplinary team fosters knowledge sharing and high-quality outcomes.

Company Mission

The employer is committed to establishing a better working world by enhancing long-term stakeholder value and fostering trust in capital markets. Leveraging data, technology, and diverse teams worldwide, the organization delivers assurance, consultancy, and strategic services to address complex challenges across global industries.

Level

Senior

Minimum education

Bachelor's Degree

How they work

Communication Problem Solving Adaptability Leadership
🤖
Online · instant AI help