Cyber Defense Incident Responder – Assistant Director

Company: EY (Ernst & Young)
Apply for the Cyber Defense Incident Responder – Assistant Director
Location: London
Job Description:

Overview

As a Senior Cyber Incident Response Coordinator at EY Technology, you drive global incident response. You’ll coordinate events, liaise with cross-functional teams, and guide incident processes to protect EY and client data. You’ll operate in a fast-paced, high-stakes environment, shaping response plans and post-incident improvements. This role blends technical leadership with diplomacy and clear communication, across a global security program.

Pay / Benefits

  • flexible environment
  • diverse and inclusive culture
  • globally connected teams
  • opportunity to shape security programs
  • professional development support
  • competitive benefits (as part of EY)

Responsibilities

  • Coordinate response efforts to cybersecurity incidents caused by external threats across global time zones
  • Act as liaison and relationship manager with Business, Legal, Risk, vendors, and external parties
  • Engage General Counsel, Data Privacy/Protection, and Risk Management contacts to align on incidents
  • Drive integration with other incident management programs for consistency
  • Lead development and improvement of processes and documentation for scalable response operations
  • Collaborate with Incident Response leads to review performance and implement lessons learned
  • Draft timely communications and provide updates to leadership during and after events
  • Own and maintain internal playbooks and knowledgebase
  • Participate in on-call rotation to cover off-hours incidents

Key requirements

  • 7+ years in cybersecurity roles related to incident response, SOC, threat intelligence, or related fields
  • Deep understanding of incident response lifecycle and forensics
  • Experience with SIEMs and cross-domain security operations
  • Knowledge of Windows and Unix/Linux environments
  • Ability to manage global, complex incidents and communicate effectively
  • Experience with electronic discovery, forensic tools, and regulatory considerations
  • Willingness to pursue relevant certifications (GCFE, GCFA, GCIH, CISA, CISM, CISSP, CCIM)
  • Bachelor’s or Master’s Degree in a tech field or equivalent experience
  • Strong written and verbal communication, integrity, and diplomacy
  • Excellent communication and writing skills
  • Diplomacy and stakeholder management
  • Ability to work under pressure and make sound judgments
  • Incident response lifecycle
  • Forensics and chain-of-custody
  • Cybersecurity event analysis

…

Posted: October 1st, 2026