TC-CS-Cyber Detection and Response-SOC-Manager @ EY
Cyber Crime - Indiana, PA
Apply NowJob Description
TC-CS-Cyber Detection and Response-SOC-Manager At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. Join us and build an exceptional experience for yourself, and a better working world for all. As part of our EY-cyber security team, the Threat Detection & Response Operations Manager will lead Operations/Delivery for TDR engagements with end-to-end security incident investigation support ensuring client SLAs and KPIs leveraging multiple SIEM /EDR/NSM solutions. The opportunity We're looking for a Security Manager with expertise in SOC Operations & Delivery with hands-on knowledge on SIEM, EDR, NSM, and Threat Intelligence solutions. Your key responsibilities Oversee the process of detecting, reporting, and responding to security incidents, ensuring that the SOC team can effectively manage incidents when they occur. Manage the security tools and technologies used by the SOC team, ensuring they are properly configured and maintained, and that they can effectively monitor and detect security threats. Lead and manage the Security Operations Centre primarily responsible for security event monitoring of clients' networks. Ensure that Service Level Agreements are defined, tracked, and met for all clients. Provide technical leadership and advice to junior team members on SOC activities. Revise Standard Operating Policies & Procedures as required and ensure they are followed by the team. Identify opportunities to improve security monitoring and operational tasks. Convey complex technical security concepts to technical and non-technical audiences including executives. Develop and maintain productive working relationships with client personnel. Oversee daily SOC tasks that can be automated. Provide both strategic view and benefits to clients and work with limited resources to achieve it. Skills and attributes for success Hands-on expertise of SIEM technologies such as Microsoft Sentinel and Splunk from a security analyst's point of view. Expert knowledge and experience in Security Monitoring. Knowledge in cloud security and IoT/OT is a value add. Knowledge in network monitoring technology platforms such as Fidelis, ExtraHop, Darktrace, etc. Knowledge in endpoint protection tools, techniques, and platforms such as Carbon Black, Defender, CrowdStrike. Ability to work with minimal levels of supervision or oversight. Customer service oriented - Meets commitments to customers; seeks feedback from customers to identify improvement opportunities. To qualify for the role, you must have B. Tech./ B.E. with sound technical skills. Ability to work in client time zone. Strong command of verbal and written English language. Demonstrate both technical acumen and critical thinking abilities. Strong interpersonal and presentation skills. Minimum 10 years of hands-on experience operating/implementing/designing SIEM solutions and proven experience in Project Management. Certification in any of the SIEM platforms. Knowledge of RegEx, Perl scripting, and SQL query language is a value add. Certifications: CISM, CEH, CISSP, GCIH, GIAC, SABSA, TOGAF. What we look for Proven experience in leading operations for SOC projects, with hands-on experience in SIEM configuration and setup. EY | Building a better working world #J-18808-Ljbffr
Created: 2025-02-01