Location: Taguig
Other locations: Primary Location Only
Date: Jul 21, 2026
Requisition ID: 1692585
Service line
Cyber Security – Position Title: Senior Incident Response Analyst
Overview
At EY you will have the opportunity to build a career with a global team that values diversity, inclusion, and innovation.
Opportunity
As a Senior Incident Response Analyst, you will lead efforts to detect, investigate, contain, and remediate complex security incidents across cloud, on‑premise, and hybrid environments. You will work with cutting‑edge technologies and global teams to protect EY’s infrastructure and data from evolving cyber threats. Your technical expertise will be used for advanced threat analysis, digital forensics, and root‑cause investigations. You will guide and mentor junior analysts, enhance detection and response capabilities, and contribute to continuous improvement of incident response processes and playbooks.
Key Responsibilities
- Tier 3 Security Incident Response
- Conduct Tier 3 incident response for application, network, and infrastructure security alert events.
- Use documented procedures and in‑house security technologies to manage incidents effectively.
- Perform response actions on managed hosts, isolate suspected compromised hosts, and execute pre‑approved actions to disrupt cyberattacks.
- Clarify incident information, recommend containment, eradication, and recovery actions, and provide updates on cyberdefense calls.
- Coordination and Task Assignment
- Assign containment, eradication, and recovery tasks to appropriate resource teams.
- Ensure clear communication and coordination with relevant teams during incident response activities.
- Engage relevant parties for issue escalation and reporting, and communicate critical incidents to stakeholders, including executive management.
- Response Actions and Host Management
- Perform response actions on managed hosts where the Security Operations Center (SOC) team has requisite access and permissions.
- Isolate suspected compromised or infected hosts and execute other pre‑approved actions.
- Peer Review and Quality Assurance
- Conduct periodic peer reviews of Tier 2 analyst work to identify trends and areas for improvement.
- Provide constructive feedback to enhance overall quality of incident response efforts.
- Continuous Improvement and Learning
- Stay updated with the latest cybersecurity threats, trends, and technologies.
- Contribute to the development and enhancement of incident response processes and playbooks.
- Maintain comprehensive documentation of all incidents, actions taken, and lessons learned.
- Team Management (as required)
- Decision‑making, optimizing processes, resource management, and overseeing task execution.
- Allocate personnel, supervise team members, ensure necessary tools and support, and evaluate performance to meet organizational goals.
Skills and Attributes for Success
- Proven experience in incident response, threat hunting, and digital forensics.
- Strong knowledge of cyberattack tactics, techniques, and procedures aligned with MITRE ATT&CK.
- Proficiency with SIEM tools (e.g., Splunk, Microsoft Sentinel), EDR platforms, and SOAR frameworks.
- Experience conducting log analysis, packet inspection, and malware triage.
- Expertise in incidents involving cloud environments (AWS, Azure, GCP) and hybrid infrastructure.
- Familiarity with threat intelligence integration, playbook automation, and incident post‑mortem reporting.
- Strong understanding of network protocols, operating systems, and security controls.
- Excellent communication skills to convey technical findings to technical and non‑technical stakeholders.
- Experience mentoring junior analysts and fostering knowledge sharing.
- Strong documentation and reporting skills supporting compliance and continuous improvement.
- Professional certifications such as GCIH, GCFA, GCIA, CEH, CISSP, or CCIR are advantageous.
What We Look For
- 3–5 years of experience in cybersecurity operations, particularly in a SOC or similar environment.
- Proficiency in security monitoring tools, including Sentinel SIEM, IDS/IPS, EDR, and SOAR solutions.
- Strong knowledge of application, network, and infrastructure security.
- Excellent analytical, problem‑solving, and decision‑making skills.
- Ability to work under pressure and manage multiple incidents simultaneously.
- Strong communication and teamwork skills, with the ability to coordinate across cross‑functional teams.
- Familiarity with global cybersecurity standards and regulatory requirements.
Benefits
- Competitive salary and performance‑based bonuses.
- Comprehensive health, dental, and vision coverage.
- Retirement plans and flexible work arrangements.
- Continuous learning and professional development opportunities.
We are an equal opportunity employer and are committed to Diversity, Equity & Inclusion.