GDS Consulting_Cyber Detection & Response Senior

Ernst & Young Advisory Services Sdn Bhd

Taguig

On-site

PHP 1,200,000 - 1,800,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive salary
Health benefits
Retirement plans
Professional development

Job summary

Ernst & Young Advisory Services Sdn Bhd is seeking a Senior Incident Response Analyst to lead Tier 3 security incident response across cloud, on‑premise, and hybrid environments. You will investigate, contain, and remediate complex incidents, mentor junior analysts, and improve playbooks and detection capabilities.

You will work with global teams, leverage MITRE ATT&CK, and coordinate with stakeholders including executive management. Strong communication and documentation skills are essential.

Qualifications

  • 3–5 years in cybersecurity operations, SOC or similar
  • Proficiency with Sentinel SIEM, IDS/IPS, EDR and SOAR
  • Strong knowledge of application, network and infrastructure security
  • Excellent analytical, problem-solving and decision-making skills
  • Ability to manage multiple incidents and work under pressure
  • Certifications such as GCIH, GCFA, GCIA, CEH, CISSP are advantageous

Responsibilities

  • Lead Tier 3 security incident response for applications, networks and infrastructure
  • Coordinate containment, eradication and recovery actions with cross‑functional teams
  • Perform actions on managed hosts and isolate compromised systems
  • Conduct peer reviews of analyst work and provide constructive feedback
  • Stay updated on threats and enhance incident response playbooks
  • Oversee team tasks, allocate resources, and monitor performance

Skills

Incident response
Threat hunting
Digital forensics
MITRE ATT&CK
Communication

Education

Bachelor's degree in CS/IT or related field

Tools

Splunk
Microsoft Sentinel
EDR platforms
SOAR

Job description

Location: Taguig

Other locations: Primary Location Only

Date: Jul 21, 2026

Requisition ID: 1692585

Service line

Cyber Security – Position Title: Senior Incident Response Analyst

Overview

At EY you will have the opportunity to build a career with a global team that values diversity, inclusion, and innovation.

Opportunity

As a Senior Incident Response Analyst, you will lead efforts to detect, investigate, contain, and remediate complex security incidents across cloud, on‑premise, and hybrid environments. You will work with cutting‑edge technologies and global teams to protect EY’s infrastructure and data from evolving cyber threats. Your technical expertise will be used for advanced threat analysis, digital forensics, and root‑cause investigations. You will guide and mentor junior analysts, enhance detection and response capabilities, and contribute to continuous improvement of incident response processes and playbooks.

Key Responsibilities
  • Tier 3 Security Incident Response
    • Conduct Tier 3 incident response for application, network, and infrastructure security alert events.
    • Use documented procedures and in‑house security technologies to manage incidents effectively.
    • Perform response actions on managed hosts, isolate suspected compromised hosts, and execute pre‑approved actions to disrupt cyberattacks.
    • Clarify incident information, recommend containment, eradication, and recovery actions, and provide updates on cyberdefense calls.
  • Coordination and Task Assignment
    • Assign containment, eradication, and recovery tasks to appropriate resource teams.
    • Ensure clear communication and coordination with relevant teams during incident response activities.
    • Engage relevant parties for issue escalation and reporting, and communicate critical incidents to stakeholders, including executive management.
  • Response Actions and Host Management
    • Perform response actions on managed hosts where the Security Operations Center (SOC) team has requisite access and permissions.
    • Isolate suspected compromised or infected hosts and execute other pre‑approved actions.
  • Peer Review and Quality Assurance
    • Conduct periodic peer reviews of Tier 2 analyst work to identify trends and areas for improvement.
    • Provide constructive feedback to enhance overall quality of incident response efforts.
  • Continuous Improvement and Learning
    • Stay updated with the latest cybersecurity threats, trends, and technologies.
    • Contribute to the development and enhancement of incident response processes and playbooks.
    • Maintain comprehensive documentation of all incidents, actions taken, and lessons learned.
  • Team Management (as required)
    • Decision‑making, optimizing processes, resource management, and overseeing task execution.
    • Allocate personnel, supervise team members, ensure necessary tools and support, and evaluate performance to meet organizational goals.
Skills and Attributes for Success
  • Proven experience in incident response, threat hunting, and digital forensics.
  • Strong knowledge of cyberattack tactics, techniques, and procedures aligned with MITRE ATT&CK.
  • Proficiency with SIEM tools (e.g., Splunk, Microsoft Sentinel), EDR platforms, and SOAR frameworks.
  • Experience conducting log analysis, packet inspection, and malware triage.
  • Expertise in incidents involving cloud environments (AWS, Azure, GCP) and hybrid infrastructure.
  • Familiarity with threat intelligence integration, playbook automation, and incident post‑mortem reporting.
  • Strong understanding of network protocols, operating systems, and security controls.
  • Excellent communication skills to convey technical findings to technical and non‑technical stakeholders.
  • Experience mentoring junior analysts and fostering knowledge sharing.
  • Strong documentation and reporting skills supporting compliance and continuous improvement.
  • Professional certifications such as GCIH, GCFA, GCIA, CEH, CISSP, or CCIR are advantageous.
What We Look For
  • 3–5 years of experience in cybersecurity operations, particularly in a SOC or similar environment.
  • Proficiency in security monitoring tools, including Sentinel SIEM, IDS/IPS, EDR, and SOAR solutions.
  • Strong knowledge of application, network, and infrastructure security.
  • Excellent analytical, problem‑solving, and decision‑making skills.
  • Ability to work under pressure and manage multiple incidents simultaneously.
  • Strong communication and teamwork skills, with the ability to coordinate across cross‑functional teams.
  • Familiarity with global cybersecurity standards and regulatory requirements.
Benefits
  • Competitive salary and performance‑based bonuses.
  • Comprehensive health, dental, and vision coverage.
  • Retirement plans and flexible work arrangements.
  • Continuous learning and professional development opportunities.

We are an equal opportunity employer and are committed to Diversity, Equity & Inclusion.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GDS Consulting_Cyber Detection And Response Senior
GDS Consulting_Cyber Detection And Response Senior

EY • Taguig

On-site
PHP 1,200,000 - 2,400,000
Cyber Detection & Response Engineer, Cross-Platform Management, Senior
Cyber Detection & Response Engineer, Cross-Platform Management, Senior

Ernst & Young Advisory Services Sdn Bhd • Taguig

On-site
PHP 800,000 - 1,200,000
Coaching & feedback
Skill development opportunities
Flexibility to manage role
GDS Consulting_Cyber Threat Management Senior Penetration Tester
GDS Consulting_Cyber Threat Management Senior Penetration Tester

Ernst & Young Advisory Services Sdn Bhd • Taguig

On-site
Support from engaging colleagues
Opportunities for skill development
Flexible working arrangements
GDS Consulting_Cyber Risk, Compliance & Resilience- Senior
GDS Consulting_Cyber Risk, Compliance & Resilience- Senior

Ernst & Young Advisory Services Sdn Bhd • Taguig

On-site
PHP 900,000 - 1,300,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

RecruitNest Consulting • Taguig

On-site
PHP 1,200,000 - 2,100,000
GDS Philippines - Cybersecurity Accelerated Hiring
GDS Philippines - Cybersecurity Accelerated Hiring

EY • Philippines

On-site
PHP 2,398,081 - 5,395,683
Cybersecurity Operations Engineer
Cybersecurity Operations Engineer

RecruitNest Consulting • Taguig

On-site
PHP 1,200,000 - 1,800,000
Cyber Detection And Response Engineer Cross-Platform Management Senior
Cyber Detection And Response Engineer Cross-Platform Management Senior

EY • Taguig

On-site
PHP 1,000,000 - 2,000,000
GDS Consulting_CyberSecurity_Partner
GDS Consulting_CyberSecurity_Partner

Ernst & Young Advisory Services Sdn Bhd • Taguig

On-site
PHP 1,800,000 - 3,000,000
Digital Forensic & Incident Response Senior Analyst - Hybrid Ortigas - 70K
Digital Forensic & Incident Response Senior Analyst - Hybrid Ortigas - 70K

weSource Management Consultancy Firm • Pasig

Hybrid