Ernst & Young LLP ( EY India )

EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager

Ernst & Young LLP ( EY India )
Kochi
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 12 yearsMin. 12 years

Job Description

EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

EY – Cybersecurity Manager (SOC, Incident Response & Threat Intelligence)

Overview

As a Manager in EY’s Cybersecurity practice, you will play a pivotal role in delivering advanced Security Operations, Incident Response, Security Orchestration, and Threat Intelligence services across diverse client environments. We are seeking a Security Operations Manager to support MSSP and multi-tenant Security Operations Centers (SOC), administering, deploying, and overseeing IBM QRadar SIEM, Splunk Enterprise, ELK Stack, IBM SOAR Resilient, and CTM360 Threat Management Platform.

The role supports multiple client environments across IT and OT ecosystems, ensuring effective threat detection, incident response, security orchestration, and threat intelligence operations. Candidates may have expertise in one or more platforms, with opportunities for cross-training and growth across the security operations technology stack.

The Opportunity

We are seeking cybersecurity professionals with 12+ years of experience in Security Operations, Incident Response, Threat Intelligence, Cyber Defence, or cybersecurity consulting. The ideal candidate will possess deep expertise in SIEM, SOAR, and Threat Intelligence platforms while demonstrating the ability to lead client engagements, manage security operations teams, and contribute to the growth of EY's managed security services capabilities.

High-performing individuals who demonstrate leadership, innovation, and alignment with EY's values and talent policies may be considered for accelerated career progression and leadership opportunities within the cybersecurity practice.

Key Responsibilities

SIEM Administration - IBM QRadar, Splunk & ELK Stack (IT & OT Security Monitoring)

  • Deploy, configure, and administer IBM QRadar, Splunk, and ELK Stack SIEM platforms across multiple client environments.
  • Design and implement SIEM use cases, correlation rules, dashboards, and reporting mechanisms.
  • Integrate log sources from network, endpoint, cloud, application, and OT environments.
  • Monitor and optimize SIEM performance, health, and event processing capabilities.
  • Perform tuning of offense rules to minimize false positives and improve detection efficiency.
  • Support onboarding of new customers, assets, and log sources into the managed SOC environment.
  • Lead investigations of security alerts, incidents, and suspicious activities identified through IBM QRadar, Splunk, and ELK Stack.
  • Develop and maintain detection content aligned to evolving threat landscapes and industry best practices.
  • Support incident response activities, forensic investigations, and root cause analysis.
  • Collaborate with stakeholders to improve security visibility across IT and OT environments.
  • Communicate complex technical concepts to senior stakeholders and business leaders.
  • Mentor junior consultants and SOC analysts, fostering a culture of continuous learning and operational excellence.

SOAR Engineering & Security Automation

  • Deploy and configure SOAR platforms such as Phantom, XSOAR, Resilient supporting multi-tenant MSSP operations.
  • Design and implement automated incident response workflows and response playbooks.
  • Develop integrations between SOAR, SIEM, endpoint security, ticketing systems, and threat intelligence platforms.
  • Configure incident types, workflows, tasks, and escalation processes for client environments.
  • Maintain and enhance security orchestration workflows to improve SOC efficiency and response times.
  • Troubleshoot integration, automation, and workflow performance issues.
  • Collaborate with SOC teams to identify automation opportunities across incident handling processes.
  • Lead customer onboarding, migration, and expansion activities within SOAR platforms.
  • Develop custom scripts and automation use cases using supported APIs and integration frameworks.
  • Ensure governance, auditability, and operational effectiveness of automated response actions.
  • Support SOC analysts during complex incident investigations and escalations.
  • Communicate complex technical concepts to senior stakeholders and business leaders.
  • Mentor junior consultants and engineers in automation best practices.

Threat Intelligence Operations

  • Deploy, configure, and manage Threat Management Platform such as CTM360, CyberArk, BitSight, RecordedFuture capabilities across client environments.
  • Monitor external threat exposure and digital attack surfaces for multiple clients.
  • Perform threat intelligence analysis to identify emerging threats, adversary activities, and indicators of compromise (IOCs).
  • Correlate threat intelligence findings with SIEM and SOAR platforms to enhance detection capabilities.
  • Develop threat intelligence reports, executive briefings, and strategic risk assessments.
  • Monitor brand exposure, domain threats, credential leaks, phishing campaigns, and digital risks.
  • Support proactive threat hunting activities using intelligence-driven methodologies.
  • Create and maintain threat detection use cases based on intelligence findings.
  • Collaborate with incident response teams during active cyber incidents.
  • Provide actionable recommendations to clients for risk mitigation and exposure reduction.
  • Support intelligence sharing and threat-informed defines initiatives.

Security Operations & Incident Response Leadership

  • Lead security monitoring, threat detection, incident response, and threat intelligence activities across multiple client environments.
  • Manage MSSP service delivery, ensuring adherence to SLAs, KPIs, and operational objectives.
  • Support major incident management, cyber crisis response, and post-incident reviews.
  • Coordinate across security, infrastructure, cloud, and application teams during investigations.
  • Conduct regular service reviews and provide recommendations for security posture improvement.
  • Drive operational excellence through process improvement, automation, and innovation.
  • Support business development efforts, solution design, and customer presentations.
  • Contribute to the development of SOC service offerings, methodologies, and intellectual property.

Skills and Attributes for Success

  • Deep understanding of cybersecurity technologies including SIEM, SOAR, EDR, XDR, NDR, MDR, and Threat Intelligence Platforms
  • Strong knowledge of Security Operations Center (SOC) processes and incident response methodologies
  • Experience supporting both IT and Operational Technology (OT) security environments.
  • Understanding of threat actor tactics, techniques, and procedures (TTPs)
  • Strong analytical, investigation, and problem-solving skills
  • Excellent stakeholder management and customer-facing consulting capabilities
  • Ability to manage multiple clients and engagements simultaneously.
  • Strong leadership and team management skills
  • Experience delivering services in a Managed Security Services (MSSP) environment.
  • Business acumen and client-focused mindset

To Qualify for the Role, You Must Have

  • B. Tech or M. Tech in Cybersecurity, Computer Science, Electronics, Information Security, or related disciplines
  • 12+ years of relevant cybersecurity experience
  • Hands-on experience administering and managing SIEM platforms, including IBM QRadar, Splunk, and/or ELK Stack
  • Hands-on experience with IBM SOAR Resilient and security automation technologies
  • Experience in Threat Intelligence Operations and exposure management platforms
  • Experience supporting SOC operations, incident response, and threat hunting activities.
  • Strong understanding of IT security monitoring, detection engineering, and incident handling
  • Strong command of verbal and written English
  • Experience with scripting or programming languages such as Python, PowerShell, SQL, or similar
  • Experience working within multi-client or MSSP environments is preferred.

What We Look For

  • Professionals who are enthusiastic about cybersecurity operations, threat detection, incident response, and threat intelligence. Individuals who demonstrate leadership, innovation, operational excellence, and the ability to deliver impactful outcomes within a consulting and managed security services environment. A strong sense of ownership, continuous learning, customer focus, and alignment with EY's values will be critical to success in this role.

EY | Building a better working world



EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.



Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.



Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Job role

Work location
Work locationKochi, KL, IN, 682313 +1 more…
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 12 years

About company

Name
NameErnst & Young LLP ( EY India )
Job posted by Ernst & Young LLP ( EY India )

Similar jobs you can apply for

IT Security
Ernst & Young LLP ( EY India )

Security Manager

Ernst & Young LLP ( EY India )
Kochi
Work from Office
Full Time
Min. 12 years
Ernst & Young LLP ( EY India )

Security Manager

Ernst & Young LLP ( EY India )
Kochi
Work from Office
Full Time
Min. 12 years
Ernst & Young LLP ( EY India )

Security Manager

Ernst & Young LLP ( EY India )
Kochi
Work from Office
Full Time
Min. 12 years
Ernst & Young LLP ( EY India )

Security Manager

Ernst & Young LLP ( EY India )
Kochi
Work from Office
Full Time
Min. 12 years
Ernst & Young LLP ( EY India )

Security Manager

Ernst & Young LLP ( EY India )
Kochi
Work from Office
Full Time
Min. 12 years
Marriott Hotels India

Security Supervisor

Marriott Hotels India
Kochi
Work from Office
Full Time
Any experience

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 12 to 31 years are eligible to apply for this job. You can apply for more jobs in Kochi to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Kochi at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Kochi . Through apna, you can find jobs in 64 cities across India. Join NOW!