Ernst & Young

Cyber Triage and Forensics Shift Lead Supervising Associate

Ernst & Young$91K — $170K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or Information Security, or equivalent work experience (3-4 years)
  • 4-5 years in a Security Monitoring/Security Operations Center (SOC) environment
  • Proficiency in intrusion detection platforms and electronic investigation
  • Working knowledge of Linux and/or Windows systems administration, including Active Directory
  • Scripting or programming skills in languages such as Shell scripting, Python, PowerShell, etc.

Responsibilities

  • Manage daily operations and performance of the CTF Analysts
  • Ensure efficient responses to email and incident queues
  • Distribute workload within the threat hunting team and supervise their actions
  • Participate in analysis and triage of security events
  • Provide technical leadership and mentorship to junior analysts
  • Set performance expectations and manage team outcomes
  • Report case status and significant incidents to global leadership
  • Update Standard Operating Procedures (SOPs) and promote continuous improvement

Benefits

  • Comprehensive compensation and benefits package based on performance
  • Flexible working model with expected in-person collaboration 40-60% of the time
  • Flexible vacation policy allowing personalized vacation planning
  • Time off for designated EY Paid Holidays and personal circumstances
  • Medical and dental coverage, pension and 401(k) plans,
Full Job Description
The opportunity

The CTF Shift Lead at EY plays a critical role in maintaining the efficiency and effectiveness of the Cyber Triage and Forensics team's daily operations. Tasked with managing the performance of Junior and Senior Triage Analysts, this position ensures that the team responds swiftly to threats and manages case queues effectively. The Shift Lead's involvement in analysis and triage, combined with their responsibility for setting performance expectations and providing technical leadership, is essential for upholding high standards of cybersecurity practices. Reporting to the global leadership team, the Shift Lead's insights and updates are vital for informed decision-making and strategic alignment within the organization's cybersecurity efforts.

Your key responsibilities

You will work collaboratively to detect and respond to information security incidents, develop, maintain, and follow procedures for security event alerting, and participate in security investigations. The CTF Analyst II will perform tasks including monitoring, research, classification and analysis of security events that occur on the network or endpoint.
  • Manage day-to-day operations and performance of the CTF Analysts
  • Ensure prompt and efficient response to email and case queues
  • Distribute workload among the threat hunting team and oversee their activities
  • Participate in the analysis and triage of security events
  • Provide technical leadership and mentorship to junior analysts
  • Set clear performance expectations and manage team performance
  • Report case status and significant incident updates to the global lead
  • Update Standard Operating Procedures (SOPs) and drive continuous improvement within the team
  • Coordinate with the Technical Lead for incident and investigation support as needed


Skills and attributes for success
  • Familiarity with the principles of network and endpoint security, current threat and attack trends, and a basic understanding of the OSI model
  • Working knowledge of Defense in depth strategies
  • Understanding Information Security Principles, Technologies, and Practices
  • Demonstrable experience with multiple security event detection platforms
  • Thorough understanding of TCP/IP and basic IDS/IPS rules to identify and/or prevent malicious activity
  • Demonstrated integrity in a professional environment
  • Good social, communication, and technical writing skills
  • Comfortable navigating and troubleshooting Linux and Windows system issues


To qualify for the role you must have
  • A Bachelor's degree in Computer Science, Information Systems, Information Security, or equivalent work experience (3-4 years).
  • A minimum of 4-5 years of experience in a Security Monitoring/Security Operations Center environment (SOC), investigating security events, threats, and/or vulnerabilities.
  • Understanding of electronic investigation and log correlation with proficiency in the latest intrusion detection platforms.
  • Working knowledge of Linux and/or Windows systems administration, including Active Directory.
  • Scripting or programming skills (Shell scripting, Python, PowerShell, Perl, Java, etc.).


Ideally, you'll also have
  • Desired certifications such as SSCP, CEH, GCIH, GCFA, GCIA, GSEC, GIAC, Security+.
  • Previous leadership experience as a team lead or supervisor


What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
  • We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $91,100 to $170,400. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $109,300 to $193,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Cyber Triage and Forensics Shift Lead Supervising Associate jobs: