Government and Public Sector - Cybersecurity - Operations and Threat Detection Response - Sr Manager
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Security Management & Operations
Government and Public Sector
- Cybersecurity
- Operations and Threat Detection Response
- Sr Manager The opportunity
As a Senior Manager in Security Operations & Threat Detection and Response within EY’s Government & Public Sector practice, you will lead the strategy, design, transformation, and operation of mission‑critical Security Operations Centers (SOCs) for federal, state, local, and education clients. This role blends strategic cybersecurity advisory, operational leadership, and business development ownership in classified and highly regulated environments, up to the Top Secret (TS) level.
You will lead large, complex engagements supported by cleared delivery teams, serve as a trusted advisor to senior government stakeholders, and act as a primary driver of revenue growth for EY’s GPS Threat Detection & Response offerings.
- Define and drive security operations strategies and target operating models aligned to agency missions, risk tolerance, and regulatory mandates.
- Design and implement SOC operating models that support cleared, U.S.
-based delivery in environments up to the TS level, hybrid architectures, and follow‑the‑sun coverage where permissible. - Own engagement delivery outcomes, ensuring services meet EY quality standards, contractual SLAs, and government client expectations.
- Contribute to the development of EY GPS and global cybersecurity methodologies, assets, and accelerators in Threat Detection & Response.
- Lead the design and operation of AI‑enabled and automation‑driven SOC capabilities, including agent‑based workflows and advanced analytics that accelerate alert triage, enrichment, and response.
- Drive XDR‑led detection strategies, unifying telemetry across EDR, NDR, SIEM, identity, cloud, and SaaS platforms into a coherent and prioritized threat detection model.
- Oversee multi‑cloud and hybrid SOC architectures, integrating Azure, AWS, and on‑prem environments into centralized detection and response operations.
- Own security operations performance metrics, including MTTD, MTTR, dwell time, alert fidelity, and automation coverage; use these KPIs to drive continuous improvement and executive‑level reporting.
- Establish fusion across adjacent operational domains, including vulnerability management, identity security, data protection, and threat intelligence, reflecting how GPS programs are funded, governed, and measured.
- Oversee day‑to‑day SOC operations supporting classified (up to TS) and unclassified environments
, including:- Threat monitoring, alert triage, and escalation
- Incident containment, eradication, and recovery coordination
- Detection engineering, use‑case development, advanced analytics, and tuning across SIEM and XDR platforms
- Threat hunting and integration of cyber threat intelligence
- SIEM and SOAR runbook development and optimization
- Act as Incident Commander and executive escalation point for high‑severity cyber incidents, coordinating response with client leadership and government stakeholders.
- Integration of automated response and orchestration to reduce analyst burden and improve response consistency.
- Lead post‑incident reviews using MITRE ATT&CK and adversary‑informed defense techniques to measurably improve detection coverage and response effectiveness.
- Advise senior government stakeholders on SOC modernization roadmaps, translating operational metrics and detection outcomes into mission risk, compliance posture, and investment justification.
- Lead SOC assessments and maturity reviews using EY and industry frameworks (e.g., NIST CSF, NIST 800‑53, RMF, ISO 27001).
- Develop actionable roadmaps to mature clients’ Sec Ops capabilities across tooling, cleared workforce models, processes, and governance.
- Prepare and deliver client‑ready proposals, Statements of Work (SoWs), executive briefings, and classified or unclassified presentations as required.
- Ensure adherence to EY risk management, independence, and quality standards across all engagements.
- Oversee documentation of SOC procedures, incident records, and governance artifacts to support audits, inspections, and regulatory reviews.
- Support clients in aligning security operations with public sector mandates and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).