Government and Public Sector - Cybersecurity - Operations and Threat Detection Response - Sr Manager
Listed on 2026-07-14
-
IT/Tech
Cybersecurity, Security Management & Operations
Senior Manager, Security Operations & Threat Detection and Response – Government & Public Sector
From strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high‑performing teams, quality work at the highest professional standards, operational know‑how from across our global organization, and creative and bold ideas that drive innovation.
Theopportunity
As a Senior Manager in Security Operations & Threat Detection and Response within EY’s Government & Public Sector (GPS) practice, you will lead the strategy, design, transformation, and operation of mission‑critical Security Operations Centers (SOCs) for federal, state, local, and education clients. This role blends strategic cybersecurity advisory, operational leadership, and business development ownership in classified and highly regulated environments, up to the Top Secret (TS) level.
You will lead large, complex engagements supported by cleared delivery teams, serve as a trusted advisor to senior government stakeholders, and act as a primary driver of revenue growth for EY’s GPS Threat Detection & Response offerings.
This role is expected to lead the modernization of government security operations through AI‑enabled analytics, automation‑driven workflows, and XDR‑led telemetry unification across hybrid and multi‑cloud environments. The Senior Manager will be accountable for transforming traditional SOC models into metrics‑driven, outcome‑oriented operations that improve detection fidelity, reduce response time, and operationalize compliance at scale across mission‑critical federal programs.
YourKey Responsibilities
- Define and drive security operations strategies and target operating models aligned to agency missions, risk tolerance, and regulatory mandates.
- Design and implement SOC operating models that support cleared, U.S.
-based delivery in environments up to the TS level, hybrid architectures, and follow‑the‑sun coverage where permissible. - Own engagement delivery outcomes, ensuring services meet EY quality standards, contractual SLAs, and government client expectations.
- Contribute to the development of EY GPS and global cybersecurity methodologies, assets, and accelerators in Threat Detection & Response.
- Lead the design and operation of AI‑enabled and automation‑driven SOC capabilities, including agent‑based workflows and advanced analytics that accelerate alert triage, enrichment, and response.
- Drive XDR‑led detection strategies, unifying telemetry across EDR, NDR, SIEM, identity, cloud, and SaaS platforms into a coherent and prioritized threat detection model.
- Oversee multi‑cloud and hybrid SOC architectures, integrating Azure, AWS, and on‑prem environments into centralized detection and response operations.
- Own security operations performance metrics, including MTTD, MTTR, dwell time, alert fidelity, and automation coverage, using these KPIs to drive continuous improvement and executive‑level reporting.
- Establish fusion across adjacent operational domains, including vulnerability management, identity security, data protection, and threat intelligence, reflecting how GPS programs are funded, governed, and measured.
- Oversee day‑to‑day SOC operations supporting classified (up to TS) and unclassified environments, including:
- Threat monitoring, alert triage, and escalation
- Incident containment, eradication, and recovery coordination
- Detection engineering, use‑case development, advanced analytics, and tuning across SIEM and XDR platforms
- Threat hunting and integration of cyber threat intelligence
- SIEM and SOAR runbook development and optimization
- Act as Incident Commander and executive escalation point for high‑severity cyber incidents, coordinating response with client leadership and government stakeholders.
- Integration of automated response and orchestration to reduce analyst burden and improve response consistency.
- Lead post‑incident reviews using MITRE ATT&CK and adversary‑informed…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).