Logo
Ernst & Young Advisory Services Sdn Bhd

Senior Manager- Technology Consulting -MSOC & DFIR Services

Ernst & Young Advisory Services Sdn Bhd, Senior, Ohio, United States

Save Job

Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Select how often (in days) to receive an alert: Location: Riyadh Other locations: Primary Location Only Date: 10 Sept 2025 Requisition ID: 1642149 Role Purpose Lead the Managed SOC and Digital Forensics & Incident Response stream, ensuring timely threat detection, incident handling, escalation protocols, and forensic investigations. Key Responsibilities Oversee SOC operations across L1, L2, and L3 tiers. Define alert thresholds, escalation matrices, and incident runbooks. Coordinate threat hunts and root cause analysis (RCA). Manage DFIR tooling and evidence handling procedures. Liaise with vendors for out-of-hours incident support. Requirements 8–10 years in SOC leadership or DFIR roles. Hands-on with incident response, malware analysis, SIEM triage. Experience with forensic tools (e.g., FTK, EnCase). Certifications: GCFA, GCIH, or equivalent. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It’s yours to build. EY | Building a better working world. EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients. Provider Description Enabled SAP as service provider "route" is used for session stickiness "careerSiteCompanyId" is used to send the request to the correct data centre "JSESSIONID" is placed on the visitor's device during the session so the server can identify the visitor

#J-18808-Ljbffr