Location: Anywhere in Country
At EY, we're all in to shape your future with confidence.
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Role Description
Role Family
Incident Coordination / Operational Response Leadership
Primary Focus
Incident command, cross-functional coordination, escalation management, communications, and resolution tracking
Seniority
Lead / Senior Individual Contributor
Role Positioning
Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events
PRACTICE DESCRIPTION
Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams.
This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services.
JOB SUMMARY
We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents.
The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness.
Role positioning: This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.
KEY RESPONSIBILITIES
Incident Command and Coordination
Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
Establish incident command structure, response rhythm, and clear ownership during active incidents.
Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
Assign, confirm, and track incident actions through restoration and closure.
Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.
Escalation Management
Evaluate incident severity, operational impact, and escalation requirements.
Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.
Communications Management
Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
Support business, site, customer, or leadership communications where required.
Ensure incident communications remain factual, concise, and aligned to approved response practices.
Resolution Tracking and Recovery Management
Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
Validate restoration criteria, recovery milestones, and transition back to normal operations.
Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
Support handoff from active incident response into remediation, problem management, or continuous improvement activities.
Cross-Team Operational Leadership
Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
Promote consistent incident handling practices across service domains and operational teams.
Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
Support operational readiness exercises, incident simulations, and tabletop activities as needed.
Build familiarity with service dependencies, support models, escalation paths, and response expectations.
Post-Incident Review and Continuous Improvement
Coordinate post-incident reviews and lessons-learned discussions for significant incidents.
Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
Track remediation commitments, action items, and improvement opportunities through completion.
Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.
QUALIFICATIONS
Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
Ability to coordinate technical teams without directly performing all technical remediation activities.
Strong communication, facilitation, documentation, prioritization, and decision-support skills.
Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.
Preferred Qualifications
Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.
TECHNICAL SKILLS
Incident Coordination
Operational Response
Communication & Governance
Incident command
Service restoration
Stakeholder communications
Action tracking
Escalation management
Executive updates
Response coordination
Cross-domain triage
Status reporting
Major incident practices
Operational dependencies
Post-incident reviews
Decision logs
Support model awareness
Playbook improvement
**WHAT WE