Join to apply for the Security Analyst role at EY
At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
The Internal Investigations Services (IIS) team is responsible for responding to cyber security incidents and events caused by EY Personnel, Contractors and Associates globally. The scope of IIS also includes performing computer forensic reviews and managing eDiscovery requests supporting General Counsel.
Senior Specialist Internal Investigations Services acts as a lead technical investigator for information gathering, analysis and reporting in support of digital forensic investigations
Your Key Responsibilities
- Leads security investigations and eDiscovery matters
- Produces fact-based technical reports detailing events over specified periods of time for the investigation and shares the reports with stakeholders to act upon
- Advise and assist stakeholders on the relevance of information derived from internal and external sources associated with information security matters, digital forensic inquiries, and investigative work
- Identify and propose areas for improvement in IIS processes and procedures
Skills And Attributes For Success
In depth technical knowledge (IT infrastructure, forensic tools, forensic methodologies)Strong investigative and analytical mentality, and problem-solving skillsAble to see the comprehensive picture based on the correlation of the data captured from the various data sourcesAbility to multitask in a time sensitive environment with awareness of confidentiality and local privacy lawsFlexibility to adjust to multiple demands, ambiguity and rapid change environmentGlobal approach for working with different cultures and backgroundsExcellent teaming skillsAbility to team well with others to facilitate and enhance the understanding & compliance to security policiesKnowledge of existing and emerging legal issues within information security environments (i.e., data privacy)Possess an efficient and versatile communication styleProven integrity and judgment within a professional environmentAbility to work in a global environment (Virtual teaming, multiple jurisdictions)Experiences in investigation case managementA strong information security background and knowledge to speak thoughtfully to both technical and non-technical teamsAbility to appropriate balance work / personal prioritiesUnderstanding of the Big 4 workplace culture and business structureConduct interview skills with investigative mind-set, supporting GCO from a technical perspectiveOther Requirements :
Some weekend work should be expected
To qualify for the role you must have
Education : Bachelor or Master Degree in Computer Science or a related field
Experience
5-10 years of experience in one or more of the following :
Information Security, demonstrating experience in investigative unit and incident response.Information Security, in depth understanding of cyber investigation, forensic tools, and methodologies, including : log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processesBe familiar with a basic understanding of legalities surrounding discovery and analysis of electronically stored informationExperience with Forensic tools such as Encase, F-Response, FTK, Nuix, Axiom,...Experience with Microsoft Purview, Defender and other monitoring toolsFamiliar with Microsoft environment (Exchange, SharePoint, Purview , Sentinel, Azure…)Knowledge of scripting languages such as Python to automate collectionExperience with PowerShellCertification Requirements : Candidates must hold or be actively pursuing related professional certifications such as CISSP, Security+, EnCE, ACE, GCFE, GCIA
Ideally, you'll also have
Certifications demonstrating interest and development of Soft SkillsWhat We Offer You
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $91,100 to $170,400.Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances.EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity / expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis.
J-18808-Ljbffr