Cyber SDC - OT - Lead Incident Response Coordinator

EYHartford, DC
$104,800 - $218,500Remote

About The Position

Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams. This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services. We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness. This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
  • 6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
  • Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
  • Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
  • Ability to coordinate technical teams without directly performing all technical remediation activities.
  • Strong communication, facilitation, documentation, prioritization, and decision-support skills.
  • Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.

Nice To Haves

  • Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
  • Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
  • Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
  • Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
  • Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.

Responsibilities

  • Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
  • Establish incident command structure, response rhythm, and clear ownership during active incidents.
  • Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
  • Assign, confirm, and track incident actions through restoration and closure.
  • Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.
  • Evaluate incident severity, operational impact, and escalation requirements.
  • Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
  • Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
  • Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
  • Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.
  • Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
  • Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
  • Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
  • Support business, site, customer, or leadership communications where required.
  • Ensure incident communications remain factual, concise, and aligned to approved response practices.
  • Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
  • Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
  • Validate restoration criteria, recovery milestones, and transition back to normal operations.
  • Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
  • Support handoff from active incident response into remediation, problem management, or continuous improvement activities.
  • Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
  • Promote consistent incident handling practices across service domains and operational teams.
  • Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
  • Support operational readiness exercises, incident simulations, and tabletop activities as needed.
  • Build familiarity with service dependencies, support models, escalation paths, and response expectations.
  • Coordinate post-incident reviews and lessons-learned discussions for significant incidents.
  • Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
  • Track remediation commitments, action items, and improvement opportunities through completion.
  • Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
  • Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.

Benefits

  • medical and dental coverage
  • pension and 401(k) plans
  • a wide range of paid time off options
  • flexible vacation policy
  • designated EY Paid Holidays
  • Winter/Summer breaks
  • Personal/Family Care
  • other leaves of absence
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service