Cyber SDC - OT - Lead Incident Response Coordinator
EY
- Location
- Chicago, IL, US, 60606 +80 more…
- Work model
- On-Site
- Level
- Senior
Skills
About this role
Location: Anywhere in Country At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Role Description
Role Family
Incident Coordination / Operational Response Leadership
Primary Focus
Incident command, cross-functional coordination, escalation management, communications, and resolution tracking
Seniority
Lead / Senior Individual Contributor
Role Positioning
Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events
PRACTICE DESCRIPTION Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams. This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services. JOB SUMMARY We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness. Role positioning: This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution. KEY RESPONSIBILITIES Incident Command and Coordination
Serve as the lead coordinator for incidents and major operational events requiring cross-functional response. Establish incident command structure, response rhythm, and clear ownership during active incidents. Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams. Assign, confirm, and track incident actions through restoration and closure. Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.
Escalation Management
Evaluate incident severity, operational impact, and escalation requirements. Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders. Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels. Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement. Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.
Communications Management
Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders. Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress. Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable. Support business, site, customer, or leadership communications where required. Ensure incident