At a Glance
- Tasks: Lead and evolve data incident investigations, ensuring effective triage and governance.
- Company: Join EY, a global leader in building a better working world.
- Benefits: Competitive pay, flexible working, and opportunities for career development.
- Other info: Be part of a diverse team dedicated to continuous improvement and innovation.
- Why this job: Make a real impact in risk management and security transformation.
- Qualifications: Experience in incident management and strong leadership skills required.
The predicted salary is between 59576 - 70089 £ per year.
At EY, we are committed to building a better working world. EY is looking to strengthen its enterprise data incident handling and investigation capability to improve consistency, speed and governance in suspected data incident triage and investigation. Join us and be part of a global team of over 13,000 professionals dedicated to delivering cutting-edge security transformation programs and services.
The opportunity: As a director, you will lead, execute and continuously evolve the Data Incident & Investigation capability, setting the operating model, standards and ways of working that underpin effective incident triage and investigation. You will continually improve and mature the capability end-to-end from classification and prioritisation to escalation thresholds, governance routines and MI while providing senior oversight on complex and high severity incidents. The Data Incident Capability Architect & Strategic Lead holds ongoing operational accountability for the quality, consistency and discipline of data incident handling, ensuring the capability operates effectively day-to-day while embedding continuous improvement as part of business-as-usual operations.
Location – London, Manchester or Scotland
Key Responsibilities:
- Own and lead the triage operating model to ensure consistent validation, classification, prioritisation and escalation across all suspected data incidents, including any significant data incidents, operating in a confidential environment.
- Provide senior oversight on complex or high-severity incidents, ensuring early assessment quality is sufficient to inform governance and downstream investigation.
- Set expectations and quality standards for triage execution (minimum information standards, MI integrity and hand-off requirements).
- Ensure coordinated incident response through clear engagement pathways and structured hand-offs with relevant stakeholder groups including Privacy, InfoSec, Forensics, Legal, Talent, and Leadership.
- Act as the senior escalation authority for complex triage and severity decisions, directly making or arbitrating prioritisation, classification and response decisions and engaging senior stakeholders where required to resolve risk, timing or ownership trade-offs.
- Own, operate and evolve incident MI reporting as a core capability, setting the data model and standards, chairing governance routines and using MI directly to challenge performance, drive decisions and prioritise actions across the incident portfolio.
- Identify and act on systemic weaknesses observed during live incidents, directly driving changes to standards, controls and ways of working to improve response quality, speed and discipline.
- Lead engagement with senior executives and governance forums on data incidents, presenting insights, trends and recommendations, escalating material risks and securing decisions on risk acceptance, remediation priorities and control changes.
- Represent the Data Incident function in senior forums, contributing insights, trend analysis and recommendations to influence organisational risk posture.
Skills and attributes for success:
- Strong leadership and experience in incident triage/operational risk delivery: able to set standards, drive consistency and lead through ambiguity under time pressure.
- Senior stakeholder management capability across technical and risk functions, enabling coordinated response and effective escalation.
- Excellent written and verbal communication, able to produce executive-ready briefings and high-quality MI outputs.
- Strong operational rigour with a continuous improvement mindset, able to improve processes, templates, standards and reporting routines.
To qualify, you must have:
- Professional experience delivering triage, incident management or comparable risk-based workflow delivery.
- Experience interviewing insider risk actors, witnesses and impacted individuals across both digital and human domains.
- An incident investigation professional training or certification, e.g., GIAC Incident Handler.
- Expertise in producing structured reporting/MI outputs and maintaining disciplined documentation standards.
- Experience of working in a professional services firm or partnership would be beneficial, e.g., understanding of complex matrix organisations, working with colleagues in other functions/organisations or indirect relationships.
- A passion for security and technology and identifying and solving problems.
- Motivation, commitment and the desire to continue to learn and develop.
Please note: The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address may be required and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and ensure that they have not spent more than six months outside the UK.
Join Us: At EY, you’ll have the chance to build a meaningful and fulfilling career, supported by an inclusive culture and cutting-edge technology. Together, we can create a better working world for all.
What we look for: We’re interested in people with integrity who can collaborate with people from a diverse range of backgrounds and crucially a growth mindset.
What we offer: We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions.
Plus, we offer:
- Success as defined by you: The opportunity to build and shape a new UK&I Incident & Investigations capability with firm-level impact focused on improving consistency, speed and governance in suspected data incident triage.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
If you can demonstrate the skills described above and are excited to operate at the centre of a high impact Risk Management capability, we encourage you to apply.
Director - DSO - UK Data Incident Investigations Strategic Lead - Permanent in London employer: EY
EY is an exceptional employer that fosters a collaborative and innovative work culture in Manchester, where you can thrive as an Industry Strategy & Growth Lead. With comprehensive benefits including medical coverage and flexible vacation policies, alongside a strong commitment to professional development, EY empowers its employees to grow and excel in their careers while making a meaningful impact in the consumer and health sectors.
StudySmarter Expert Advice🤫
We think this is how you could land Director - DSO - UK Data Incident Investigations Strategic Lead - Permanent in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including EY, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through EY
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at EY. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Director - DSO - UK Data Incident Investigations Strategic Lead - Permanent in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at EY insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to EY that you’re committed to staying ahead in the game.
How to prepare for a job interview at EY
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at EY to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at EY.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.