1

Intern Cyber Security Soc Analyst Jobs in Rochester, NY

Intern Cyber Security Soc Analyst information

See Rochester, NY salary details

$10

$20

$26

How much do intern cyber security soc analyst jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for intern cyber security soc analyst in Rochester, NY is $20.07, according to ZipRecruiter salary data. Most workers in this role earn between $15.91 and $22.07 per hour, depending on experience, location, and employer.

What does an intern Cyber Security SOC Analyst do?

An Intern Cyber Security SOC (Security Operations Center) Analyst assists in monitoring and responding to security incidents within an organization. Their responsibilities typically include reviewing alerts, analyzing security logs, escalating potential threats, and supporting the team in maintaining the organization's cybersecurity posture. Interns gain hands-on experience with security tools, learn how to identify vulnerabilities, and help ensure that cyber threats are detected and managed effectively. This role serves as an entry point for those interested in cybersecurity careers.

What are some common challenges an intern Cyber Security SOC Analyst might face during their internship?

As an Intern Cyber Security SOC Analyst, you may encounter challenges such as quickly learning to use security information and event management (SIEM) tools, adapting to a fast-paced environment where incidents need rapid responses, and distinguishing between real threats and false positives. Collaboration is key, as you'll often work with senior analysts and IT teams to investigate alerts. Gaining hands-on experience with live security incidents and staying updated on the latest cyber threats are essential parts of the role.

What are the key skills and qualifications needed to thrive as an intern Cyber Security SOC Analyst, and why are they important?

To thrive as an Intern Cyber Security SOC Analyst, you need a basic understanding of networking, cybersecurity principles, and incident response, typically supported by coursework or certifications like CompTIA Security+ or Cisco CCNA. Familiarity with Security Information and Event Management (SIEM) tools, intrusion detection systems, and ticketing platforms is commonly required. Strong analytical thinking, attention to detail, and effective communication help interns collaborate with team members and respond to security threats efficiently. These skills and qualities are crucial for detecting, analyzing, and mitigating cyber threats in real time to protect organizational assets.

What is the difference between Intern Cyber Security Soc Analyst vs Security Operations Center (SOC) Analyst?

AspectIntern Cyber Security Soc AnalystSecurity Operations Center (SOC) Analyst
CertificationsBasic cybersecurity certifications (e.g., CompTIA Security+)Advanced certifications (e.g., GIAC, CISSP) often preferred
Work EnvironmentInternship setting, learning-focused, supervisedFull-time, shift-based, operational environment
ResponsibilitiesAssisting with monitoring, basic analysis, and learningMonitoring security alerts, incident response, threat analysis
Experience LevelEntry-level, learning phaseEntry to mid-level, active security monitoring

While both roles involve security monitoring, an Intern Cyber Security Soc Analyst is primarily a learning position assisting with basic tasks, whereas a SOC Analyst actively monitors and responds to security threats in a professional environment.

Are there intern cyber security SOC analyst internships?

Intern cyber security SOC analyst internships are available at various organizations, providing hands-on experience in security operations centers. These internships typically require knowledge of security tools, monitoring, and incident response, and may be offered during summer or semester periods to students pursuing cybersecurity or related degrees.

Is an Intern Cyber Security SOC Analyst still in demand?

Intern Cyber Security SOC Analysts are in demand as organizations prioritize cybersecurity and threat monitoring. Gaining skills in SIEM tools, threat detection, and security protocols can improve job prospects, especially with relevant certifications like CompTIA Security+ or Cisco CyberOps. Demand is driven by increasing cyber threats and the need for entry-level security talent in various industries.

What are the most commonly searched types of Cyber Security Soc Analyst jobs in Rochester, NY?

The most popular types of Cyber Security Soc Analyst jobs in Rochester, NY are:

What are popular job titles related to Intern Cyber Security Soc Analyst jobs in Rochester, NY?

For Intern Cyber Security Soc Analyst jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Intern Cyber Security Soc Analyst jobs in Rochester, NY look for?

The top searched job categories for Intern Cyber Security Soc Analyst jobs in Rochester, NY are:

What cities near Rochester, NY are hiring for Intern Cyber Security Soc Analyst jobs?

Cities near Rochester, NY with the most Intern Cyber Security Soc Analyst job openings:

Infographic showing various Intern Cyber Security Soc Analyst job openings in Rochester, NY as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $41,740 per year, or $20.1 per hour.

Cyber SDC - OT - Lead Incident Response Coordinator

Ernst & Young Oman

Rochester, NY • On-site

$125 - $218/hr

Other

Medical, Dental, Retirement, PTO

Posted 16 hours ago

Posted today


Job description

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Role Description Role Family

Incident Coordination / Operational Response Leadership

Primary Focus

Incident command, cross-functional coordination, escalation management, communications, and resolution tracking

Seniority

Lead / Senior Individual Contributor

Role Positioning

Central incident coordination role supporting operational, security, infrastructure, connectivity, monitoring, and service-impacting events

Practice Description

Complex technology environments require disciplined incident coordination to restore services quickly, manage operational impact, and maintain clear communication across technical and business stakeholders. The Lead Incident Response Coordinator role provides the structure, communication, escalation, and accountability needed when incidents affect multiple service domains or require coordinated response across several teams.

This role works across operations, cybersecurity, monitoring, network, infrastructure, application, platform, vendor, site support, and leadership teams to coordinate response activities, track recovery actions, maintain stakeholder awareness, and help drive timely restoration of services.

Job Summary

We are seeking a Lead Incident Response Coordinator to serve as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents.

The role leads incident command activities, coordinates cross-functional response efforts, manages communications and escalations, tracks resolution actions, and helps ensure timely service restoration while maintaining operational accountability and stakeholder awareness.

Role positioning:

This role is focused on incident command, coordination, communication, escalation, and resolution management. It is not intended to replace deep technical remediation teams, SOC analysts, engineering teams, or service owners. Instead, it ensures the right teams are engaged, actions are tracked, decisions are visible, and incidents progress toward resolution.

Key Responsibilities Incident Command and Coordination
  • Serve as the lead coordinator for incidents and major operational events requiring cross-functional response.
  • Establish incident command structure, response rhythm, and clear ownership during active incidents.
  • Coordinate response activities across technical, operational, cybersecurity, vendor, and stakeholder teams.
  • Assign, confirm, and track incident actions through restoration and closure.
  • Ensure response activities remain aligned to incident priority, business impact, and restoration objectives.
Escalation Management
  • Evaluate incident severity, operational impact, and escalation requirements.
  • Coordinate engagement of appropriate technical specialists, support teams, vendors, and leadership stakeholders.
  • Escalate unresolved issues, critical blockers, and material operational risks through the appropriate channels.
  • Facilitate rapid decision-making when response efforts require prioritization, ownership clarification, or leadership engagement.
  • Maintain clear visibility into escalation status, response ownership, and unresolved dependencies.
Communications Management
  • Develop and coordinate clear incident communications for response teams, leadership, and impacted stakeholders.
  • Maintain stakeholder awareness throughout the incident lifecycle, including status, impact, actions, blockers, and recovery progress.
  • Coordinate communication cadence during high-priority incidents and ensure updates are accurate, consistent, and actionable.
  • Support business, site, customer, or leadership communications where required.
  • Ensure incident communications remain factual, concise, and aligned to approved response practices.
Resolution Tracking and Recovery Management
  • Maintain incident action logs, decision records, recovery tasks, dependencies, and blockers.
  • Drive accountability across participating response teams and ensure assigned actions are tracked to completion.
  • Validate restoration criteria, recovery milestones, and transition back to normal operations.
  • Coordinate closure activities and ensure incident records accurately reflect the response timeline and outcome.
  • Support handoff from active incident response into remediation, problem management, or continuous improvement activities.
Cross-Team Operational Leadership
  • Coordinate incident response across monitoring, network, infrastructure, cybersecurity, endpoint, platform, application, vendor, and site support teams.
  • Promote consistent incident handling practices across service domains and operational teams.
  • Help remove response friction by clarifying ownership, next actions, decision points, and escalation paths.
  • Support operational readiness exercises, incident simulations, and tabletop activities as needed.
  • Build familiarity with service dependencies, support models, escalation paths, and response expectations.
Post-Incident Review and Continuous Improvement
  • Coordinate post-incident reviews and lessons‑learned discussions for significant incidents.
  • Identify recurring issues, coordination gaps, communication challenges, and operational improvement opportunities.
  • Track remediation commitments, action items, and improvement opportunities through completion.
  • Support updates to incident response playbooks, communication templates, escalation matrices, and operational procedures.
  • Measure and communicate incident response trends, recurring themes, and response effectiveness improvements.
Qualifications
  • Bachelor's degree in Information Technology, Cybersecurity, Engineering, Business, or equivalent experience preferred.
  • 6+ years of experience in incident management, operations coordination, cybersecurity operations, infrastructure operations, service management, or technical delivery roles.
  • Experience coordinating incidents, escalations, major operational events, or cross-functional response activities.
  • Strong understanding of operational support models, service restoration practices, escalation processes, and stakeholder communications.
  • Ability to coordinate technical teams without directly performing all technical remediation activities.
  • Strong communication, facilitation, documentation, prioritization, and decision-support skills.
  • Ability to operate effectively under pressure and maintain clear structure during high-impact incidents.
Preferred Qualifications
  • Experience in managed services, cybersecurity operations, network operations, infrastructure operations, or industrial/operational technology environments.
  • Experience with major incident management, incident command, ITIL processes, service restoration, problem management, or operational governance.
  • Familiarity with monitoring platforms, SIEM/SOC workflows, ticketing systems, collaboration tools, and operational dashboards.
  • Experience coordinating response across network, firewall, Zero Trust, monitoring, security, platform, vendor, and site teams.
  • Relevant certifications such as ITIL, Security+, CISSP Associate, CISM, PMP, or comparable incident management, service management, or cybersecurity credentials.
Technical Skills Incident Coordination Operational Response Communication & Governance

Incident command

Service restoration

Stakeholder communications

Action tracking

Escalation management

Executive updates

Response coordination

Cross-domain triage

Status reporting

Major incident practices

Operational dependencies

Post-incident reviews

Decision logs

Support model awareness

Playbook improvement

What we offer you

At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well‑being.
SHORT STAFFING PROFILE VERSION

Lead Incident Response Coordinator: Serves as the central point of coordination for operational, cybersecurity, infrastructure, connectivity, monitoring, and service-impacting incidents. Leads incident command activities, manages cross-functional response coordination, drives escalation and stakeholder communications, tracks restoration actions, and supports post-incident review and continuous improvement. Focuses on coordination, communications, escalation, and accountability rather than deep technical remediation.

Are you ready to shape your future with confidence?

EY accepts applications for this position on an on-going basis.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com .

#J-18808-Ljbffr