Ernst & Young

Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

Ernst & Young$65K — $99K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Proven experience in a Tier 1 or Tier 2 SOC or MSSP environment.
  • Hands-on expertise with Microsoft Sentinel, including analytics rules and incident investigations.
  • Experience with Microsoft Defender technologies.
  • Exposure to investigations across cloud, endpoint, and identity domains.
  • Understanding of attack techniques and incident response methodologies.
  • Ability to manage multiple investigations while maintaining documentation quality.
  • Strong communication skills, capable of explaining technical findings to security-focused audiences.
  • Proficiency in French, especially Quebec French, is a plus.

Responsibilities

  • Perform security monitoring and investigation of alerts using Microsoft Sentinel and Defender.
  • Escalate confirmed or complex incidents related to potential compromises.
  • Investigate using various sources like log analytics and endpoint telemetry.
  • Document security incidents with root cause analysis and impact assessments.
  • Assist in containment and recovery under senior guidance.
  • Support tuning and maintenance of Sentinel analytics rules.
  • Document detection gaps and contribute to use case development.
  • Support threat hunting activities to identify suspicious activity.
  • Communicate incident findings clearly to clients and stakeholders.
  • Contribute to playbook and procedural improvements for operational excellence.

Benefits

  • Opportunities for continuous professional development and training.
  • Participation in knowledge sharing and case reviews.
  • Engagement in a client-facing environment with diverse experiences.
  • Involvement in the development of cutting-edge detection capabilities.
  • Supportive team environment focused on operational excellence.
Full Job Description
The opportunity

Ernst & Young is seeking junior and intermediate-level technical security professionals with hands-on expertise in Microsoft Sentinel and Microsoft Defender to support our Managed Detection and Response (MDR) services within a Security Operations Center (SOC) environment.

This role is designed for an experienced Tier 1 / Tier 2 SOC Analyst who performs threat detection, investigation, and response activities. The successful candidate will operate in a client-facing MSSP environment and will contribute directly to the quality, effectiveness, and continuous improvement of EY's MDR services.

This job posting relates to an existing vacancy within our organization.

Your key responsibilities:

Working with our technical team and clients the candidate will be responsible for:

Security Monitoring and Incident Response
  • Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks.
  • Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios.
  • Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud-native audit logs.
  • Validate, scope, and document security incidents, including root cause analysis and impact assessment.
  • Assist with containment and recovery under senior guidance.


Detection Engineering and Use Case Development
  • Support tuning and maintenance of Sentinel analytics rules.
  • Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources.
  • Document detection gaps
  • Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment.


Threat Hunting
  • Support threat hunting activities
  • Identify anomalous or suspicious activity that may not trigger existing detections.
  • Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps.


Client Engagement and Technical Advisory
  • Communicating incident findings clearly
  • Participating in client calls when required
  • Supporting onboarding and steady-state operations
  • Support senior team members in identifying logging, configuration improvements.
  • Support onboarding and steady-state operations for MDR clients within a managed services context.


Operational Excellence
  • Contribute to playbooks and procedural improvements.
  • Participate in knowledge sharing and case reviews.
  • Assist with service quality improvements, detection maturity, and operational consistency across clients.
  • Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements.


Key Requirements:
  • Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level.
  • Hands-on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations.
  • Experience with Microsoft Defender technologies, including Defender for Endpoint and identity-related signals.
  • Exposure to investigations across cloud, endpoint, and identity domains.
  • Working understanding of attack techniques, threat actor behaviors, and incident response methodologies.
  • Ability to manage multiple investigations simultaneously while maintaining investigation quality and documentation.
  • Strong written and verbal communication skills, with the ability to explain technical findings to security-focused audiences.
  • Proficiency in French, including Quebec French, is desired for client facing engagements.


Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Relevant certifications such as:
    o Microsoft Certified: Azure Security Engineer Associate
    o Microsoft Sentinel specialization
    o CISSP, GCED, GCIA, or similar (preferred, not required)
  • Minimum 1-2 years of experience in cybersecurity operations, with significant time spent in incident response and security monitoring roles.
  • Prior experience in a client-facing or managed services environment is strongly preferred


EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.

  • Toronto, Calgary, Vancouver : $65,500 - $99,000
  • Ottawa, St. John's : $62,500 - $94,000
  • Halifax, Saint John, Dieppe, Victoria : $59,000 - $89,000

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant jobs: