Ernst & Young

Senior Consultant - Microsoft Sentinel and Defender Engineer

Ernst & Young$90K — $126K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or diploma in computer science, IT, cybersecurity, engineering, or equivalent experience.
  • 7+ years of cybersecurity experience, with recent focus on Microsoft Sentinel and Defender engineering.
  • Client-facing experience in consulting, MSSP, MDR, or enterprise security roles.
  • Preferred Microsoft Certified: Security Operations Analyst Associate (SC-200) certification.
  • Familiarity with source control, infrastructure as code, and CI/CD for Microsoft Sentinel content is a plus.
  • Experience in integrating Microsoft Sentinel with various security platforms is considered an asset.

Responsibilities

  • Lead the design and implementation of Microsoft Sentinel solutions for clients.
  • Configure Microsoft Sentinel in various environments while adhering to security and regulatory frameworks.
  • Create and maintain analytics rules and detection use cases using Kusto Query Language (KQL).
  • Automate processes involving incident handling and reporting using Azure Logic Apps.
  • Onboard multi-tenant access through Azure Lighthouse and Microsoft Entra B2B.
  • Provide senior technical support for incident investigations and service improvements.
  • Document solutions and provide guidance to peers without direct management.

Benefits

  • Comprehensive medical, prescription drug, and dental coverage.
  • Defined contribution pension plan.
  • Flexible vacation policy with firm-paid days for long weekends.
  • Statutory holidays and paid personal days based on location.
  • Support and coaching from experienced colleagues in the industry.
  • Learning opportunities for skill development and career progression.
  • Flexibility to manage your role according to personal style.
Full Job Description
The opportunity

EY is seeking a senior, hands-on Microsoft security engineer to support the design, implementation, and continuous improvement of our Managed Detection and Response (MDR) services. You will work directly with clients and delivery teams to architect and deploy Microsoft Sentinel, engineer detections and security use cases, build automation with Azure Logic Apps, develop operational workbooks, and integrate Microsoft Defender solutions. You will also help onboard and operate customer environments through Azure Lighthouse and Microsoft Entra B2B. The successful candidate combines deep engineering experience with clear client communication, practical problem solving, and ownership from design through production support.

This job posting relates to an existing vacancy within our organization.

Your role at a glance

Key responsibilities

As a senior technical member of the MDR team, you will:

Microsoft Sentinel architecture and implementation
  • Lead the technical design and implementation of Microsoft Sentinel SIEM and SOAR solutions for new and existing MDR clients.
  • Design workspace, data ingestion, retention, access-control, and multi-tenant operating models that account for security, regulatory, scalability, and cost requirements.
  • Configure Microsoft Sentinel in the Microsoft Defender portal, Log Analytics workspaces, data connectors, diagnostic settings, content solutions, watchlists, and supporting Azure resources.
  • Detection engineering and threat analytics
  • Create, test, tune, document, and maintain analytics rules, hunting queries, parsers, and functions using Kusto Query Language (KQL).
  • Translate threat scenarios, intelligence, customer risks, and operational requirements into practical detection use cases mapped to recognized frameworks such as MITRE ATT&CK.
  • Integrate and correlate telemetry from Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure, Microsoft 365, and third-party security technologies.
  • Automation, orchestration, and reporting
  • Design, build, secure, and troubleshoot Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.
  • Automate incident enrichment, triage, notification, containment, remediation, ticketing, and evidence collection across Microsoft and third-party systems.
  • Develop Microsoft Sentinel workbooks and service dashboards that provide actionable views of threats, incidents, coverage, operational performance, and data ingestion.
  • Multi-tenant onboarding and engineering
  • Design and implement secure cross-tenant access using Azure Lighthouse and Microsoft Entra B2B collaboration.
  • Work with customer identity, cloud, network, and security teams to establish permissions, managed identities, service principals, and least-privilege role assignments.
  • Troubleshoot complex onboarding, data-connector, ingestion, query, automation, and access issues across customer environments.
  • MDR service engineering and client collaboration
  • Provide senior technical support for incident investigation, threat hunting, detection tuning, platform health, and continuous service improvement.
  • Lead technical workshops, gather requirements, explain design decisions, and provide clear recommendations to client security and technology stakeholders.
  • Produce solution designs, deployment plans, runbooks, testing evidence, operational documentation, and knowledge-transfer material.
  • Provide technical guidance and peer review to engineers and analysts without direct people-management responsibility.


Skills and attributes for success
  • Substantial hands-on experience designing, implementing, and operating Microsoft Sentinel in enterprise or managed-service environments.
  • Advanced KQL skills and demonstrated experience developing analytics rules, hunting queries, functions, parsers, workbooks, and detection content.
  • Strong experience with Microsoft Defender XDR, including relevant Defender products across endpoints, identity, email and collaboration, cloud apps, and cloud workloads.
  • Hands-on experience building Azure Logic Apps, Microsoft Sentinel playbooks, and automation rules, including API-based integration, authentication, permissions, error handling, and monitoring.
  • Experience architecting Microsoft Sentinel deployments, including workspace strategy, data connectors, ingestion and retention, role-based access control, and operational cost management.
  • Experience implementing and supporting multi-tenant access with Azure Lighthouse and Microsoft Entra B2B collaboration.
  • Understanding of incident response, threat hunting, detection engineering, security operations, and common threat frameworks.
  • Ability to lead technical discussions with clients, convert requirements into implementable designs, and communicate complex concepts clearly.
  • Ability to work independently, manage competing priorities, document work, review peer solutions, and take ownership of technical outcomes.


Qualifications
  • Bachelor's degree or diploma in computer science, information technology, cybersecurity, engineering, or a related discipline, or equivalent practical experience.
  • Typically, seven or more years of cybersecurity experience, including significant recent experience delivering Microsoft Sentinel and Defender engineering work.
  • Experience working in a client-facing consulting, MSSP, MDR, or enterprise security engineering role.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) is preferred. Azure, identity, architecture, or security certifications are considered an asset.
  • Experience with source control, infrastructure as code, CI/CD, or deployment automation for Microsoft Sentinel content is considered an asset.
  • Experience integrating Microsoft Sentinel with IT service management, threat intelligence, network security, identity, endpoint, email, or cloud platforms is considered an asset.


What we offer

At EY, our Total Rewards package supports our commitment to creating a leading people culture - built on high-performance teaming - where everyone can achieve their potential and contribute to building a better working world for our people, our clients and our communities. It's one of the many reasons we repeatedly win awards for being a great place to work

We offer a competitive compensation package where you'll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a comprehensive medical, prescription drug and dental coverage, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well-being. Plus, we offer:
  • Support and coaching from some of the most engaging colleagues in the industry
  • Learning opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that's right for you.


EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.
  • Toronto, Calgary, Vancouver, Edmonton: $90,500 to $126,000 per year

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Senior Consultant - Microsoft Sentinel and Defender Engineer jobs: