Ernst & Young

Senior Security Operations Analyst - Microsoft Sentinel and Defender

Ernst & Young • $90K — $126K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of cybersecurity experience, focusing on security operations and incident investigation.
  • Bachelor's degree or diploma in cybersecurity, IT, or related field, or equivalent experience.
  • Experience in a client-facing MSSP, MDR, or enterprise security operations role.
  • Microsoft Certified: Security Operations Analyst Associate (preferred).
  • Advanced Kusto Query Language skills for investigations and threat hunting.

Responsibilities

  • Lead investigations of complex security incidents across various customer environments.
  • Correlate diverse evidence to determine the scope and impact of incidents.
  • Develop timelines and document evidence, recommending containment actions.
  • Coordinate response activities with clients and internal teams.
  • Use Microsoft Sentinel and Defender to manage security alerts and incidents.
  • Automate incident response processes and improve operational workflows.
  • Support onboarding and improvements of customer environments and incident handling.

Benefits

  • Discretionary bonus program based on performance.
  • Comprehensive medical, prescription drug, and dental coverage.
  • Defined contribution pension plan and vacation policy.
  • Paid personal days and firm paid days for extended weekends.
  • Learning opportunities for skill development and career progression.
Full Job Description
EY is seeking a senior, hands-on security operations analyst to support Managed Detection and Response services in a multi-customer Managed Security Service Provider environment. You will lead complex security incident investigations using Microsoft Sentinel and Microsoft Defender XDR, perform threat hunting and detection tuning, and improve response workflows through Microsoft Sentinel automation rules, playbooks, and Azure Logic Apps. You will work across multiple customer environments, provide technical guidance to other analysts, and communicate clear findings and response recommendations to clients. The successful candidate will bring strong investigative judgement, advanced Microsoft security platform experience, and the ability to manage concurrent incidents and priorities in a client-facing environment. This job posting relates to an existing vacancy within our organization. Your key responsibilities: As a senior technical member of the security operations team, you will: Security incident investigation and response 3 Lead the triage and investigation of complex or high-severity security incidents across multiple customer environments. 3 Correlate endpoint, identity, email, cloud, network, and threat intelligence evidence to determine incident scope, root cause, and business impact. 3 Develop investigation timelines, document evidence, identify attacker activity, and recommend containment and remediation actions. 3 Coordinate escalations and response activities with clients, internal teams, and other technical specialists. 3 Produce clear incident records, client communications, and post-incident findings. Microsoft Sentinel and Defender operations 3 Use Microsoft Sentinel and Microsoft Defender XDR to investigate, prioritize, and respond to security alerts and incidents. 3 Investigate activity across Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud. 3 Write and optimize Kusto Query Language queries for incident investigation, threat hunting, reporting, and detection validation. 3 Review and tune analytics rules, hunting queries, workbooks, watchlists, parsers, and related detection content. 3 Identify gaps in telemetry, detection coverage, and platform configuration, then recommend practical improvements. Automation and continuous improvement 3 Design, build, test, and maintain Microsoft Sentinel automation rules and playbooks using Azure Logic Apps. 3 Automate incident enrichment, triage, notification, ticketing, evidence collection, and approved containment actions. 3 Troubleshoot playbook failures, integration issues, permissions, API connections, and workflow reliability. 3 Improve analyst workflows and standard operating procedures based on incident lessons, recurring alert patterns, and service metrics. 3 Apply appropriate approvals, access controls, logging, and error handling to automated response actions. MSSP service delivery 3 Manage investigations and technical priorities across multiple customers with different environments, procedures, and service commitments. 3 Follow customer-specific rules of engagement, escalation paths, response procedures, and service-level requirements. 3 Work directly with client security and technology teams to gather context, explain findings, and recommend next steps. 3 Support onboarding and operational improvement of customer environments, including data connectors, telemetry validation, and incident workflows. 3 Provide technical coaching and peer review to other analysts without direct people-management responsibility. Skills and attributes for success 3 Senior-level experience investigating complex cybersecurity incidents in a Security Operations Centre, Managed Detection and Response, or incident response environment. 3 Strong hands-on experience with Microsoft Sentinel and Microsoft Defender XDR in production environments. 3 Experience supporting multiple customers in an MSSP or MDR environment is strongly preferred. 3 Advanced Kusto Query Language skills for investigation, threat hunting, detection development, and reporting. 3 Hands-on experience creating and maintaining Microsoft Sentinel analytics rules, hunting queries, workbooks, automation rules, and playbooks. 3 Hands-on experience building Azure Logic Apps for security orchestration and response, including connectors, APIs, authentication, permissions, error handling, and monitoring. 3 Experience investigating endpoint, identity, email, cloud, and network threats using Microsoft and third-party telemetry. 3 Strong understanding of incident response, threat hunting, detection engineering, threat intelligence, and MITRE ATT&CK. 3 Ability to manage concurrent investigations and priorities while maintaining clear documentation and timely client communication. 3 Ability to explain technical findings, risk, and response recommendations to both technical and non-technical stakeholders. 3 Sound judgement when working under pressure and handling high-severity incidents. To qualify for the role you must have 3 Typically, 5+ years of cybersecurity experience, including substantial recent experience in security operations and incident investigation. 3 Bachelors degree or diploma in cybersecurity, computer science, information technology, engineering, or a related discipline, or equivalent practical experience. 3 Experience in a client-facing MSSP, MDR, consulting, or enterprise security operations role. 3 Microsoft Certified: Security Operations Analyst Associate, SC-200, is preferred. 3 Azure, Microsoft security, incident response, digital forensics, or cloud security certifications are considered assets. 3 Experience with ServiceNow or another IT service management platform is considered an asset. 3 Experience with source control, infrastructure as code, CI/CD, or automated deployment of Microsoft Sentinel content is considered an asset. 3 Experience with Azure Lighthouse, Microsoft Entra B2B, or other multi-tenant access models is considered an asset. What we look for We look for individuals who take initiative, demonstrate strong technical judgment, and show the ability to lead through influence. If you thrive in collaborative environments and are passionate about improving operational efficiency, this role is an excellent fit. What we offer We offer a competitive compensation package where youll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you to decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a discretionary bonus program, a comprehensive medical, prescription drug and dental coverage plan, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well-being. Plus, we offer: 3 Support and coaching from some of the most engaging colleagues in the industry 3 Learning opportunities to develop new skills and progress your career 3 The freedom and flexibility to handle your role in a way thats right for you EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets. 3 Toronto/London/Ottawa/Waterloo/Vancouver/Victoria/ Calgary/ Edmonton: $90,500 to $126,000 Are you ready to shape your future with confidence? Apply today. To help create the best experience during the recruitment process, please describe any accommodations you may need.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Senior Security Operations Analyst - Microsoft Sentinel and Defender jobs: