At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
The opportunity
EY is seeking a senior, hands-on Microsoft security engineer to support the design, implementation, and continuous improvement of our Managed Detection and Response (MDR) services. You will work directly with clients and delivery teams to architect and deploy Microsoft Sentinel, engineer detections and security use cases, build automation with Azure Logic Apps, develop operational workbooks, and integrate Microsoft Defender solutions. You will also help onboard and operate customer environments through Azure Lighthouse and Microsoft Entra B2B. The successful candidate combines deep engineering experience with clear client communication, practical problem solving, and ownership from design through production support.
This job posting relates to an existing vacancy within our organization.
Your role at a glance
Key responsibilities
As a senior technical member of the MDR team, you will:
Microsoft Sentinel architecture and implementation
- Lead the technical design and implementation of Microsoft Sentinel SIEM and SOAR solutions for new and existing MDR clients.
- Design workspace, data ingestion, retention, access-control, and multi-tenant operating models that account for security, regulatory, scalability, and cost requirements.
- Configure Microsoft Sentinel in the Microsoft Defender portal, Log Analytics workspaces, data connectors, diagnostic settings, content solutions, watchlists, and supporting Azure resources.
- Detection engineering and threat analytics
- Create, test, tune, document, and maintain analytics rules, hunting queries, parsers, and functions using Kusto Query Language (KQL).
- Translate threat scenarios, intelligence, customer risks, and operational requirements into practical detection use cases mapped to recognized frameworks such as MITRE ATT&CK.
- Integrate and correlate telemetry from Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure, Microsoft 365, and third-party security technologies.
- Automation, orchestration, and reporting
- Design, build, secure, and troubleshoot Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.
- Automate incident enrichment, triage, notification, containment, remediation, ticketing, and evidence collection across Microsoft and third-party systems.
- Develop Microsoft Sentinel workbooks and service dashboards that provide actionable views of threats, incidents, coverage, operational performance, and data ingestion.
- Multi-tenant onboarding and engineering
- Design and implement secure cross-tenant access using Azure Lighthouse and Microsoft Entra B2B collaboration.
- Work with customer identity, cloud, network, and security teams to establish permissions, managed identities, service principals, and least-privilege role assignments.
- Troubleshoot complex onboarding, data-connector, ingestion, query, automation, and access issues across customer environments.
- MDR service engineering and client collaboration
- Provide senior technical support for incident investigation, threat hunting, detection tuning, platform health, and continuous service improvement.
- Lead technical workshops, gather requirements, explain design decisions, and provide clear recommendations to client security and technology stakeholders.
- Produce solution designs, deployment plans, runbooks, testing evidence, operational documentation, and knowledge-transfer material.
- Provide technical guidance and peer review to engineers and analysts without direct people-management responsibility.
Skills and attributes for success
- Substantial hands-on experience designing, implementing, and operating Microsoft Sentinel in enterprise or managed-service environments.
- Advanced KQL skills and demonstrated experience developing analytics rules, hunting queries, functions, parsers, workbooks, and detection content.
- Strong experience with Microsoft Defender XDR, including relevant Defender products across endpoints, identity, email and collaboration, cloud apps, and cloud workloads.
- Hands-on experience building Azure Logic Apps, Microsoft Sentinel playbooks, and automation rules, including API-based integration, authentication, permissions, error handling, and monitoring.
- Experience architecting Microsoft Sentinel deployments, including workspace strategy, data connectors, ingestion and retention, role-based access control, and operational cost management.
- Experience implementing and supporting multi-tenant access with Azure Lighthouse and Microsoft Entra B2B collaboration.
- Understanding of incident response, threat hunting, detection engineering, security operations, and common threat frameworks.
- Ability to lead technical discussions with clients, convert requirements into implementable designs, and communicate complex concepts clearly.
- Ability to work independently, manage competing priorities, document work, review peer solutions, and take ownership of technical outcomes.
Qualifications
- Bachelor’s degree or diploma in computer science, information technology, cybersecurity, engineering, or a related discipline, or equivalent practical experience.
- Typically, seven or more years of cybersecurity experience, including significant recent experience delivering Microsoft Sentinel and Defender engineering work.
- Experience working in a client-facing consulting, MSSP, MDR, or enterprise security engineering role.
- Microsoft Certified: Security Operations Analyst Associate (SC-200) is preferred. Azure, identity, architecture, or security certifications are considered an asset.
- Experience with source control, infrastructure as code, CI/CD, or deployment automation for Microsoft Sentinel content is considered an asset.
- Experience integrating Microsoft Sentinel with IT service management, threat intelligence, network security, identity, endpoint, email, or cloud platforms is considered an asset.
What we offer
At EY, our Total Rewards package supports our commitment to creating a leading people culture - built on high-performance teaming - where everyone can achieve their potential and contribute to building a better working world for our people, our clients and our communities. It's one of the many reasons we repeatedly win awards for being a great place to work
We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a comprehensive medical, prescription drug and dental coverage, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well-being. Plus, we offer:
- Support and coaching from some of the most engaging colleagues in the industry
- Learning opportunities to develop new skills and progress your career
- The freedom and flexibility to handle your role in a way that’s right for you.
EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.
- Toronto, Calgary, Vancouver, Edmonton: $90,500 to $126,000 per year
Inclusiveness at EY
Inclusiveness is at the heart of who we are and how we work. We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation. Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.
Learn about our commitment to Inclusiveness at https://www.ey.com/en_ca/about-us/corporate-responsibility/equity
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
At EY, we use artificial intelligence (AI) tools as one element of our recruitment process to enhance efficiency and improve the candidate experience. While AI supports us in our process, human judgment and decision-making remain integral in our candidate experience. We are committed to the responsible use of AI, and our practices are continuously reviewed and refined to ensure they align with ethical principles and regulatory requirements.
To all recruitment agencies: EY does not accept unsolicited resumes from recruitment agencies. Any resumes submitted without a prior agreement or request from our hiring team will not be considered. EY is not responsible for any fees related to unsolicited resumes.