At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
The opportunity
EY is seeking a senior, hands-on security operations analyst to support Managed Detection and Response services in a multi-customer Managed Security Service Provider environment.
You will lead complex security incident investigations using Microsoft Sentinel and Microsoft Defender XDR, perform threat hunting and detection tuning, and improve response workflows through Microsoft Sentinel automation rules, playbooks, and Azure Logic Apps. You will work across multiple customer environments, provide technical guidance to other analysts, and communicate clear findings and response recommendations to clients.
The successful candidate will bring strong investigative judgement, advanced Microsoft security platform experience, and the ability to manage concurrent incidents and priorities in a client-facing environment.
This job posting relates to an existing vacancy within our organization.
Your key responsibilities:
As a senior technical member of the security operations team, you will:
Security incident investigation and response
- Lead the triage and investigation of complex or high-severity security incidents across multiple customer environments.
- Correlate endpoint, identity, email, cloud, network, and threat intelligence evidence to determine incident scope, root cause, and business impact.
- Develop investigation timelines, document evidence, identify attacker activity, and recommend containment and remediation actions.
- Coordinate escalations and response activities with clients, internal teams, and other technical specialists.
- Produce clear incident records, client communications, and post-incident findings.
Microsoft Sentinel and Defender operations
- Use Microsoft Sentinel and Microsoft Defender XDR to investigate, prioritize, and respond to security alerts and incidents.
- Investigate activity across Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
- Write and optimize Kusto Query Language queries for incident investigation, threat hunting, reporting, and detection validation.
- Review and tune analytics rules, hunting queries, workbooks, watchlists, parsers, and related detection content.
- Identify gaps in telemetry, detection coverage, and platform configuration, then recommend practical improvements.
Automation and continuous improvement
- Design, build, test, and maintain Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.
- Automate incident enrichment, triage, notification, ticketing, evidence collection, and approved containment actions.
- Troubleshoot playbook failures, integration issues, permissions, API connections, and workflow reliability.
- Improve analyst workflows and standard operating procedures based on incident lessons, recurring alert patterns, and service metrics.
- Apply appropriate approvals, access controls, logging, and error handling to automated response actions.
MSSP service delivery
- Manage investigations and technical priorities across multiple customers with different environments, procedures, and service commitments.
- Follow customer-specific rules of engagement, escalation paths, response procedures, and service-level requirements.
- Work directly with client security and technology teams to gather context, explain findings, and recommend next steps.
- Support onboarding and operational improvement of customer environments, including data connectors, telemetry validation, and incident workflows.
- Provide technical coaching and peer review to other analysts without direct people-management responsibility.
Skills and attributes for success
- Senior-level experience investigating complex cybersecurity incidents in a Security Operations Centre, Managed Detection and Response, or incident response environment.
- Strong hands-on experience with Microsoft Sentinel and Microsoft Defender XDR in production environments.
- Experience supporting multiple customers in an MSSP or MDR environment is strongly preferred.
- Advanced Kusto Query Language skills for investigation, threat hunting, detection development, and reporting.
- Hands-on experience creating and maintaining Microsoft Sentinel analytics rules, hunting queries, workbooks, automation rules, and playbooks.
- Hands-on experience building Azure Logic Apps for security orchestration and response, including connectors, APIs, authentication, permissions, error handling, and monitoring.
- Experience investigating endpoint, identity, email, cloud, and network threats using Microsoft and third-party telemetry.
- Strong understanding of incident response, threat hunting, detection engineering, threat intelligence, and MITRE ATT&CK.
- Ability to manage concurrent investigations and priorities while maintaining clear documentation and timely client communication.
- Ability to explain technical findings, risk, and response recommendations to both technical and non-technical stakeholders.
- Sound judgement when working under pressure and handling high-severity incidents.
To qualify for the role you must have
- Typically, 5+ years of cybersecurity experience, including substantial recent experience in security operations and incident investigation.
- Bachelor’s degree or diploma in cybersecurity, computer science, information technology, engineering, or a related discipline, or equivalent practical experience.
- Experience in a client-facing MSSP, MDR, consulting, or enterprise security operations role.
- Microsoft Certified: Security Operations Analyst Associate, SC-200, is preferred.
- Azure, Microsoft security, incident response, digital forensics, or cloud security certifications are considered assets.
- Experience with ServiceNow or another IT service management platform is considered an asset.
- Experience with source control, infrastructure as code, CI/CD, or automated deployment of Microsoft Sentinel content is considered an asset.
- Experience with Azure Lighthouse, Microsoft Entra B2B, or other multi-tenant access models is considered an asset.
What working at EY offers
What we look for
We look for individuals who take initiative, demonstrate strong technical judgment, and show the ability to lead through influence. If you thrive in collaborative environments and are passionate about improving operational efficiency, this role is an excellent fit.
What we offer
We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you to decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a discretionary bonus program, a comprehensive medical, prescription drug and dental coverage plan, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well-being. Plus, we offer:
- Support and coaching from some of the most engaging colleagues in the industry
- Learning opportunities to develop new skills and progress your career
- The freedom and flexibility to handle your role in a way that’s right for you
EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.
- Toronto/London/Ottawa/Waterloo/Vancouver/Victoria/ Calgary/ Edmonton: $90,500 to $126,000
Are you ready to shape your future with confidence? Apply today.
To help create the best experience during the recruitment process, please describe any accommodations you may need.
Inclusiveness at EY
Inclusiveness is at the heart of who we are and how we work. We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation. Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.
Learn about our commitment to Inclusiveness at https://www.ey.com/en_ca/about-us/corporate-responsibility/equity
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
At EY, we use artificial intelligence (AI) tools as one element of our recruitment process to enhance efficiency and improve the candidate experience. While AI supports us in our process, human judgment and decision-making remain integral in our candidate experience. We are committed to the responsible use of AI, and our practices are continuously reviewed and refined to ensure they align with ethical principles and regulatory requirements.
To all recruitment agencies: EY does not accept unsolicited resumes from recruitment agencies. Any resumes submitted without a prior agreement or request from our hiring team will not be considered. EY is not responsible for any fees related to unsolicited resumes.