About the Role
Ernst & Young is seeking junior and intermediate-level technical security professionals with hands-on expertise in Microsoft Sentinel and Microsoft Defender to support our Managed Detection and Response (MDR) services within a Security Operations Center (SOC) environment. This role is designed for an experienced Tier 1 / Tier 2 SOC Analyst who performs threat detection, investigation, and response activities. The successful candidate will operate in a client-facing MSSP environment and will contribute directly to the quality, effectiveness, and continuous improvement of EY’s MDR services.
Responsibilities
- Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks.
- Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios.
- Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud-native audit logs.
- Validate, scope, and document security incidents, including root cause analysis and impact assessment.
- Assist with containment and recovery under senior guidance.
- Support tuning and maintenance of Sentinel analytics rules.
- Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources.
- Document detection gaps.
- Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment.
- Support threat hunting activities.
- Identify anomalous or suspicious activity that may not trigger existing detections.
- Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps.
- Communicating incident findings clearly.
- Participating in client calls when required.
- Supporting onboarding and steady-state operations.
- Support senior team members in identifying logging, configuration improvements.
- Support onboarding and steady-state operations for MDR clients within a managed services context.
- Contribute to playbooks and procedural improvements.
- Participate in knowledge sharing and case reviews.
- Assist with service quality improvements, detection maturity, and operational consistency across clients.
- Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements.
Requirements
- Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level.
- Hands-on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations.
- Experience with Microsoft Defender technologies, including Defender for Endpoint and identity-related signals.
- Exposure to investigations across cloud, endpoint, and identity domains.
- Working understanding of attack techniques, threat actor behaviors, and incident response methodologies.
- Ability to manage multiple investigations simultaneously while maintaining investigation quality and documentation.
- Strong written and verbal communication skills, with the ability to explain technical findings to security-focused audiences.
- Proficiency in French, including Quebec French, is desired for client facing engagements.
Skills
- Microsoft Sentinel
- Microsoft Defender
- KQL
- Workbooks
- Defender for Endpoint
- Incident Response
- Security Monitoring
- Threat Detection
- Threat Hunting
- Log Analytics
- Endpoint Telemetry
- Identity Signals
- Cloud-Native Audit Logs
Location
- Toronto
- Calgary
- Vancouver
- Ottawa
- St. John's
- Halifax
- Saint John
- Dieppe
- Victoria
Work Type
- Managed Detection and Response (MDR)
- Security Operations Center (SOC)
- Managed Services
Experience Level
- Junior
- Intermediate
- Tier 1
- Tier 2
- 1-2 years of experience in cybersecurity operations
Education Level
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Sentinel specialization
- CISSP, GCED, GCIA, or similar (preferred, not required)
Salary/Compensations
- Toronto, Calgary, Vancouver : $65,500 - $99,000
- Ottawa, St. John's : $62,500 - $94,000
- Halifax, Saint John, Dieppe, Victoria : $59,000 - $89,000
About the Company
- EY is building a better working world by creating new values for clients, people, society and the planet, while building trust in capital markets.
- Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
- EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions.
- Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
- At EY, we use artificial intelligence (AI) tools as one element of our recruitment process to enhance efficiency and improve the candidate experience.
- While AI supports us in our process, human judgment and decision-making remain integral in our candidate experience.
- We are committed to the responsible use of AI, and our practices are continuously reviewed and refined to ensure they align with ethical principles and regulatory requirements.
Equal Opportunity
- Inclusiveness is the heart of who we are and how we work.
- We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging.
- We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation.
- Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us.
- Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.
- Learn about our commitment to Inclusiveness at https://www.ey.com/en_ca/about-us/corporate-responsibility/equity
