Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY

Ottawa

On-site

CAD 63,000 - 94,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EY is seeking junior to intermediate technical security professionals to support MDR services in a SOC environment. The role involves threat detection, investigation, and response using Microsoft Sentinel and Defender across cloud, endpoint, and identity domains.

The candidate will work in a client-facing MSSP setting, contributing to detections, playbooks, and incident handling while upholding regulatory and evidentiary standards. Bilingual French is a plus.

Qualifications

  • Bachelor’s degree in a related field required or equivalent experience.
  • Minimum 1–2 years in cybersecurity operations, with incident response focus.
  • Hands-on experience with Microsoft Sentinel analytics rules and Defender technologies.
  • Client-facing or MSSP experience is strongly preferred.

Responsibilities

  • Operate in a SOC/MSSP environment to monitor, investigate and respond to alerts.
  • Develop detections, hunting queries, and enrich alerts for customers.
  • Conduct threat hunting and root-cause analysis with clear documentation.
  • Engage clients, communicate findings, and support onboarding/steady-state operations.
  • Contribute to playbooks, knowledge sharing, and quality improvements.

Skills

Microsoft Sentinel
Microsoft Defender
SOC Analyst (Tier 1/2)
Communication skills

Education

Bachelor's degree in Computer Science/IT/C cybersecurity
Microsoft Certified: Azure Security Engineer Associate
CISSP/GCED/GCIA (preferred)

Tools

Azure Sentinel
Defender for Endpoint
KQL

Job description

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

The opportunity

Ernst & Young is seeking junior and intermediate-level technical security professionals with hands‑on expertise in Microsoft Sentinel and Microsoft Defender to support our Managed Detection and Response (MDR) services within a Security Operations Center (SOC) environment.

This role is designed for an experienced Tier 1 / Tier 2 SOC Analyst who performs threat detection, investigation, and response activities. The successful candidate will operate in a client‑facing MSSP environment and will contribute directly to the quality, effectiveness, and continuous improvement of EY’s MDR services.

This job posting relates to an existing vacancy within our organization.

Your key responsibilities:

Working with our technical team and clients the candidate will be responsible for:

Security Monitoring and Incident Response
  • Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks.
  • Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios.
  • Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud‑native audit logs.
  • Validate, scope, and document security incidents, including root cause analysis and impact assessment.
  • Assist with containment and recovery under senior guidance.
Detection Engineering and Use Case Development
  • Support tuning and maintenance of Sentinel analytics rules.
  • Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources.
  • Document detection gaps
  • Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment.
Threat Hunting
  • Support threat hunting activities
  • Identify anomalous or suspicious activity that may not trigger existing detections.
  • Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps.
Client Engagement and Technical Advisory
  • Communicating incident findings clearly
  • Participating in client calls when required
  • Supporting onboarding and steady‑state operations
  • Support senior team members in identifying logging, configuration improvements.
  • Support onboarding and steady‑state operations for MDR clients within a managed services context.
Operational Excellence
  • Contribute to playbooks and procedural improvements.
  • Participate in knowledge sharing and case reviews.
  • Assist with service quality improvements, detection maturity, and operational consistency across clients.
  • Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements.
Key Requirements:
  • Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level.
  • Hands‑on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations.
  • Experience with Microsoft Defender technologies, including Defender for Endpoint and identity‑related signals.
  • Exposure to investigations across cloud, endpoint, and identity domains.
  • Working understanding of attack techniques, threat actor behaviors, and incident response methodologies.
  • Ability to manage multiple investigations simultaneously while maintaining investigation quality and documentation.
  • Strong written and verbal communication skills, with the ability to explain technical findings to security‑focused audiences.
  • Proficiency in French, including Quebec French, is desired for client facing engagements.
Qualifications:
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Relevant certifications such as:
  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Sentinel specialization
  • CISSP, GCED, GCIA, or similar (preferred, not required)
  • Minimum 1-2 years of experience in cybersecurity operations, with significant time spent in incident response and security monitoring roles.
  • Prior experience in a client‑facing or managed services environment is strongly preferred

EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.

  • Toronto, Calgary, Vancouver : $65,500 - $99,000
  • Ottawa, St. John's : $62,500 - $94,000
  • Halifax, Saint John, Dieppe, Victoria : $59,000 - $89,000
Inclusiveness at EY

Inclusiveness is the heart of who we are and how we work. We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation. Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.

Learn about our commitment to Inclusiveness at https://www.ey.com/en_ca/about-us/corporate-responsibility/equity

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

At EY, we use artificial intelligence (AI) tools as one element of our recruitment process to enhance efficiency and improve the candidate experience. While AI supports us in our process, human judgment and decision‑making remain integral in our candidate experience. We are committed to the responsible use of AI, and our practices are continuously reviewed and refined to ensure they align with ethical principles and regulatory requirements.

To all recruitment agencies: EY does not accept unsolicited resumes from recruitment agencies. Any resumes submitted without a prior agreement or request from our hiring team will not be considered. EY is not responsible for any fees related to unsolicited resumes.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Victoria

On-site
CAD 59,000 - 89,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Halifax

On-site
CAD 59,000 - 89,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Toronto

Hybrid
CAD 66,000 - 99,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Vancouver

On-site
CAD 66,000 - 99,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Dieppe

On-site
CAD 59,000 - 89,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Calgary

On-site
CAD 66,000 - 99,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

Ernst & Young Advisory Services Sdn Bhd • Toronto

On-site
CAD 63,000 - 94,000
Cybersecurity - Cloud Security - Senior Consultant
Cybersecurity - Cloud Security - Senior Consultant

EY • Edmonton

On-site
CAD 90,000 - 136,000
Medical coverage
Dental coverage
Pension plan
+2
Cybersecurity - Cloud Security - Senior Consultant
Cybersecurity - Cloud Security - Senior Consultant

Ernst & Young Advisory Services Sdn Bhd • Toronto

On-site
CAD 90,000 - 136,000
Cybersecurity - Data Protection - Senior Consultant
Cybersecurity - Data Protection - Senior Consultant

EY • Calgary

On-site
CAD 90,000 - 136,000
Support and coaching from some of the
Learning opportunities to develop new
The freedom and flexibility to handle