Senior Security Operations Analyst - Microsoft Sentinel and Defender

Ernst & Young Advisory Services Sdn Bhd

Calgary

On-site

CAD 91,000 - 126,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

EY is seeking a senior, hands-on Security Operations Analyst to support Managed Detection and Response services across multiple customer environments. You will lead investigations using Microsoft Sentinel and Defender XDR, perform threat hunting, tune detections, and automate response workflows with Azure Logic Apps.

You’ll provide guidance to analysts, communicate findings to clients, and manage competing priorities in a fast-paced MSSP/MDR setting while upholding strong incident documentation.

Qualifications

  • Typically, 5+ years of cybersecurity experience in security operations.
  • Bachelor’s degree or diploma in cybersecurity or related field.
  • Client-facing MSSP, MDR, consulting, or enterprise security operations experience.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) preferred.
  • Azure security certifications are assets.
  • Experience with ServiceNow or other ITSM is an asset.
  • Experience with Azure Lighthouse or multi-tenant access models is an asset.

Responsibilities

  • Lead triage and investigation of complex security incidents across multiple customer environments.
  • Correlate endpoint, identity, email, cloud, network, and threat intelligence evidence to determine incident scope and impact.
  • Develop investigation timelines, document evidence, identify attacker activity, and recommend containment actions.
  • Coordinate escalations and response activities with clients and other teams.
  • Produce clear incident records, client communications, and post‑incident findings.
  • Write and optimize Kusto Query Language queries for investigation and reporting.
  • Review analytics rules, hunting queries, workbooks, and detectors.
  • Design and maintain Sentinel automation rules and playbooks; improve analyst workflows.

Skills

Microsoft Sentinel
Microsoft Defender XDR
Kusto Query Language
Azure Logic Apps
Security incident investigation
MSSP/MDR experience

Education

Bachelor’s degree or diploma in cybersecurity or related field

Tools

ServiceNow
Azure

Job description

Senior Security Operations Analyst - Microsoft Sentinel and Defender

Other locations: Primary Location Only

Date: 23 Sept 2026

Requisition ID: 1747094

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

The opportunity

EY is seeking a senior, hands‑on security operations analyst to support Managed Detection and Response services in a multi‑customer Managed Security Service Provider environment.

You will lead complex security incident investigations using Microsoft Sentinel and Microsoft Defender XDR, perform threat hunting and detection tuning, and improve response workflows through Microsoft Sentinel automation rules, playbooks, and Azure Logic Apps. You will work across multiple customer environments, provide technical guidance to other analysts, and communicate clear findings and response recommendations to clients.

The successful candidate will bring strong investigative judgement, advanced Microsoft security platform experience, and the ability to manage concurrent incidents and priorities in a client‑facing environment.

Your key responsibilities:

As a senior technical member of the security operations team, you will:

Security incident investigation and response

  • Lead the triage and investigation of complex or high‑severity security incidents across multiple customer environments.
  • Correlate endpoint, identity, email, cloud, network, and threat intelligence evidence to determine incident scope, root cause, and business impact.
  • Develop investigation timelines, document evidence, identify attacker activity, and recommend containment and remediation actions.
  • Coordinate escalations and response activities with clients, internal teams, and other technical specialists.
  • Produce clear incident records, client communications, and post‑incident findings.

Microsoft Sentinel and Defender operations

  • Use Microsoft Sentinel and Microsoft Defender XDR to investigate, prioritize, and respond to security alerts and incidents.
  • Investigate activity across Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
  • Write and optimize Kusto Query Language queries for incident investigation, threat hunting, reporting, and detection validation.
  • Review and tune analytics rules, hunting queries, workbooks, watchlists, parsers, and related detection content.
  • Identify gaps in telemetry, detection coverage, and platform configuration, then recommend practical improvements.

Automation and continuous improvement

  • Design, build, test, and maintain Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.
  • Automate incident enrichment, triage, notification, ticketing, evidence collection, and approved containment actions.
  • Troubleshoot playbook failures, integration issues, permissions, API connections, and workflow reliability.
  • Improve analyst workflows and standard operating procedures based on incident lessons, recurring alert patterns, and service metrics.
  • Apply appropriate approvals, access controls, logging, and error handling to automated response actions.
  • Manage investigations and technical priorities across multiple customers with different environments, procedures, and service commitments.
  • Follow customer‑specific rules of engagement, escalation paths, response procedures, and service‑level requirements.
  • Work directly with client security and technology teams to gather context, explain findings, and recommend next steps.
  • Support onboarding and operational improvement of customer environments, including data connectors, telemetry validation, and incident workflows.
  • Provide technical coaching and peer review to other analysts without direct people‑management responsibility.

Skills and attributes for success

  • Senior‑level experience investigating complex cybersecurity incidents in a Security Operations Centre, Managed Detection and Response, or incident response environment.
  • Strong hands‑on experience with Microsoft Sentinel and Microsoft Defender XDR in production environments.
  • Experience supporting multiple customers in an MSSP or MDR environment is strongly preferred.
  • Advanced Kusto Query Language skills for investigation, threat hunting, detection development, and reporting.
  • Hands‑on experience creating and maintaining Microsoft Sentinel analytics rules, hunting queries, workbooks, automation rules, and playbooks.
  • Hands‑on experience building Azure Logic Apps for security orchestration and response, including connectors, APIs, authentication, permissions, error handling, and monitoring.
  • Experience investigating endpoint, identity, email, cloud, and network threats using Microsoft and third‑party telemetry.
  • Strong understanding of incident response, threat hunting, detection engineering, threat intelligence, and MITRE ATT&CK.
  • Ability to manage concurrent investigations and priorities while maintaining clear documentation and timely client communication.
  • Ability to explain technical findings, risk, and response recommendations to both technical and non‑technical stakeholders.
  • Sound judgement when working under pressure and handling high‑severity incidents.

To qualify for the role you must have

  • Typically, 5+ years of cybersecurity experience, including substantial recent experience in security operations and incident investigation.
  • Bachelor’s degree or diploma in cybersecurity, computer science, information technology, engineering, or a related discipline, or equivalent practical experience.
  • Experience in a client‑facing MSSP, MDR, consulting, or enterprise security operations role.
  • Microsoft Certified: Security Operations Analyst Associate, SC‑200, is preferred.
  • Azure, Microsoft security, incident response, digital forensics, or cloud security certifications are considered assets.
  • Experience with ServiceNow or another IT service management platform is considered an asset.
  • Experience with source control, infrastructure as code, CI/CD, or automated deployment of Microsoft Sentinel content is considered an asset.
  • Experience with Azure Lighthouse, Microsoft Entra B2B, or other multi‑tenant access models is considered an asset.

What working at EY offers

What we look for

We look for individuals who take initiative, demonstrate strong technical judgment, and show the ability to lead through influence. If you thrive in collaborative environments and are passionate about improving operational efficiency, this role is an excellent fit.

What we offer

We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you to decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a discretionary bonus program, a comprehensive medical, prescription drug and dental coverage plan, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well‑being. Plus, we offer:

  • Support and coaching from some of the most engaging colleagues in the industry
  • Learning opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that’s right for you

EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.

  • Toronto/London/Ottawa/Waterloo/Vancouver/Victoria/ Calgary/ Edmonton: $90,500 to $126,000

Inclusion at EY

Inclusiveness isit the heart of who we are and how we work.We’recommitted to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation. Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi‑disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Operations Analyst - Microsoft Sentinel and Defender
Senior Security Operations Analyst - Microsoft Sentinel and Defender

EY • Ottawa

On-site
CAD 91,000 - 126,000
Discretionary bonus
Medical coverage
Pension plan
+1
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

Socket.dev • Dieppe

On-site
CAD 91,000 - 126,000
Medical coverage
Dental coverage
Pension plan
+1
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

Ernst & Young Advisory Services Sdn Bhd • Calgary

On-site
CAD 91,000 - 126,000
Medical and dental coverage
Pension plan (defined contribution)
Generous vacation policy and paid days
+1
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

EY • Vancouver

On-site
CAD 91,000 - 126,000
Medical, prescription drug and dental 
Defined contribution pension plan
Generous vacation policy
+1
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

EY • Edmonton

On-site
CAD 91,000 - 126,000
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

EY • Calgary

On-site
CAD 91,000 - 126,000
Medical and dental coverage
Pension plan
Generous vacation policy
+2
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

EY • Toronto

On-site
CAD 91,000 - 126,000
Total Rewards package
Coaching and development
Learning opportunities
+1
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

EY • Winnipeg

On-site
CAD 91,000 - 126,000
Medical coverage
Pension plan
Vacation policy
+4
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

EY • Halifax

On-site
CAD 91,000 - 126,000
Senior Consultant - Microsoft Sentinel and Defender Engineer (Calgary, AB, CA, T2P 1M4)
Senior Consultant - Microsoft Sentinel and Defender Engineer (Calgary, AB, CA, T2P 1M4)

EY • Calgary

On-site
CAD 91,000 - 126,000
Medical, prescription drug, and dental
Pension plan
Generous vacation policy
+2