Senior Security Operations Analyst: MS Sentinel & Defender MDR

EY

Calgary

On-site

CAD 76,000 - 126,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

EY is seeking a senior, hands-on security operations analyst to support MDR services across multiple client environments. You will lead incident investigations using Microsoft Sentinel and Defender XDR, conduct threat hunting, and improve response workflows with automation rules and Azure Logic Apps.

You will provide technical guidance to analysts, manage concurrent incidents, and communicate findings and recommendations to clients in a clear, professional manner.

Qualifications

  • Senior-level cybersecurity experience in a Security Operations Centre, MDR, or incident response environment.
  • Microsoft Sentinel and Defender XDR in production environments.
  • Experience supporting multiple customers in an MSSP/MDR environment is strongly preferred.
  • Advanced Kusto Query Language skills for investigation, threat hunting, detection development, and reporting.
  • Hands-on experience creating and maintaining Microsoft Sentinel analytics rules, hunting queries, workbooks, automation rules, and playbooks.
  • Experience building Azure Logic Apps for security orchestration and response, including connectors, APIs, authentication, permissions, error handling, and monitoring.

Responsibilities

  • Lead the triage and investigation of complex or high-severity security incidents across multiple customer environments.
  • Correlate endpoint, identity, email, cloud, network, and threat intelligence evidence to determine incident scope, root cause, and business impact.
  • Develop investigation timelines, document evidence, identify attacker activity, and recommend containment and remediation actions.
  • Coordinate escalations and response activities with clients, internal teams, and other technical specialists.
  • Produce clear incident records, client communications, and post-incident findings.
  • Design, tune, and maintain analytics rules, hunting queries, and playbooks to improve detection and response.

Skills

Microsoft Sentinel
Microsoft Defender XDR
Kusto Query Language
Azure Logic Apps
Incident response
Threat hunting
Customer-facing

Education

Bachelor's degree or diploma in cybersecurity, computer science, information technology, engineering

Tools

ServiceNow
Microsoft Defender for Endpoint

Job description

EY is seeking a senior, hands-on security operations analyst to support MDR services across multiple client environments. You will lead incident investigations using Microsoft Sentinel and Defender XDR, conduct threat hunting, and improve response workflows with automation rules and Azure Logic Apps.

You will provide technical guidance to analysts, manage concurrent incidents, and communicate findings and recommendations to clients in a clear, professional manner.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Operations Analyst: Sentinel & Defender
Senior Security Operations Analyst: Sentinel & Defender

EY • Calgary

On-site
CAD 90,000 - 130,000
Senior Microsoft Sentinel & Defender MDR Engineer
Senior Microsoft Sentinel & Defender MDR Engineer

EY • Southwestern Ontario

On-site
CAD 91,000 - 126,000
Medical coverage
Dental coverage
Pension plan
+1
Senior Microsoft Sentinel & Defender MDR Engineer
Senior Microsoft Sentinel & Defender MDR Engineer

EY • Calgary

On-site
CAD 91,000 - 126,000
Medical, prescription drug, and dental
Pension plan
Generous vacation policy
+2
Senior Microsoft Sentinel & Defender MDR Engineer
Senior Microsoft Sentinel & Defender MDR Engineer

EY • San Juan de Terranova

On-site
CAD 91,000 - 126,000
Support and coaching
Learning opportunities
Flexible work arrangements
Senior Microsoft Sentinel & Defender MDR Engineer
Senior Microsoft Sentinel & Defender MDR Engineer

EY • Winnipeg

On-site
CAD 91,000 - 126,000
Medical coverage
Pension plan
Vacation policy
+4
Senior Microsoft Sentinel & Defender Security Engineer
Senior Microsoft Sentinel & Defender Security Engineer

EY • Edmonton

On-site
CAD 91,000 - 126,000
Senior Security Operations Analyst - Microsoft Sentinel and Defender (Calgary, AB, CA, T2P 1M4)
Senior Security Operations Analyst - Microsoft Sentinel and Defender (Calgary, AB, CA, T2P 1M4)

EY • Calgary

On-site
CAD 90,000 - 130,000
Senior Security Operations Analyst - Microsoft Sentinel and Defender
Senior Security Operations Analyst - Microsoft Sentinel and Defender

Ernst & Young Advisory Services Sdn Bhd • Calgary

On-site
CAD 91,000 - 126,000
Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)
Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Calgary

On-site
CAD 110,000 - 150,000
Senior Consultant - Microsoft Sentinel and Defender Engineer
Senior Consultant - Microsoft Sentinel and Defender Engineer

Ernst & Young Advisory Services Sdn Bhd • Calgary

On-site
CAD 91,000 - 126,000
Medical and dental coverage
Pension plan (defined contribution)
Generous vacation policy and paid days
+1