Security Operations Analyst) - Consultant at EY
Canada, Ontario, Canada -
Full Time


Start Date

Immediate

Expiry Date

22 Nov, 26

Salary

0.0

Posted On

24 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description

Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks

Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios

Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud-native audit logs


Validate, scope, and document security incidents, including root cause analysis and impact assessment


Assist with containment and recovery under senior guidance


Support tuning and maintenance of Sentinel analytics rules


Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources


Document detection gaps


Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment


Support threat hunting activities


Identify anomalous or suspicious activity that may not trigger existing detections


Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps


Communicating incident findings clearly


Participating in client calls when required


Supporting onboarding and steady-state operations


Support senior team members in identifying logging, configuration improvements


Support onboarding and steady-state operations for MDR clients within a managed services context


Contribute to playbooks and procedural improvements


Participate in knowledge sharing and case reviews


Assist with service quality improvements, detection maturity, and operational consistency across clients


Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements

Qualification

checkRepresents the skills you have

Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.

Microsoft SentinelKusto Query Language (KQL)Microsoft Defender for EndpointSecurity Operations Center (SOC) OperationsManaged Security Service Provider (MSSP) OperationsIncident ResponseSecurity MonitoringThreat HuntingCloud, Endpoint, and Identity InvestigationsAttack Techniques and Threat Actor BehaviorMicrosoft Certified Azure Security Engineer AssociateCISSPGCEDGCIAClient-facing communicationFrenchWritten and verbal communicationRequired

Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level

Hands-on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations

Experience with Microsoft Defender technologies, including Defender for Endpoint and identity-related signals

Exposure to investigations across cloud, endpoint, and identity domains

Working understanding of attack techniques, threat actor behaviors, and incident response methodologies

Ability to manage multiple investigations simultaneously while maintaining investigation quality and documentation

Strong written and verbal communication skills, with the ability to explain technical findings to security-focused audiences

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline

Relevant certifications such as:

o    Microsoft Certified: Azure Security Engineer Associate

o    Microsoft Sentinel specialization

o    CISSP, GCED, GCIA, or similar (preferred, not required)

Minimum 1-2 years of experience in cybersecurity operations, with significant time spent in incident response and security monitoring roles

Preferred

Proficiency in French, including Quebec French, is desired for client facing engagements

Prior experience in a client-facing or managed services environment is strongly preferred

Responsibilities
Loading...