About The Position

Ernst & Young is seeking junior and intermediate-level technical security professionals with hands-on expertise in Microsoft Sentinel and Microsoft Defender to support our Managed Detection and Response (MDR) services within a Security Operations Center (SOC) environment. This role is designed for an experienced Tier 1 / Tier 2 SOC Analyst who performs threat detection, investigation, and response activities. The successful candidate will operate in a client-facing MSSP environment and will contribute directly to the quality, effectiveness, and continuous improvement of EY’s MDR services. This job posting relates to an existing vacancy within our organization.

Requirements

  • Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level.
  • Hands-on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations.
  • Experience with Microsoft Defender technologies, including Defender for Endpoint and identity-related signals.
  • Exposure to investigations across cloud, endpoint, and identity domains.
  • Working understanding of attack techniques, threat actor behaviors, and incident response methodologies.
  • Ability to manage multiple investigations simultaneously while maintaining investigation quality and documentation.
  • Strong written and verbal communication skills, with the ability to explain technical findings to security-focused audiences.
  • Proficiency in French, including Quebec French, is desired for client facing engagements.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Relevant certifications such as: Microsoft Certified: Azure Security Engineer Associate, Microsoft Sentinel specialization, CISSP, GCED, GCIA, or similar (preferred, not required)
  • Minimum 1-2 years of experience in cybersecurity operations, with significant time spent in incident response and security monitoring roles.
  • Prior experience in a client-facing or managed services environment is strongly preferred

Nice To Haves

  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Sentinel specialization
  • CISSP, GCED, GCIA, or similar

Responsibilities

  • Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks.
  • Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios.
  • Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud-native audit logs.
  • Validate, scope, and document security incidents, including root cause analysis and impact assessment.
  • Assist with containment and recovery under senior guidance.
  • Support tuning and maintenance of Sentinel analytics rules.
  • Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources.
  • Document detection gaps.
  • Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment.
  • Support threat hunting activities.
  • Identify anomalous or suspicious activity that may not trigger existing detections.
  • Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps.
  • Communicating incident findings clearly.
  • Participating in client calls when required.
  • Supporting onboarding and steady-state operations.
  • Support senior team members in identifying logging, configuration improvements.
  • Support onboarding and steady-state operations for MDR clients within a managed services context.
  • Contribute to playbooks and procedural improvements.
  • Participate in knowledge sharing and case reviews.
  • Assist with service quality improvements, detection maturity, and operational consistency across clients.
  • Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements.

Benefits

  • EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service