Ernst and Young

Senior Consultant - Microsoft Sentinel and Defender Engineer

Ernst and Young
Apply
1 day ago
Calgary, CanadaSenior

Responsibilities

  • Lead the technical design and implementation of Microsoft Sentinel SIEM and SOAR solutions for new and existing MDR clients.
  • Design workspace, data ingestion, retention, access-control, and multi-tenant operating models.
  • Configure Microsoft Sentinel, Log Analytics workspaces, data connectors, diagnostic settings, content solutions, watchlists, and supporting Azure resources.
  • Create, test, tune, document, and maintain analytics rules, hunting queries, parsers, functions, and detection use cases using Kusto Query Language.
  • Integrate telemetry from Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure, Microsoft 365, and third-party security technologies.
  • Build and troubleshoot Azure Logic Apps, Microsoft Sentinel playbooks, automation rules, incident workflows, and system integrations.
  • Develop Microsoft Sentinel workbooks and service dashboards for threats, incidents, coverage, operational performance, and data ingestion.
  • Implement secure cross-tenant access using Azure Lighthouse and Microsoft Entra B2B collaboration.
  • Establish permissions, managed identities, service principals, and least-privilege role assignments with customer teams.
  • Provide technical support for incident investigation, threat hunting, detection tuning, platform health, onboarding, and continuous service improvement.
  • Lead client workshops, gather requirements, explain design decisions, provide recommendations, and produce solution designs, deployment plans, runbooks, testing evidence, and operational documentation.
  • Provide technical guidance and peer review to engineers and analysts without direct people-management responsibility.

Requirements

  • Substantial hands-on experience designing, implementing, and operating Microsoft Sentinel in enterprise or managed-service environments.
  • Advanced Kusto Query Language skills and experience developing analytics rules, hunting queries, functions, parsers, workbooks, and detection content.
  • Strong experience with Microsoft Defender XDR and relevant Defender products across endpoints, identity, email and collaboration, cloud applications, and cloud workloads.
  • Hands-on experience building Azure Logic Apps, Microsoft Sentinel playbooks, and automation rules with API-based integration, authentication, permissions, error handling, and monitoring.
  • Experience architecting Microsoft Sentinel deployments covering workspace strategy, data connectors, ingestion, retention, role-based access control, and operational cost management.
  • Experience implementing and supporting multi-tenant access with Azure Lighthouse and Microsoft Entra B2B collaboration.
  • Understanding of incident response, threat hunting, detection engineering, security operations, and common threat frameworks such as MITRE ATT&CK.
  • Ability to lead client technical discussions, translate requirements into implementable designs, and communicate complex concepts clearly.
  • Ability to work independently, manage competing priorities, document work, review peer solutions, and own technical outcomes.
  • Experience in a client-facing consulting, MSSP, MDR, or enterprise security engineering role.
  • Bachelor's degree or diploma in computer science, information technology, cybersecurity, engineering, or a related discipline, or equivalent practical experience.
  • Typically seven or more years of cybersecurity experience, including significant recent Microsoft Sentinel and Defender engineering experience.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) is preferred.
  • Azure, identity, architecture, or security certifications are considered an asset.
  • Experience with source control, infrastructure as code, deployment automation for Microsoft Sentinel content, and integrations with IT service management, threat intelligence, network security, identity, endpoint, email, or cloud platforms is considered an asset.

Benefits

  • Competitive compensation package based on performance and value contributed.
  • Medical, prescription drug, and dental coverage.
  • Defined contribution pension plan.
  • Vacation policy, firm-paid days, statutory holidays, and paid personal days based on province of residence.
  • Programs and benefits supporting physical, financial, and social well-being.
  • Support and coaching from experienced colleagues.
  • Learning opportunities to develop new skills and progress your career.
  • Freedom and flexibility to handle the role in a way that is right for the employee.
  • The listed locations are Toronto, Calgary, Vancouver, and Edmonton, with an anticipated salary range of $90,500 to $126,000 per year.
  • EY promotes an inclusive workplace and provides accessibility, diversity, equity, and belonging initiatives.

Tech Stack

Categories

Ernst and Young

About Ernst and Young

10,000+ employees

Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.

Contact me