Senior Consultant

4 days ago

Winnipeg, Manitoba, Canada Socket.dev Full-time
At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

The opportunity EY is seeking a senior, hands‑on Microsoft security engineer to support the design, implementation, and continuous improvement of our Managed Detection and Response (MDR) services. You will work directly with clients and delivery teams to architect and deploy Microsoft Sentinel, engineer detections and security use cases, build automation with Azure Logic Apps, develop operational workbooks, and integrate Microsoft Defender solutions. You will also help onboard and operate customer environments through Azure Lighthouse and Microsoft Entra B2B. The successful candidate combines deep engineering experience with clear client communication, practical problem solving, and ownership from design through production support.

This job posting relates to an existing vacancy within our organization.

Your role at a glance Key responsibilities As a senior technical member of the MDR team, you will:

Microsoft Sentinel architecture and implementation

Lead the technical design and implementation of Microsoft Sentinel SIEM and SOAR solutions for new and existing MDR clients.

Design workspace, data ingestion, retention, access-control, and multi‑tenant operating models that account for security, regulatory, scalability, and cost requirements.

Configure Microsoft Sentinel in the Microsoft Defender portal, Log Analytics workspaces, data connectors, diagnostic settings, content solutions, watchlists, and supporting Azure resources.

Detection engineering and threat analytics

Create, test, tune, document, and maintain analytics rules, hunting queries, parsers, and functions using Kusto Query Language (KQL).

Translate threat scenarios, intelligence, customer risks, and operational requirements into practical detection use cases mapped to recognized frameworks such as MITRE ATT&CK.

Integrate and correlate telemetry from Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure, Microsoft 365, and third‑party security technologies.

Automation, orchestration, and reporting

Design, build, secure, and troubleshoot Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.

Automate incident enrichment, triage, notification, containment, remediation, ticketing, and evidence collection across Microsoft and third‑party systems.

Develop Microsoft Sentinel workbooks and service dashboards that provide actionable views of threats, incidents, coverage, operational performance, and data ingestion.

Multi‑tenant onboarding and engineering

Design and implement secure cross‑tenant access using Azure Lighthouse and Microsoft Entra B2B collaboration.

Work with customer identity, cloud, network, and security teams to establish permissions, managed identities, service principals, and least‑privilege role assignments.

Troubleshoot complex onboarding, data‑connector, ingestion, query, automation, and access issues across customer environments.

MDR service engineering and client collaboration

Provide senior technical support for incident investigation, threat hunting, detection tuning, platform health, and continuous service improvement.

Lead technical workshops, gather requirements, explain design decisions, and provide clear recommendations to client security and technology stakeholders.

Produce solution designs, deployment plans, runbooks, testing evidence, operational documentation, and knowledge‑transfer material.

Provide technical guidance and peer review to engineers and analysts without direct people‑management responsibility.

Skills and attributes for success

Substantial hands‑on experience designing, implementing, and operating Microsoft Sentinel in enterprise or managed‑service environments.

Advanced KQL skills and demonstrated experience developing analytics rules, hunting queries, functions, parsers, workbooks, and detection content.

Strong experience with Microsoft Defender XDR, including relevant Defender products across endpoints, identity, email and collaboration, cloud apps, and cloud workloads.

Hands‑on experience building Azure Logic Apps, Microsoft Sentinel playbooks, and automation rules, including API‑based integration, authentication, permissions, error handling, and monitoring.

Experience architecting Microsoft Sentinel deployments, including workspace strategy, data connectors, ingestion and retention, role‑based access control, and operational cost management.

Experience implementing and supporting multi‑tenant access with Azure Lighthouse and Microsoft Entra