KanzleiweltKanzleiwelt
EY Ernst & Young GmbH Wirtschaftsprüfungsgesellschaft

Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY Ernst & Young GmbH Wirtschaftsprüfungsgesellschaft

📍 EschbornSteuerberater & WPVollzeit🏢 Sehr große Unternehmen (>1.000 MA)

Sie werden zur Karriereseite des Arbeitgebers weitergeleitet.

Details

Unternehmen
EY Ernst & Young GmbH Wirtschaftsprüfungsgesellschaft
Standort
Eschborn
Bereich
Steuerberater & WP
Vertragsart
Vollzeit
Unternehmensgröße
Sehr große Unternehmen (>1.000 MA)
Aktualisiert
4. September 2026

Interesse an dieser Stelle?

Klicken Sie auf "Jetzt bewerben" um direkt zur Stellenausschreibung des Arbeitgebers zu gelangen. Die Bewerbung erfolgt direkt beim Arbeitgeber.

Zur Bewerbung →

Sie suchen Kanzlei-Profis? Zusammenarbeit anfragen →

Stellenbeschreibung

Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

Location: Toronto

Other locations: Primary Location Only

Salary: Competitive

Date: Aug 13, 2026

Job description

Requisition ID: 1735659

At EY, were all in to shape your future with confidence.

Well help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

The opportunity

Ernst & Young is seeking junior and intermediate-level technical security professionals with hands-on expertise in Microsoft Sentinel and Microsoft Defender to support our Managed Detection and Response (MDR) services within a Security Operations Center (SOC) environment.

This role is designed for an experienced Tier 1 / Tier 2 SOC Analyst who performs threat detection, investigation, and response activities. The successful candidate will operate in a client-facing MSSP environment and will contribute directly to the quality, effectiveness, and continuous improvement of EYs MDR services.

This job posting relates to an existing vacancy within our organization.

Your key responsibilities:

Working with our technical team and clients the candidate will be responsible for:

Security Monitoring and Incident Response

Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks.

Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios.

Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud-native audit logs.

Validate, scope, and document security incidents, including root cause analysis and impact assessment.

Assist with containment and recovery under senior guidance.

Detection Engineering and Use Case Development

Support tuning and maintenance of Sentinel analytics rules.

Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources.

Document detection gaps

Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment.

Threat Hunting

Support threat hunting activities

Identify anomalous or suspicious activity that may not trigger existing detections.

Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps.

Client Engagement and Technical Advisory

Communicating incident findings clearly

Participating in client calls when required

Supporting onboarding and steady-state operations

Support senior team members in identifying logging, configuration improvements.

Support onboarding and steady-state operations for MDR clients within a managed services context.

Operational Excellence

Contribute to playbooks and procedural improvements.

Participate in knowledge sharing and case reviews.

Assist with service quality improvements, detection maturity, and operational consistency across clients.

Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements.

Key Requirements:

Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level.

Hands-on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations.

Experience with Microsoft Defender technologies, including Defender for Endpoint and identity-related signals.

Exposure to investigations across cloud, endpoint, and identity domains.

Auszug aus der Stellenausschreibung des Arbeitgebers. Die Bewerbung erfolgt über "Jetzt bewerben".

Sie sind der Arbeitgeber dieser Stelle? Die Stelle ist bereits besetzt, veraltet oder soll aus anderen Gründen entfernt werden? Stellenanzeige kostenlos entfernen lassen →

Mission Personal Jobportale

Spezialisierte Jobportale für jede Branche - alle aus dem Hause Mission Personal GmbH, Münster.