More jobs:
Senior Security Operations Analyst - Microsoft Sentinel and Defender
Job Description & How to Apply Below
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
The opportunity EY is seeking a senior, hands-on security operations analyst to support Managed Detection and Response services in a multi-customer Managed Security Service Provider environment.
You will lead complex security incident investigations using Microsoft Sentinel and Microsoft Defender XDR, perform threat hunting and detection tuning, and improve response workflows through Microsoft Sentinel automation rules, playbooks, and Azure Logic Apps. You will work across multiple customer environments, provide technical guidance to other analysts, and communicate clear findings and response recommendations to clients.
The successful candidate will bring strong investigative judgement, advanced Microsoft security platform experience, and the ability to manage concurrent incidents and priorities in a client-facing environment.
This job posting relates to an existing vacancy within our organization.
Your key responsibilities:
As a senior technical member of the security operations team, you will:
Security incident investigation and response Lead the triage and investigation of complex or high-severity security incidents across multiple customer environments.
Correlate endpoint, identity, email, cloud, network, and threat intelligence evidence to determine incident scope, root cause, and business impact.
Develop investigation timelines, document evidence, identify attacker activity, and recommend containment and remediation actions.
Coordinate escalations and response activities with clients, internal teams, and other technical specialists.
Produce clear incident records, client communications, and post-incident findings.
Microsoft Sentinel and Defender operations Use Microsoft Sentinel and Microsoft Defender XDR to investigate, prioritize, and respond to security alerts and incidents.
Investigate activity across Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
Write and optimize Kusto Query Language queries for incident investigation, threat hunting, reporting, and detection validation.
Review and tune analytics rules, hunting queries, workbooks, watchlists, parsers, and related detection content.
Identify gaps in telemetry, detection coverage, and platform configuration, then recommend practical improvements.
Automation and continuous improvement Design, build, test, and maintain Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.
Automate incident enrichment, triage, notification, ticketing, evidence collection, and approved containment actions.
Troubleshoot playbook failures, integration issues, permissions, API connections, and workflow reliability.
Improve analyst workflows and standard operating procedures based on incident lessons, recurring alert patterns, and service metrics.
Apply appropriate approvals, access controls, logging, and error handling to automated response actions.
MSSP service delivery Manage investigations and technical priorities across multiple customers with different environments, procedures, and service commitments.
Follow customer-specific rules of engagement, escalation paths, response procedures, and service-level requirements.
Work directly with client security and technology teams to gather context, explain findings, and recommend next steps.
Support onboarding and operational improvement of customer environments, including data connectors, telemetry validation, and incident workflows.
Provide technical coaching and peer review to other…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×