Senior Consultant - Microsoft Sentinel and Defender Engineer
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, Azure, Systems Engineer, Cloud Computing: Infrastructure & Operations
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
The opportunityEY is seeking a senior, hands-on Microsoft security engineer to support the design, implementation, and continuous improvement of our Managed Detection and Response (MDR) services. You will work directly with clients and delivery teams to architect and deploy Microsoft Sentinel, engineer detections and security use cases, build automation with Azure Logic Apps, develop operational workbooks, and integrate Microsoft Defender solutions. You will also help onboard and operate customer environments through Azure Lighthouse and Microsoft Entra B2B.
The successful candidate combines deep engineering experience with clear client communication, practical problem solving, and ownership from design through production support.
This job posting relates to an existing vacancy within our organization.
Your role at a glanceKey Responsibilities
As a senior technical member of the MDR team, you will:
Microsoft Sentinel architecture and implementation- Lead the technical design and implementation of Microsoft Sentinel SIEM and SOAR solutions for new and existing MDR clients.
- Design workspace, data ingestion, retention, access-control, and multi-tenant operating models that account for security, regulatory, scalability, and cost requirements.
- Configure Microsoft Sentinel in the Microsoft Defender portal, Log Analytics work spaces, data connectors, diagnostic settings, content solutions, watchlists, and supporting Azure resources.
- Detection engineering and threat analytics
- Create, test, tune, document, and maintain analytics rules, hunting queries, parsers, and functions using Kusto Query Language (KQL).
- Translate threat scenarios, intelligence, customer risks, and operational requirements into practical detection use cases mapped to recognized frameworks such as MITRE ATT&CK.
- Integrate and correlate telemetry from Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra , Azure, Microsoft 365, and third-party security technologies.
- Automation, orchestration, and reporting
- Design, build, secure, and troubleshoot Microsoft Sentinel automation rules and playbooks using Azure Logic Apps.
- Automate incident enrichment, triage, notification, containment, remediation, ticketing, and evidence collection across Microsoft and third-party systems.
- Develop Microsoft Sentinel workbooks and service dashboards that provide actionable views of threats, incidents, coverage, operational performance, and data ingestion.
- Multi-tenant onboarding and engineering
- Design and implement secure cross-tenant access using Azure Lighthouse and Microsoft Entra B2B collaboration.
- Work with customer identity, cloud, network, and security teams to establish permissions, managed identities, service principals, and least-privilege role assignments.
- Troubleshoot complex onboarding, data-connector, ingestion, query, automation, and access issues across customer environments.
- MDR service engineering and client collaboration
- Provide senior technical support for incident investigation, threat hunting, detection tuning, platform health, and continuous service improvement.
- Lead technical workshops, gather requirements, explain design decisions, and provide clear recommendations to client security and technology stakeholders.
- Produce solution designs, deployment plans, runbooks, testing evidence, operational documentation, and knowledge-transfer material.
- Provide technical guidance and peer review to engineers and analysts without direct people-management responsibility.
- Substantial…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).