GMS - Senior - Cloud Access Security
EY
EY
Join EY and embark on a career defined by your unique contributions. As a Senior Cloud Access Security professional, you'll leverage global scale, supportive culture, and advanced technology to foster your professional growth. Your distinct perspective will be instrumental in enhancing EY's capabilities, creating an exceptional experience for yourself and contributing to a better working world for everyone.
As a Senior Cloud Access Security Analyst, your core duties involve actively triaging SaaS alerts within the Microsoft Defender portal, enriching them with crucial context such as user, application, IP, and activity details. You will meticulously monitor Cloud Discovery findings to identify and flag Shadow IT risks for review. Maintaining accurate ticket updates, ensuring evidence is captured, and facilitating smooth shift handoffs are essential, adhering strictly to runbooks for SaaS incidents.
Your role will extend to leading investigations into suspicious SaaS activities, risky OAuth applications, and anomalous data access patterns. You'll conduct in-depth analysis across Cloud App entities to determine the scope of impact, pinpoint root causes, and propose effective containment strategies, including guidance on session revocation, app governance, and permission reviews. Furthermore, you'll optimize policies to minimize false positives, define sanctioned versus unsanctioned workflows, and generate comprehensive monthly SaaS risk reports.
We are seeking professionals with proven familiarity in triaging security alerts within the Defender portal and experience working with ITSM systems. A strong foundation in SaaS security concepts, including recognizing risky user behaviors, identifying data exfiltration indicators, and spotting admin activity red flags, is crucial. Demonstrable understanding of how Cloud Applications connect to SaaS, utilizing API-based visibility and controls, is essential.
Candidates must possess robust incident investigation skills, particularly within Defender portal workflows for Cloud Apps. A solid grasp of SaaS identity risk patterns and the nuances of OAuth permission abuse is expected. A functional understanding of API connector behavior and its inherent constraints will be highly valued. Preferred qualifications include a minimum of 3 years in Cloud technology, with a focus on CASB or Security Engineering roles, and a high-level awareness of Cloud Discovery ingestion concepts (both log-based and API-based). The ideal candidate can seamlessly integrate CASB and web security operations, maintaining strong SaaS risk visibility and disciplined policy tuning.
EY Global Delivery Services ( EY GDS)
Management Consulting