Apply now »

Security Engineer - EY Global Delivery Services

Location:  CABA
Other locations:  Primary Location Only
Salary: Competitive
Date:  Sep 11, 2026

Job description

Requisition ID:  1739789

STS Lab Operations Engineer (Rank 64)

 

The Opportunity

The EY Security Technology Services (STS) Lab is the innovation and engineering engine behind EY's global cybersecurity platform. As a Lab Operations & Access Engineer at the Supervising Associate level within the STS Lab team in GDS Argentina, you will be the hands-on operational backbone of the lab's day-to-day functioning. You will own lab account provisioning, RBAC governance, shared asset management, and request fulfillment — ensuring that engineers, architects, and SMEs across IAM, Defender XDR, Sentinel, and Purview can work in well-governed, properly segmented lab environments. You will work closely with the STS Lab Lead, Cloud Platform Security Architects, and the Configuration & Automation Engineering team to maintain the operational health and access integrity of the lab's Microsoft Fabric and Azure-based building blocks.

Your Key Responsibilities

  • Lab Account Management — Provision, maintain, and decommission lab user accounts across Azure AD / Entra ID, Microsoft 365, and Fabric tenants following defined lifecycle processes.
  • RBAC & Access Governance — Design, implement, and audit Role-Based Access Control across Azure subscriptions, Fabric workspaces, Microsoft Defender, and Microsoft Sentinel environments; enforce least-privilege principles.
  • Shared Asset Management — Track and govern shared lab resources including virtual machines, shared credentials vaults, and network segments to prevent configuration drift.
  • Serve as the first point of contact for day-to-day lab support requests; triage access issues, environment faults, and provisioning requests with defined SLAs.
  • Azure Portal Deployments — Execute controlled deployments through the Azure Portal and ARM/Bicep templates for new lab resources; coordinate change approvals and maintain deployment logs.
  • GitHub Workflows — Manage lab access request pipelines and change tracking via GitHub Issues and pull requests; contribute to automation scripts and GitHub Actions workflows that streamline provisioning.
  • Microsoft Defender Integration — Support onboarding of lab endpoints and identities to Microsoft Defender for Endpoint and Defender for Identity; validate policy assignments and alert suppression rules for lab environments.
  • Documentation & Runbooks — Produce and maintain clear operational runbooks, access matrices, and asset registers that other team members can execute independently.
  • Cross-functional Collaboration — Coordinate with IAM, Defender/Sentinel, Purview, and Endpoint Security SMEs to ensure access models align with engineering needs.

 

Skills and Attributes for Success

We are interested in people who bring operational discipline and a security-first mindset from supporting large enterprises or lab environments. As a successful candidate you will have functional, technical, and hands-on delivery experience with Azure access management, Microsoft security tooling, and structured request handling.

  • Azure Portal proficiency — comfortable navigating, deploying, and governing resources across multiple Azure subscriptions and Entra ID tenants.
  • RBAC expertise — proven ability to design and implement role assignments at Tenant, Management Group, Subscription, Resource Group, and Resource level.
  • GitHub fluency — experience using GitHub for issue tracking, pull requests, and basic GitHub Actions for automation; familiarity with GitHub Copilot is a plus.
  • Microsoft Defender awareness — working knowledge of Defender for Endpoint, Defender for Identity, or Defender for Cloud, particularly around onboarding and policy configuration.
  • Operational mindset — structured, detail-oriented, and able to manage multiple concurrent requests without losing track of asset state or access entitlements.
  • Communication — fluent English, written and verbal; able to translate technical access requirements into clear, auditable records.
  • Collaboration — comfortable working across globally distributed, culturally diverse teams and able to coordinate without formal authority.

 

To Qualify for the Role, You Must Have

  • 3–5 years of experience in IT Operations, Cloud Operations, or Security Engineering with demonstrable hands-on work in access management or lab/environment support.
  • Technical proficiency with Microsoft Azure: Azure Portal, Entra ID (Azure AD), RBAC, Subscriptions, and Resource Management.
  • Hands-on experience with GitHub for operational workflows — issue tracking, branching, and pull request management.
  • Working knowledge of Microsoft Defender products (Defender for Endpoint, Defender for Identity, or Defender for Cloud).
  • Experience managing shared infrastructure assets and maintaining accurate asset inventories.
  • Strong troubleshooting and triage skills; ability to resolve access and environment issues methodically.
  • Ability to document processes and produce runbooks for global distribution.

 

Ideally, You Will Also Have

  • Bachelor’s degree in computer science, Engineering, IT, or a related field — or equivalent work experience.
  • Microsoft certification: AZ-104 (Azure Administrator), SC-300 (Identity and Access Administrator), or SC-200 (Security Operations Analyst).
  • Familiarity with Microsoft Fabric capacities, workspace, and domain management.
  • Experience with PowerShell or Python scripting for automated provisioning and access review tasks.
  • Exposure to Microsoft Sentinel, Purview, or Entra Privileged Identity Management (PIM).
  • Background in ITSM tooling (ServiceNow or similar) for structured request and change management.
  • Security certification: GSEC, CompTIA Security+, or equivalent.

 

What We Look For

This role is perfect for you if you combine operational reliability with a genuine curiosity for security tooling. We are looking for people who:

  • Bring governance rigor — access matrices are kept current, assets are tagged, and every change is logged.
  • Own the queue: when a request comes in, it gets resolved — and the fix gets documented.
  • Are comfortable operating as a trusted gatekeeper in a fast-moving lab environment where new tools are constantly being evaluated.
  • Operate with a startup mindset inside a large global organization — proactive, adaptable, and solutions-oriented.

 

 

What We Offer

  • Continuous learning: Access to EY's global learning platforms, technical training, and certification sponsorship.
  • Success as defined by you: Tools and flexibility to make a significant impact — deepen your technical specialization or grow into cloud engineering or architecture roles.
  • Transformative leadership: Coaching and confidence-building to help you grow as a technical leader globally.
  • Diverse and inclusive culture: You will be accepted for who you are; flexible working arrangements supported.
  • Competitive compensation aligned to the Argentine senior technology market, including performance-based incentives.

 

Apply now »