TC-CS-CDR-Splunk-Senior
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Service Line - Senior Splunk Engineer
Experience
- 3-7 years
About Global Delivery Services
Global Delivery Services refers to EY's worldwide network of service delivery centers. The GDS team plays an important role in EY's strategy by ensuring effective support to EY's growth agenda.
Our journey started in 2002 with approximately 200 people. Today we stand at 80,000+ professionals in ten locations around the world. We operate in Argentina, China, Hungary, India, Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom.
Client service is focused on providing Consulting, Assurance, Tax, Strategy & Transactions, and Knowledge support to our clients around the world. The teams enable account teams worldwide to provide seamless, high-quality, value-added support, helping deliver exceptional client service.
The Opportunity
EY is seeking a highly motivated Senior Splunk Engineer with 3-7 years of hands-on experience in Splunk Enterprise and Splunk Enterprise Security. The candidate will support the administration, optimization, and enhancement of Splunk environments while developing advanced security use cases, correlation searches, dashboards, and detection content. This role requires strong cybersecurity and SIEM expertise, along with the ability to collaborate with global teams to strengthen threat detection, monitoring, and response capabilities.
Your Key Responsibilities
- Administer and maintain Splunk Enterprise and Splunk Enterprise Security environments across distributed deployments.
- Manage Splunk components including indexers, search heads, deployment servers, heavy forwarders, universal forwarders, and clustered environments.
- Perform Splunk upgrades, patching, troubleshooting, health checks, performance tuning, and capacity planning.
- Onboard and normalize logs from Windows, Linux, cloud, network, security, application, and OT/IoT platforms.
- Create, maintain, and optimize data models, CIM mappings, field extractions, lookup tables, tags, event types, macros, and knowledge objects.
- Develop and tune correlation searches, notable events, risk-based alerts, adaptive responses, and security detection content in Splunk ES.
- Design dashboards, reports, and visualizations for SOC, threat hunting, incident response, operational monitoring, and leadership reporting.
- Write efficient SPL queries for threat detection, investigation, reporting, compliance, and operational use cases.
- Reduce false positives through alert tuning, suppression logic, risk scoring, and detection content optimization.
- Support the use-case lifecycle including requirement gathering, design, development, testing, deployment, documentation, and continuous improvement.
- Collaborate with SOC, Threat Intelligence, Incident Response, IAM, Cloud, Infrastructure, and client teams to improve detection coverage.
- Integrate Splunk with third-party security tools, ticketing platforms, and SOAR solutions where required.
Skills and Attributes for Success
Required Skills
- 3-7 years of experience in Splunk Enterprise, Splunk Enterprise Security, cybersecurity engineering.
- Strong understanding of Splunk architecture, distributed deployments, clustered environments, data ingestion, indexing, search optimization, and license management.
- Hands-on experience with Splunk ES features such as Incident Review, Risk-Based Alerting, threat intelligence framework, notable events, data models, and correlation searches.
- Advanced proficiency in SPL and experience building dashboards, reports, alerts, saved searches, and operational monitoring use cases.
- Practical experience with onboarding, parsing, normalizing, and troubleshooting logs from multiple enterprise technologies.
- Working knowledge of MITRE ATT&CK, Cyber Kill Chain, common attack techniques, and security analytics methodologies.
- Familiarity with Linux administration and scripting using Python, Bash, or PowerShell.
- Strong analytical thinking, problem-solving ability, documentation discipline, and communication skills.
Preferred Skills
- Experience with Splunk ES, content development, and splunk administration
- Relevant Splunk certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, or Splunk Cybersecurity Defense Analyst.
- Any cyber security certificate will be extra advantage
What We Look For
- A self-driven security professional with strong ownership and problem-solving mindset.
- Passion for cybersecurity, threat detection, security analytics, and continuous improvement.
- Ability to work effectively with global stakeholders, cross-functional teams, and client-facing teams.
- Clear communication style, strong documentation skills, and ability to explain technical concepts in a business-friendly manner.
- Willingness to learn emerging technologies and deliver high-quality outcomes in a fast-paced environment.
What We Offer You
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams.
Are you ready to shape your future with confidence? Apply today.
Our Commitment
Our Commitment: As a commitment, we persistently endeavour to embody our values, fulfil our purpose, and champion inclusiveness. Our dedication is to cultivate EY into an environment where diverse perspectives are celebrated, creating a supportive atmosphere for individuals to authentically be themselves and contribute their utmost.
Professional Development: From entry-level employees to senior leaders, we believe in continuous learning. We offer opportunities to build new skills, take on leadership roles, and connect and grow through mentorship.
People and Culture: In our dynamic workplace, diversity, equity, and inclusiveness are ingrained in our culture. We're united by a commitment to create an environment where every individual's differences are valued, practices are equitable, fostering a sense of belonging.
Benefits: Embark on a transformative career journey with us and indulge in a suite of premium benefits, encompassing exclusive health and wellness packages, enticing rewards, and cutting-edge learning opportunities that empower you to continually grow and excel in your professional and personal development.
How to Apply: If you are passionate to join us and are aligned with our commitment to building a better working world, we invite you to apply by completing the recruitment process and providing your consent to data privacy. Successful candidates advance to a competency-based interview. If mutual interest persists, a job offer awaits.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.