TC-CS-CDR-Splunk-Senior

Ernst & Young Advisory Services Sdn Bhd

Chennai District

On-site

INR 1,200,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Premium benefits
Global exposure

Job summary

Ernst & Young Advisory Services Sdn Bhd, based in India, seeks a Senior Splunk Engineer with 3-7 years of hands-on experience in Splunk Enterprise and Splunk Enterprise Security. The role focuses on administering and optimizing Splunk environments, developing advanced security use cases, dashboards, and detection content across global teams.

The candidate will collaborate with SOC, Threat Intelligence, Incident Response, IAM, and Cloud teams to strengthen threat detection, monitoring, and

Qualifications

  • 3-7 years of hands-on experience in Splunk Enterprise and Splunk Enterprise Security.
  • Strong understanding of Splunk architecture, distributed deployments, clustering, data ingestion, indexing, search optimization, and license management.
  • Hands-on experience with SPL, dashboards, alerts, and operational monitoring use cases.
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, and security analytics methodologies.

Responsibilities

  • Administer and maintain Splunk Enterprise and Splunk Enterprise Security across distributed deployments.
  • Manage indexers, search heads, deployment servers, heavy forwarders, universal forwarders, and clusters.
  • Perform upgrades, patching, troubleshooting, health checks, performance tuning, and capacity planning.
  • Onboard and normalize logs from Windows, Linux, cloud, network, security, and OT/IoT platforms.
  • Create and optimize data models, CIM mappings, field extractions, lookups, and knowledge objects.
  • Develop and tune correlation searches, notable events, risk-based alerts, and detection content in Splunk ES.
  • Design dashboards, reports, and visualizations for SOC, threat hunting, and incident response.
  • Write efficient SPL queries for threat detection, investigation, and reporting.
  • Reduce false positives through alert tuning and detection content optimization.
  • Collaborate with SOC, Threat Intelligence, IAM, Cloud, and client teams to improve detection coverage.

Skills

Splunk Enterprise
Splunk Enterprise Security
Cybersecurity engineering
SPL queries
Python/Bash scripting
Linux administration
MITRE ATT&CK knowledge

Tools

Splunk ES
Python
Linux

Job description

Experience
  • 3-7 years
About Global Delivery Services

Global Delivery Services refers to EY's worldwide network of service delivery centers. The GDS team plays an important role in EY's strategy by ensuring effective support to EY's growth agenda.

Our journey started in 2002 with approximately 200 people. Today we stand at 80,000+ professionals in ten locations around the world. We operate in Argentina, China, Hungary, India, Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom.

Client service is focused on providing Consulting, Assurance, Tax, Strategy & Transactions, and Knowledge support to our clients around the world. The teams enable account teams worldwide to provide seamless, high-quality, value-added support, helping deliver exceptional client service.

The Opportunity

EY is seeking a highly motivated Senior Splunk Engineer with 3-7 years of hands-on experience in Splunk Enterprise and Splunk Enterprise Security. The candidate will support the administration, optimization, and enhancement of Splunk environments while developing advanced security use cases, correlation searches, dashboards, and detection content. This role requires strong cybersecurity and SIEM expertise, along with the ability to collaborate with global teams to strengthen threat detection, monitoring, and response capabilities.

Your Key Responsibilities
  • Administer and maintain Splunk Enterprise and Splunk Enterprise Security environments across distributed deployments.
  • Manage Splunk components including indexers, search heads, deployment servers, heavy forwarders, universal forwarders, and clustered environments.
  • Perform Splunk upgrades, patching, troubleshooting, health checks, performance tuning, and capacity planning.
  • Onboard and normalize logs from Windows, Linux, cloud, network, security, application, and OT/IoT platforms.
  • Create, maintain, and optimize data models, CIM mappings, field extractions, lookup tables, tags, event types, macros, and knowledge objects.
  • Develop and tune correlation searches, notable events, risk-based alerts, adaptive responses, and security detection content in Splunk ES.
  • Design dashboards, reports, and visualizations for SOC, threat hunting, incident response, operational monitoring, and leadership reporting.
  • Write efficient SPL queries for threat detection, investigation, reporting, compliance, and operational use cases.
  • Reduce false positives through alert tuning, suppression logic, risk scoring, and detection content optimization.
  • Support the use-case lifecycle including requirement gathering, design, development, testing, deployment, documentation, and continuous improvement.
  • Collaborate with SOC, Threat Intelligence, Incident Response, IAM, Cloud, Infrastructure, and client teams to improve detection coverage.
  • Integrate Splunk with third-party security tools, ticketing platforms, and SOAR solutions where required.
Skills and Attributes for Success
Required Skills
  • 3-7 years of experience in Splunk Enterprise, Splunk Enterprise Security, cybersecurity engineering.
  • Strong understanding of Splunk architecture, distributed deployments, clustered environments, data ingestion, indexing, search optimization, and license management.
  • Hands-on experience with Splunk ES features such as Incident Review, Risk-Based Alerting, threat intelligence framework, notable events, data models, and correlation searches.
  • Advanced proficiency in SPL and experience building dashboards, reports, alerts, saved searches, and operational monitoring use cases.
  • Practical experience with onboarding, parsing, normalizing, and troubleshooting logs from multiple enterprise technologies.
  • Working knowledge of MITRE ATT&CK, Cyber Kill Chain, common attack techniques, and security analytics methodologies.
  • Familiarity with Linux administration and scripting using Python, Bash, or PowerShell.
  • Strong analytical thinking, problem-solving ability, documentation discipline, and communication skills.
Preferred Skills
  • Experience with Splunk ES, content development, and splunk administration
  • Relevant Splunk certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, or Splunk Cybersecurity Defense Analyst.
  • Any cyber security certificate will be extra advantage
What We Look For
  • A self-driven security professional with strong ownership and problem-solving mindset.
  • Passion for cybersecurity, threat detection, security analytics, and continuous improvement.
  • Ability to work effectively with global stakeholders, cross-functional teams, and client-facing teams.
  • Clear communication style, strong documentation skills, and ability to explain technical concepts in a business-friendly manner.
  • Willingness to learn emerging technologies and deliver high-quality outcomes in a fast-paced environment.
What We Offer You

At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams.

Our Commitment

As a commitment, we persistently endeavour to embody our values, fulfil our purpose, and champion inclusiveness. Our dedication is to cultivate EY into an environment where diverse perspectives are celebrated, creating a supportive atmosphere for individuals to authentically be themselves and contribute their utmost.

Professional Development:

From entry-level employees to senior leaders, we believe in continuous learning. We offer opportunities to build new skills, take on leadership roles, and connect and grow through mentorship.

People and Culture:

In our dynamic workplace, diversity, equity, and inclusiveness are ingrained in our culture. We're united by a commitment to create an environment where every individual's differences are valued, practices are equitable, fostering a sense of belonging.

Benefits:

Embark on a transformative career journey with us and indulge in a suite of premium benefits, encompassing exclusive health and wellness packages, enticing rewards, and cutting-edge learning opportunities that empower you to continually grow and excel in your professional and personal development.

EY | Building a better working world

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Select how often (in days) to receive an alert:

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Operations - W6 - ES And F0116
Cyber Security Operations - W6 - ES And F0116

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 4,000,000 - 6,000,000
CMS-Senior-Sentinel SOAR
CMS-Senior-Sentinel SOAR

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 1,200,000 - 2,000,000
TC-CS-IAM-SailPoint-Senior
TC-CS-IAM-SailPoint-Senior

Ernst & Young Advisory Services Sdn Bhd • Pune District

On-site
INR 1,800,000 - 3,000,000
FS-RISK CONSULTING-TPRM-SENIOR
FS-RISK CONSULTING-TPRM-SENIOR

Ernst & Young Advisory Services Sdn Bhd • Hyderabad

On-site
INR 900,000 - 1,400,000
TC-CS-Cyber Architecture- OT and Engineering-infrastructure Security-Manager
TC-CS-Cyber Architecture- OT and Engineering-infrastructure Security-Manager

EY • Thiruvananthapuram

On-site
INR 1,400,000 - 2,100,000
Health insurance
Flexible work environment
Learning opportunities
Cyber Security Operations - W6 - ES And F0116
Cyber Security Operations - W6 - ES And F0116

EY • Bengaluru

On-site
INR 2,800,000 - 5,000,000
FS-RISK CONSULTING- TPRM-MANAGER
FS-RISK CONSULTING- TPRM-MANAGER

EY • Pune District

On-site
INR 1,500,000 - 2,700,000
FS-RISK CONSULTING- TPRM-MANAGER
FS-RISK CONSULTING- TPRM-MANAGER

EY • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Health benefits
Learning & development
Cyber Security Operations - W6 - ES And F0116
Cyber Security Operations - W6 - ES And F0116

EY • Hyderabad

On-site
INR 4,500,000 - 7,500,000
Flexible working
Career development
Total Rewards program
CMS-Senior-Splunk SOAR
CMS-Senior-Splunk SOAR

EY • Chennai District

On-site
INR 1,800,000 - 3,200,000