E

Senior Splunk Engineer

Ernst & Young · Chennai, Tamil Nadu

5–12 yrs experienceFlexTimePosted 3 days ago
Apply now →

Job description

TC-CS-CDR-Splunk-Senior At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Service Line - Senior Splunk Engineer Experience 3-7 years About Global Delivery Services Global Delivery Services refers to EY's worldwide network of service delivery centers. The GDS team plays an important role in EY's strategy by ensuring effective support to EY's growth agenda. Our journey started in 2002 with approximately 200 people. Today we stand at 80,000 professionals in ten locations around the world. We operate in Argentina, China, Hungary, India, Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom. Client service is focused on providing Consulting, Assurance, Tax, Strategy \& Transactions, and Knowledge support to our clients around the world. The teams enable account teams worldwide to provide seamless, high-quality, value-added support, helping deliver exceptional client service. The Opportunity EY is seeking a highly motivated Senior Splunk Engineer with 3-7 years of hands-on experience in Splunk Enterprise and Splunk Enterprise Security. The candidate will support the administration, optimization, and enhancement of Splunk environments while developing advanced security use cases, correlation searches, dashboards, and detection content. This role requires strong cybersecurity and SIEM expertise, along with the ability to collaborate with global teams to strengthen threat detection, monitoring, and response capabilities. Your Key Responsibilities Administer and maintain Splunk Enterprise and Splunk Enterprise Security environments across distributed deployments. Manage Splunk components including indexers, search heads, deployment servers, heavy forwarders, universal forwarders, and clustered environments. Perform Splunk upgrades, patching, troubleshooting, health checks, performance tuning, and capacity planning. Onboard and normalize logs from Windows, Linux, cloud, network, security, application, and OT/IoT platforms. Create, maintain, and optimize data models, CIM mappings, field extractions, lookup tables, tags, event types, macros, and knowledge objects. Develop and tune correlation searches, notable events, risk-based alerts, adaptive responses, and security detection content in Splunk ES. Design dashboards, reports, and visualizations for SOC, threat hunting, incident response, operational monitoring, and leadership reporting. Write efficient SPL queries for threat detection, investigation, reporting, compliance, and operational use cases. Reduce false positives through alert tuning, suppression logic, risk scoring, and detection content optimization. Support the use-case lifecycle including requirement gathering, design, development, testing, deployment, documentation, and continuous improvement. Collaborate with SOC, Threat Intelligence, Incident Response, IAM, Cloud, Infrastructure, and client teams to improve detection coverage. Integrate Splunk with third-party security tools, ticketing platforms, and SOAR solutions where required. Skills and Attributes for Success Required Skills 3-7 years of experience in Splunk Enterprise, Splunk Enterprise Security, cybersecurity engineering. Strong understanding of Splunk architecture, distributed deployments, clustered environments, data ingestion, indexing, search optimization, and license management. Hands-on experience with Splunk ES features such as Incident Review, Risk-Based Alerting, threat intelligence framework, notable events, data models, and correlation searches. Advanced proficiency in SPL and experience building dashboards, reports, alerts, saved searches, and operational monitoring use cases. Practical experience with onboarding, parsing, normalizing, and troubleshooting logs from multiple enterprise technologies. Working knowledge of MITRE ATT\&CK, Cyber Kill Chain, common attack techniques, and security analytics methodologies. Familiarity with Linux administration and scripting using Python, Bash, or PowerShell. Strong analytical thinking, problem-solving ability, documentation discipline, and communication skills. Preferred Skills Experience with Splunk ES, content development, and splunk administration Relevant Splunk certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, or Splunk Cybersecurity Defense Analyst. Any cyber security certificate will be extra advantage What We Look For A self-driven security professional with strong ownership and problem-solving mindset. Passion for cybersecurity, threat detection, security analytics, and continuous improvement. Ability to work effectively with global stakeholders, cross-functional teams, and client-facing teams. Clear communication style, strong documentation skills, and ability to explain technical concepts in a business-friendly manner. Willingness to learn emerging technologies and deliver high-quality outcomes in a fast-paced environment. What We Offer You At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Are you ready to shape your future with confidence? Apply today. Our Commitment Our Commitment: As a commitment, we persistently endeavour to embody our values, fulfil our purpose, and champion inclusiveness. Our dedication is to cultivate EY into an environment where diverse perspectives are celebrated, creating a supportive atmosphere for individuals to authentically be themselves and contribute their utmost. Professional Development : From entry-level employees to senior leaders,