yoinka

Consultant / Senior Consultant - Cybersecurity Operation Centre (Splunk Engineer) - Tech Consulting

EY

Ebene, MUSenior
Sign in to applyVerified 1h ago
Location
Ebene, MU
Work model
On-Site
Level
Senior

Skills

SplunkCybersecurityAWS

About this role

What if we didn’t focus on who you are now, but who you could become? Here at EY, you will have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. Join us and build an exceptional experience for yourself, and a better working world for all.  The exceptional EY experience. It's yours to build. The opportunity: your next adventure awaits Technology Consulting business is a fast-growing sub-service line within EY’s Consulting service line. A dynamic group focused on providing high-value independent, trusted advice to clients, with a focus on transformation programmes. EY work with clients in creating value and delivering world-class Digital, Data & IT capabilities to support business needs. Working closely with our industry groups and leveraging the EY brand as independent, trusted advisors, we provide our high-profile clients with a range of services.   We are seeking a skilled Splunk Engineer to join our cybersecurity and observability team. The candidate should have hands-on experience managing the complete Splunk lifecycle, including migrations, platform optimization, use case development, and deep integration with EDR/XDR and SOAR platforms such as SentinelOne and Cisco XDR. The role spans AWS environments, endpoint security, threat detection, and automated response, delivering advanced SOC and observability capabilities in a 24×7 operational environment. Key Responsibilities

Own and execute Splunk migration projects from on-premises to Splunk Cloud (SaaS), ensuring minimal disruption, scalability, and adherence to Splunk best practices. Design, implement, and maintain Splunk security and observability use cases, dashboards, reports, and alerts for SOC, threat hunting, and IT operations. Integrate Splunk with SentinelOne (Singularity Platform) for EDR/XDR telemetry ingestion, advanced correlation, and endpoint-driven threat detection and response. Correlate SentinelOne alerts, behavioral detections, storyline data, and endpoint telemetry with Splunk Enterprise Security for enhanced investigation and threat hunting. Integrate Splunk with UEBA, AI-driven analytics, Wazuh, SentinelOne, Cisco XDR/SOAR, and other security tools to enable end-to-end detection and response. Develop and maintain correlation searches, risk-based alerting (RBA), and ES notable events leveraging endpoint, network, cloud, and identity data. Perform Splunk platform administration, including installation, upgrades, performance tuning, index/storage optimization, and troubleshooting. Design and maintain custom parsers, field extractions, lookups, and CIM-compliant normalization for diverse log sources, including endpoint and EDR data. Onboard and manage AWS security and operational logs (CloudTrail, GuardDuty, VPC Flow Logs, ELB/ALB, CloudWatch, Security Hub) into Splunk. Develop and document SOAR/XDR playbooks integrating Splunk with SentinelOne and Cisco XDR for automated containment, isolation, remediation, and enrichment. Collaborate with SOC, IR, and IT teams to identify detection gaps and create custom security use cases aligned with business and risk priorities. Provide guidance and enablement to L1/L2 SOC analysts on Splunk, SentinelOne alert triage, investigations, and response workflows. Maintain documentation including architecture diagrams, SOPs, onboarding guides, and runbooks. Stay current with Splunk, SentinelOne, XDR/EDR trends, and emerging threat techniques (MITRE ATT&CK).

Skills & Qualifications

Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience). Strong experience with Splunk Enterprise and/or Splunk Cloud (SaaS), including architecture, deployment, and migrations. Hands-on experience integrating SentinelOne EDR/XDR with SIEM platforms (Splunk), including API-based ingestion and alert correlation. Solid understanding of

Consultant / Senior Consultant - Cybersecurity Operation Centre (Splunk Engineer) - Tech Consulting at EY, Ebene, MU | Yoinka