TC-CS-CDR-Splunk-Senior Professional (Chennai)

TC-CS-CDR-Splunk-Senior Professional (Chennai)

06 Aug
|
EY
|
Chennai

06 Aug

EY

Chennai

Service Line - Senior Splunk Engineer

Experience

- 3-7 years

The Opportunity

EY is seeking a highly motivated Senior Splunk Engineer with 3-7 years of hands-on experience in Splunk Enterprise and Splunk Enterprise Security. The candidate will support the administration, optimization, and enhancement of Splunk environments while developing advanced security use cases, correlation searches, dashboards, and detection content. This role requires strong cybersecurity and SIEM expertise, along with the ability to collaborate with global teams to strengthen threat detection, monitoring, and response capabilities.

Your Key Responsibilities

- Administer and maintain Splunk Enterprise and Splunk Enterprise Security environments across distributed deployments.
- Manage Splunk components including indexers, search heads, deployment servers, heavy forwarders, universal forwarders, and clustered environments.
- Perform Splunk upgrades, patching, troubleshooting, health checks, performance tuning, and capacity planning.
- Onboard and normalize logs from Windows, Linux, cloud, network, security, application, and OT/IoT platforms.
- Create, maintain, and optimize data models, CIM mappings, field extractions, lookup tables, tags, event types, macros, and knowledge objects.
- Develop and tune correlation searches, notable events, risk-based alerts, adaptive responses, and security detection content in Splunk ES.
- Design dashboards, reports, and visualizations for SOC, threat hunting, incident response, operational monitoring, and leadership reporting.
- Write efficient SPL queries for threat detection, investigation, reporting, compliance,



and operational use cases.
- Reduce false positives through alert tuning, suppression logic, risk scoring, and detection content optimization.
- Support the use-case lifecycle including requirement gathering, design, development, testing, deployment, documentation, and continuous improvement.
- Collaborate with SOC, Threat Intelligence, Incident Response, IAM, Cloud, Infrastructure, and client teams to improve detection coverage.
- Integrate Splunk with third-party security tools, ticketing platforms, and SOAR solutions where required.

Skills and Attributes for Success

Required Skills

- 3-7 years of experience in Splunk Enterprise, Splunk Enterprise Security, cybersecurity engineering.
- Strong understanding of Splunk architecture, distributed deployments, clustered environments, data ingestion, indexing, search optimization, and license management.
- Hands-on experience with Splunk ES features such as Incident Review, Risk-Based Alerting, threat intelligence framework, notable events, data models, and correlation searches.
- Advanced proficiency in SPL and experience building dashboards, reports, alerts, saved searches, and operational monitoring use cases.
- Practical experience with onboarding, parsing,



normalizing, and troubleshooting logs from multiple enterprise technologies.
- Working knowledge of MITRE ATTCK, Cyber Kill Chain, common attack techniques, and security analytics methodologies.
- Familiarity with Linux administration and scripting using Python, Bash, or PowerShell.
- Strong analytical thinking, problem-solving ability, documentation discipline, and communication skills.

Preferred Skills

- Experience with Splunk ES, content development, and splunk administration
- Relevant Splunk certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, or Splunk Cybersecurity Defense Analyst.
- Any cyber security certificate will be extra advantage

What We Look For

- A self-driven security professional with strong ownership and problem-solving mindset.
- Passion for cybersecurity, threat detection, security analytics, and continuous improvement.
- Ability to work effectively with global stakeholders, cross-functional teams, and client-facing teams.
- Explicit communication style, strong documentation skills, and ability to explain technical concepts in a business-friendly manner.
- Willingness to learn emerging technologies and deliver high-quality outcomes in a fast-paced environment.

Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 TC-CS-CDR-Splunk-Senior Professional (Chennai)
🏢 EY
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: tc-cs-cdr-splunk-senior professional (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: tc-cs-cdr-splunk-senior professional (chennai) / chennai