Cybersecurity SOC Splunk Engineer (Consultant/Senior Consultant)
EY · Ébène
Job description
About the role
EY is looking for a skilled Splunk Engineer to join its Cybersecurity Operations Centre within the Technology Consulting practice. You will work on end‑to‑end Splunk solutions, from migration to cloud to advanced threat detection, supporting a 24×7 SOC environment.
Key responsibilities
- Lead Splunk migration projects from on‑premises to Splunk Cloud (SaaS) while ensuring minimal disruption and scalability.
- Design, implement and maintain security and observability use cases, dashboards, reports and alerts for SOC, threat hunting and IT operations.
- Integrate Splunk with SentinelOne, Cisco XDR/SOAR and other EDR/XDR platforms for telemetry ingestion and automated response.
- Correlate endpoint, network, cloud and identity data using Splunk Enterprise Security, UEBA and AI‑driven analytics.
- Develop and maintain correlation searches, risk‑based alerting and notable events.
- Perform Splunk platform administration including installation, upgrades, performance tuning, index/storage optimisation and troubleshooting.
- Create custom parsers, field extractions, lookups and ensure CIM‑compliant normalization for diverse log sources.
- Onboard and manage AWS security logs (CloudTrail, GuardDuty, VPC Flow Logs, ELB/ALB, CloudWatch, Security Hub) into Splunk.
Required profile
- Proven experience managing the full Splunk lifecycle, including migrations and platform optimisation.
- Hands‑on experience with Splunk Cloud and Splunk Enterprise Security.
- Strong knowledge of AWS security services and log sources.
- Experience integrating EDR/XDR solutions such as SentinelOne and Cisco XDR.
- Ability to operate in a 24×7 SOC or observability environment.
Required skills
- Splunk (on‑prem, Cloud, Enterprise Security)
- AWS services: CloudTrail, GuardDuty, VPC Flow Logs, ELB/ALB, CloudWatch, Security Hub
- SentinelOne (Singularity Platform)
- Cisco XDR / SOAR
- UEBA and AI‑driven analytics
- Wazuh
- Custom parsers, field extractions, CIM normalization
- Correlation searches, risk‑based alerting, notable events
- Splunk platform administration (installation, upgrades, performance tuning, index/storage optimisation)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Mauritius.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 3 weeks from now
41 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
EY
Ébène