Talent.com
TC-CS-Cyber Detection and Response-Splunk engineer-Senior
TC-CS-Cyber Detection and Response-Splunk engineer-SeniorEY Studio+ Nederland • Delhi, Delhi, India
TC-CS-Cyber Detection and Response-Splunk engineer-Senior

TC-CS-Cyber Detection and Response-Splunk engineer-Senior

EY Studio+ Nederland • Delhi, Delhi, India
13 days ago
Job description

At EY youll have the chance to build a career as unique as you are with the global scale support inclusive culture and technology to become the best version of you. And were counting on your unique voice and perspective to help EY become even better too. Join us and build an exceptional experience for yourself and a better working world for all.

Senior - CTM Threat Detection & Response

We are seeking a highly skilled and experienced Senior Splunk Implementation Specialist to lead and oversee the deployment administration and use case development of Splunk Enterprise Security (ES) applications. The ideal candidate will have a deep understanding of Splunks capabilities and a strong background in cybersecurity. This role requires an individual with extensive experience in implementing and managing Splunk ES as well as developing and maintaining security use cases to enhance clients security posture.

KEY Capabilities :

  • Experience in working with Splunk Enterprise Splunk Enterprise Security & Splunk UEBA
  • Lead the planning design and implementation of Splunk Enterprise Security (ES) across the organization.
  • Develop and manage the Splunk implementation project plan including timelines milestones and resource allocation.
  • Coordinate with cross-functional teams including IT security and compliance to ensure seamless integration of Splunk with existing systems and processes.
  • Oversee the configuration and customization of Splunk ES to meet the organizations specific security requirements.
  • Develop implement and maintain security use cases correlation searches and dashboards within Splunk ES.
  • Provide expert guidance and support to the security operations team in the use of Splunk ES for threat hunting and incident investigation.
  • Ensure compliance with industry standards and regulatory requirements related to security monitoring and incident response.
  • Develop and maintain documentation for Splunk configurations processes and procedures.
  • Good knowledge in programming or Scripting languages such as Python (preferred) JavaScript (preferred) Bash PowerShell Bash etc.
  • Experience in onboarding data into Splunk from various sources including unsupported (in-house built) by creating custom parsers.
  • Expertise in SIEM content development which includes developing process for automated security event monitoring and alerting along with corresponding event response plans for systems.

Experience in creating use cases under Cyber kill chain and MITRE attack framework.

  • Experience in installation configuration and usage of premium Splunk Apps and Add-ons such as ES App UEBA ITSI etc
  • Sound knowledge in configuration of Alerts and Reports.
  • Good exposure in automatic lookup data models and creating complex SPL queries.
  • Create modify and tune the SIEM rules to adjust the specifications of alerts and incidents to meet client requirement.
  • Work with the client SPOC to for correlation rule tuning (as per use case management life cycle) incident classification and prioritization recommendations.
  • Experience in creating custom commands custom alert action adaptive response actions etc.
  • Qualification & experience :

  • Minimum of 5 to 7 years experience with a depth of network architecture knowledge that will translate over to deploying and integrating a complicated security intelligence solution into global enterprise environments.
  • Proven experience in implementing and managing Splunk Enterprise Security (ES) applications.
  • Strong understanding of cybersecurity principles threat detection and incident response.
  • Extensive experience in developing and maintaining security use cases correlation searches and dashboards within Splunk ES.
  • Excellent project management skills with a track record of successfully leading complex security projects.
  • Strong leadership and team management skills with the ability to mentor and develop team members.
  • Excellent communication and interpersonal skills with the ability to collaborate effectively with stakeholders at all levels.
  • Relevant certifications such as CISSP CISM Splunk Certified Admin Splunk Certified Architect or similar are highly desirable. Certifications in a core security related discipline will be an added advantage.
  • Desired Skills :

  • Familiarity with scripting and automation tools (e.g. Python PowerShell) for security operations and incident response.
  • Knowledge of regulatory and compliance frameworks (e.g. GDPR HIPAA NIST).
  • Experience in conducting security assessments and audits.
  • Ability to develop and implement security policies procedures and best practices.
  • Strong analytical and problem-solving skills.
  • EY Building a better working world

    EY exists to build a better working world helping to create long-term value for clients people and society and build trust in the capital markets.

    Enabled by data and technology diverse EY teams in over 150 countries provide trust through assurance and help clients grow transform and operate.

    Working across assurance consulting law strategy tax and transactions EY teams ask better questions to find new answers for the complex issues facing our world today.

    Key Skills

    Children Activity,Apprentice,Advertising,Gallery,IT Software,Barista

    Employment Type : Full Time

    Experience : years

    Vacancy : 1

    Create a job alert for this search

    And • Delhi, Delhi, India

    Related jobs
    Senior Detection Engineer - Crowdstrike

    Senior Detection Engineer - Crowdstrike

    Insight Global, LLC • Delhi, IN
    Required Skills & Experience : - 5+ years in detection engineering, threat hunting, or security operations.Endpoint & identity ...Show more
    Last updated: 8 days ago • Promoted
    TC-CS-IAM -IMP-CyberArk -Senior

    TC-CS-IAM -IMP-CyberArk -Senior

    Confidential • Noida, India
    At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your u...Show more
    Last updated: 14 days ago • Promoted
    Senior Hardware Engineer

    Senior Hardware Engineer

    Byteforge Systems • New Delhi, Delhi, India
    We are a startup product development firm that specializes in creating wearables, consumer electronics, and medical devices. Clients often approach us with unique challenges that require a creative ...Show more
    Last updated: 8 days ago • Promoted
    Senior Integration Engineer

    Senior Integration Engineer

    9NEXUS • Delhi, IN
    Job Title : Senior Integration Engineer.REST), ensuring performance, governance, and security compliance.MuleSoft, SnapLogic, Globalscape, Informatica, and Fivetran. Manage database integrations and ...Show more
    Last updated: 3 hours ago • Promoted • New!
    In-Person Hiring Drive- Cyber-D&R-SPLUNK Engineer-Gurgaon DLF-1st Nov'25(Saturday)

    In-Person Hiring Drive- Cyber-D&R-SPLUNK Engineer-Gurgaon DLF-1st Nov'25(Saturday)

    Deloitte • Gurugram, Haryana, India
    We have scheduled hiring drive at Gurgaon DLF office on 1st Nov'25 (Saturday).Interested applicants kindly apply using the link - https : / / southasiacareers. Please refer the below JD for ready refere...Show more
    Last updated: 3 days ago • Promoted
    GTM Engineer (Agency) — ABM & AI

    GTM Engineer (Agency) — ABM & AI

    xGrowth • Meerut, IN
    Remote (APAC time zones preferred; must overlap reliably with Australian business hours).Growth runs ABM programs for mid-market and enterprise tech across APJ and work with some of the largest tec...Show more
    Last updated: 13 days ago • Promoted
    TC CS CDR Splunk Engineer Staff

    TC CS CDR Splunk Engineer Staff

    EY Studio+ Nederland • Delhi, Delhi, India
    At EY youll have the chance to build a career as unique as you are with the global scale support inclusive culture and technology to become the best version of you. And were counting on your unique ...Show more
    Last updated: 13 days ago • Promoted
    TC-CS-IAM-CyberArk-Staff

    TC-CS-IAM-CyberArk-Staff

    Confidential • Gurugram, Gurgaon / Gurugram, India
    At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your u...Show more
    Last updated: 3 days ago • Promoted
    Senior Engineer - Platform

    Senior Engineer - Platform

    REA • Gurgaon, India
    In 1995, in a garage in Melbourne, Australia, REA Group was born from a simple question : Can we change the way the world experiences property?. Fast forward 30 years, REA Group is a market leader in...Show more
    Last updated: 30+ days ago • Promoted
    Splunk

    Splunk

    Tata Consultancy Services • New Delhi, Delhi, India
    Splunk related activities like Onboarding logs to Splunk, queries to be used in Splunk and Dashboard creation in Splunk.Associate should be well versed in Unix and Database(mySQL / Oracle).Show more
    Last updated: 14 days ago • Promoted
    Senior HPC Engineer

    Senior HPC Engineer

    Netweb Technologies India Ltd. • Faridabad, Haryana, India
    Accomplished HPC Systems Engineer with 8–10 years of enterprise Linux administration and over 5 years of hands-on experience managing large-scale HPC clusters exceeding 500 cores and multi-petabyte...Show more
    Last updated: 30+ days ago • Promoted
    Splunk Engineer Security Detections

    Splunk Engineer Security Detections

    GoDaddy • Gurgaon, Haryana, India
    At GoDaddy the future of work looks different for each team.Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days)and s...Show more
    Last updated: 30+ days ago • Promoted
    CyberArk SME

    CyberArk SME

    NuSummit Cybersecurity • Delhi, IN
    CyberArk SME – 6+ year, remote.CyberArk CDE certification is Mandatory.CyberArk SaaS implementation and understanding of on-prem components requirements. Onboarding of devices- Kubernetes, Windows, ...Show more
    Last updated: 21 days ago • Promoted
    Cyber Security Engineer with Splunk

    Cyber Security Engineer with Splunk

    IntraEdge • Delhi, IN
    This role will lead the development and implementation of intelligent security solutions using SIEM, SOAR, and machine learning to enhance detection, response, and operational efficiency across the...Show more
    Last updated: 30+ days ago • Promoted
    Cloud IAM Engineer

    Cloud IAM Engineer

    Vertex Agility • Meerut, IN
    Job title : Cloud IAM Engineer.Join Vertex Agility — a high-performance, remote-first consultancy shaping the future of identity security and cloud-native automation. Own and deploy IAM across cloud...Show more
    Last updated: 3 days ago • Promoted
    DDI ENGINEER

    DDI ENGINEER

    TWO95 International, Inc • Meerut, IN
    Salary – Market (Based on the experience).Networking Professional (DNS, DHCP and IPAM (DDI).ONE+ years network and DDI experience. Experience with Active Directory.Experience with Linux based OS.Exc...Show more
    Last updated: 3 hours ago • Promoted • New!
    In-Person Hiring Drive-Cyber-D&R-Threat Detection Engineer-Gurgaon-1st Nov'25 (Saturday)

    In-Person Hiring Drive-Cyber-D&R-Threat Detection Engineer-Gurgaon-1st Nov'25 (Saturday)

    Deloitte • Delhi, India
    We have scheduled hiring drive at Gurgaon DLF office on 1st Nov'25 (Saturday).Interested applicants kindly apply using the link - https : / / southasiacareers. Please refer the below JD for ready refere...Show more
    Last updated: 2 days ago • Promoted
    Cloud Engineer – SCG India

    Cloud Engineer – SCG India

    SCG • New Delhi, Delhi, India
    SCG is modernizing operations in India by integrating.The Cloud Engineer manages SCG’s cloud-based systems, ensuring.Deploy, manage, and optimize cloud infrastructure (AWS, Azure, or GCP).Monitor s...Show more
    Last updated: 30+ days ago • Promoted