> Markdown version of [/jobs/ext/2678310-consultant-senior-consultant-cybersecurity-operation-centre-splunk-engineer-tech-consulting](https://www.wearedevelopers.com/jobs/ext/2678310-consultant-senior-consultant-cybersecurity-operation-centre-splunk-engineer-tech-consulting). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Consultant / Senior Consultant - Cybersecurity Operation Centre (Splunk Engineer) - Tech Consulting - **Company:** Ernst & Young GmbH - **Location:** Stuttgart, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing, Program Optimization, Cyber Security, Linux, Information Technology Operations, Intrusion Detection and Prevention, Machine Learning, Performance Tuning, Runbook, Security Information and Event Management, Systems Integration, EndPointSecurity, Data Ingestion, Mitre Att&ck, Indexer, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Information Technology, Cybercrime, Cloud Migration, Api Design, Cloudwatch, Splunk, SentinelOne Expertise, Cisco - **Published:** September 2, 2026 - **Apply:** https://careers.ey.com/talentcommunity/apply/1289693001/?locale=en_GB ## About the Role * Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience). * Strong experience with Splunk Enterprise and/or Splunk Cloud (SaaS), including architecture, deployment, and migrations. * Hands-on experience integrating SentinelOne EDR/XDR with SIEM platforms (Splunk), including API-based ingestion and alert correlation. * Solid understanding of endpoint security concepts, malware behavior, ransomware detection, lateral movement, and persistence techniques. * Experience with Wazuh, UEBA, AI/ML-driven analytics, and security data enrichment. * Proficiency in log ingestion, indexing, SPL searches, dashboards, correlation rules, alerts, and knowledge objects. * Experience with Splunk Enterprise Security (ES) and risk-based alerting models. * Hands-on experience ingesting and analyzing AWS cloud security logs in Splunk. * Familiarity with Cisco security ecosystem, including Umbrella, Secure Firewall, Secure Endpoint, Cisco XDR, SOAR playbooks, SecureX. * Understanding of networking, operating systems (Windows/Linux), and SOC operations. * Splunk certifications (Core, ES, Cloud Admin) and SentinelOne or XDR-related certifications are a strong plus. Soft Skills * Strong analytical, investigative, and problem-solving skills. * Ability to translate technical detections into actionable SOC outcomes. * Excellent communication and collaboration skills across SOC, IR, and IT teams. * Comfortable working in a fast-paced, 24/7 SOC environment. * Proactive mindset with a focus on automation, detection maturity, and continuous improvement. Desired Experience * 3-5 years of experience in Splunk administration, security engineering, or SOC analytics. * Proven experience with Splunk Cloud migrations, SaaS management, or large-scale deployments. * Hands-on experience integrating SentinelOne with SIEM/SOAR for endpoint detection, automated containment, and investigation workflows. * Experience creating security use cases and SOAR/XDR playbooks using Splunk ES, SentinelOne, and Cisco XDR. * Exposure to threat hunting, incident response, and MITRE ATT&CK-aligned detections. What we look for If you're a natural leader, with a talent for motivating individuals, building relationships, and solving complex client problems, we're interested in you. You'll need to be ready to listen and confident in challenging the status quo. Top performers in this role will have strong experience contributing content to pursuits, collaboratively structuring work, managing teams, developing reusable collateral, and experience working with client executives. If you have a genuine passion for helping businesses achieve their full potential, this role is for you. ## Description We are seeking a skilled Splunk Engineer to join our cybersecurity and observability team. The candidate should have hands-on experience managing the complete Splunk lifecycle, including migrations, platform optimization, use case development, and deep integration with EDR/XDR and SOAR platforms such as SentinelOne and Cisco XDR. The role spans AWS environments, endpoint security, threat detection, and automated response, delivering advanced SOC and observability capabilities in a 24×7 operational environment., * Own and execute Splunk migration projects from on-premises to Splunk Cloud (SaaS), ensuring minimal disruption, scalability, and adherence to Splunk best practices. * Design, implement, and maintain Splunk security and observability use cases, dashboards, reports, and alerts for SOC, threat hunting, and IT operations. * Integrate Splunk with SentinelOne (Singularity Platform) for EDR/XDR telemetry ingestion, advanced correlation, and endpoint-driven threat detection and response. * Correlate SentinelOne alerts, behavioral detections, storyline data, and endpoint telemetry with Splunk Enterprise Security for enhanced investigation and threat hunting. * Integrate Splunk with UEBA, AI-driven analytics, Wazuh, SentinelOne, Cisco XDR/SOAR, and other security tools to enable end-to-end detection and response. * Develop and maintain correlation searches, risk-based alerting (RBA), and ES notable events leveraging endpoint, network, cloud, and identity data. * Perform Splunk platform administration, including installation, upgrades, performance tuning, index/storage optimization, and troubleshooting. * Design and maintain custom parsers, field extractions, lookups, and CIM-compliant normalization for diverse log sources, including endpoint and EDR data. * Onboard and manage AWS security and operational logs (CloudTrail, GuardDuty, VPC Flow Logs, ELB/ALB, CloudWatch, Security Hub) into Splunk. * Develop and document SOAR/XDR playbooks integrating Splunk with SentinelOne and Cisco XDR for automated containment, isolation, remediation, and enrichment. * Collaborate with SOC, IR, and IT teams to identify detection gaps and create custom security use cases aligned with business and risk priorities. * Provide guidance and enablement to L1/L2 SOC analysts on Splunk, SentinelOne alert triage, investigations, and response workflows. * Maintain documentation including architecture diagrams, SOPs, onboarding guides, and runbooks. * Stay current with Splunk, SentinelOne, XDR/EDR trends, and emerging threat techniques (MITRE ATT&CK). ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)