Jobs in Mauritius
Consultant / Senior Consultant - Cybersecurity Operation Centre (Splunk Engineer) - Tech Consulting
What if we didn’t focus on who you are now, but who you could become? Here at EY, you will have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. Join us and build an exceptional experience for yourself, and a better working world for all. The Exceptional EY Experience. It's Yours To Build. The opportunity: your next adventure awaits Technology Consulting business is a fast-growing sub-service line within EY’s Consulting service line. A dynamic group focused on providing high-value independent, trusted advice to clients, with a focus on transformation programmes. EY work with clients in creating value and delivering world-class Digital, Data & IT capabilities to support business needs. Working closely with our industry groups and leveraging the EY brand as independent, trusted advisors, we provide our high-profile clients with a range of services. We are seeking a skilled Splunk Engineer to join our cybersecurity and observability team. The candidate should have hands-on experience managing the complete Splunk lifecycle, including migrations, platform optimization, use case development, and deep integration with EDR/XDR and SOAR platforms such as SentinelOne and Cisco XDR. The role spans AWS environments, endpoint security, threat detection, and automated response, delivering advanced SOC and observability capabilities in a 24×7 operational environment. Key Responsibilities • Own and execute Splunk migration projects from on-premises to Splunk Cloud (SaaS), ensuring minimal disruption, scalability, and adherence to Splunk best practices. • Design, implement, and maintain Splunk security and observability use cases, dashboards, reports, and alerts for SOC, threat hunting, and IT operations. • Integrate Splunk with SentinelOne (Singularity Platform) for EDR/XDR telemetry ingestion, advanced correlation, and endpoint-driven threat detection and response. • Correlate SentinelOne alerts, behavioral detections, storyline data, and endpoint telemetry with Splunk Enterprise Security for enhanced investigation and threat hunting. • Integrate Splunk with UEBA, AI-driven analytics, Wazuh, SentinelOne, Cisco XDR/SOAR, and other security tools to enable end-to-end detection and response. • Develop and maintain correlation searches, risk-based alerting (RBA), and ES notable events leveraging endpoint, network, cloud, and identity data. • Perform Splunk platform administration, including installation, upgrades, performance tuning, index/storage optimization, and troubleshooting. • Design and maintain custom parsers, field extractions, lookups, and CIM-compliant normalization for diverse log sources, including endpoint and EDR data. • Onboard and manage AWS security and operational logs (CloudTrail, GuardDuty, VPC Flow Logs, ELB/ALB, CloudWatch, Security Hub) into Splunk. • Develop and document SOAR/XDR playbooks integrating Splunk with SentinelOne and Cisco XDR for automated containment, isolation, remediation, and enrichment. • Collaborate with SOC, IR, and IT teams to identify detection gaps and create custom security use cases aligned with business and risk priorities. • Provide guidance and enablement to L1/L2 SOC analysts on Splunk, SentinelOne alert triage, investigations, and response workflows. • Maintain documentation including architecture diagrams, SOPs, onboarding guides, and runbooks. • Stay current with Splunk, SentinelOne, XDR/EDR trends, and emerging threat techniques (MITRE ATT&CK). Skills & Qualifications • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience). • Strong experience with Splunk Enterprise and/or Splunk Cloud (SaaS), including architecture, deployment, and migrations. • Hands-on experience integrating SentinelOne EDR/XDR with SIEM platforms (Splunk), including API-based ingestion and alert correlation. • Solid understanding of endpoint security concepts, malware behavior, ransomware detection, lateral movement, and persistence techniques. • Experience with Wazuh, UEBA, AI/ML-driven analytics, and security data enrichment. • Proficiency in log ingestion, indexing, SPL searches, dashboards, correlation rules, alerts, and knowledge objects. • Experience with Splunk Enterprise Security (ES) and risk-based alerting models. • Hands-on experience ingesting and analyzing AWS cloud security logs in Splunk. • Familiarity with Cisco security ecosystem, including Umbrella, Secure Firewall, Secure Endpoint, Cisco XDR, SOAR playbooks, SecureX. • Understanding of networking, operating systems (Windows/Linux), and SOC operations. • Splunk certifications (Core, ES, Cloud Admin) and SentinelOne or XDR-related certifications are a strong plus. Soft Skills • Strong analytical, investigative, and problem-solving skills. • Ability to translate technical detections into actionable SOC outcomes. • Excellent communication and collaboration skills across SOC, IR, and IT teams. • Comfortable working in a fast-paced, 24/7 SOC environment. • Proactive mindset with a focus on automation, detection maturity, and continuous improvement. Desired Experience • 3–5 years of experience in Splunk administration, security engineering, or SOC analytics. • Proven experience with Splunk Cloud migrations, SaaS management, or large-scale deployments. • Hands-on experience integrating SentinelOne with SIEM/SOAR for endpoint detection, automated containment, and investigation workflows. • Experience creating security use cases and SOAR/XDR playbooks using Splunk ES, SentinelOne, and Cisco XDR. • Exposure to threat hunting, incident response, and MITRE ATT&CK–aligned detections. What We Look For If you’re a natural leader, with a talent for motivating individuals, building relationships, and solving complex client problems, we’re interested in you. You’ll need to be ready to listen and confident in challenging the status quo. Top performers in this role will have strong experience contributing content to pursuits, collaboratively structuring work, managing teams, developing reusable collateral, and experience working with client executives. If you have a genuine passion for helping businesses achieve their full potential, this role is for you. If you have the confidence to speak up and influence a team that affects big businesses worldwide, this role is for you. What Working At EY Offers At EY, our Total Rewards package supports our commitment to creating a leading people culture - built on high-performance teaming - where everyone can achieve their potential and contribute to building a better working world for our people, our clients, and our communities. It's one of the many reasons we repeatedly win awards for being a great place to work. We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development. Plus, we offer: • Support, coaching, and feedback from some of the most engaging colleagues around. • Opportunities to develop new skills and progress your career. • The freedom and flexibility to handle your role in a way that’s right for you. EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. About EY As a global leader in Assurance, Consulting, Strategy and Transactions, Tax, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities, and creative freedom to make things better. So that whenever you join, however long you stay, the exceptional EY experience lasts a lifetime. And with a commitment to hiring and developing the most passionate people, we’ll make our ambition to be the best employer a reality. If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible. EY will recommend applicants to read our privacy statement prior to completing the pre application form above: https://www.ey.com/en_gl/privacy-statement Join us in Shaping the future with confidence. Apply now Only shortlisted candidates will be contacted.
Security Engineer
SD Worx is a leading European provider of Payroll & HR services with global reach. We have offices in Europe and Mauritius. Our goal? We bring people solutions to life and turn HR into a value source for our clients and their people. Our people solutions span the entire employee journey, from salary payment to attracting, rewarding, and developing talent. Are you ready to join us? About the role: As Security Engineer, you play a critical role in safeguarding SD Worx Group’s IT landscape and enabling business objectives through robust, future‑proof security capabilities. You ensure that security controls across infrastructure, cloud and workplace environments are not only effective, but continuously adapted to evolving threats, technologies and organisational priorities. You take end‑to‑end accountability for the implementation, effectiveness and continuous improvement of security controls, applied policies and standards across the Group. Beyond operational excellence, you actively challenge and improve cross‑functional security processes, contribute to the definition of new ways of working, and influence security priorities that impact SD Worx goals. Operating at the heart of the Security Operations and Engineering capability, you combine deep technical expertise with strong analytical, advisory and coaching skills. You proactively capture new security evolutions, translate them into actionable improvements, and embed them into the wider IT and business ecosystem spanning more than 26 countries. You play a key role in advancing SD Worx’ vulnerability management capability by evolving it from tool‑driven scanning to a risk‑contextual, intelligence‑led discipline that aligns technical exposure with business impact and threat actor behaviour. Which tasks can you expect? Security Engineering & Operational Excellence • Lead advanced security reviews, threat analysis and risk assessments across infrastructure, cloud and workplace platforms, translating findings into concrete improvements. • Design and improve security monitoring, detection and response capabilities, including metrics that demonstrate control effectiveness and risk reduction to senior stakeholders. • Drive improvements to security infrastructure and configurations (e.g. Identity & Access Management, system hardening, SIEM, IDS/IPS/XDR), challenging existing standards and proposing new controls where needed (CIS benchmarking knowledge strongly valued). • Oversee and continuously improve vulnerability management, patching and secure configuration processes, ensuring timely risk mitigation across the estate. This includes prioritizing vulnerabilities based on exploitability, exposure, attacker intent and business criticality rather than severity alone, enabling informed and outcome‑driven remediation decisions. • Perform complex incident response and forensic investigations, coordinating with cross‑functional teams, capturing lessons learned and embedding structural improvements to prevent recurrence. • Participate in a compensated on‑call rotation, providing 2nd or 3rd line escalation support when required. Process & Cross‑Functional Impact • Rethink and optimize end‑to‑end security processes across IT domains, value chains and external partners, setting or revising roles, responsibilities and operational agreements. • Ensure Group‑wide security policies, standards and frameworks (ISO, CIS, SD Worx policies) remain relevant, are effectively implemented, and align with both regulatory and business needs. • Influence and advise platform, cloud, workplace and application teams on secure‑by‑design principles, architectural decisions and risk‑based trade‑offs. • Contribute to organizational security maturity by defining standard operating procedures, SOC playbooks and scalable engineering practices. Outside‑In Thinking, Innovation & Advisory • Proactively research and interpret emerging threats, technologies and regulatory evolutions, translating them into actionable guidance for SD Worx’ complex customer and business contexts. • Advise and support innovation initiatives and strategic IT programs, ensuring security enables business growth rather than constrains it. • Act as a trusted advisor for a broad portfolio of internal customers with diverse risk profiles, balancing security, usability and operational efficiency. • Explore and introduce the responsible use of AI‑assisted security capabilities to augment human decision‑making, improve signal‑to‑noise ratio in SecOps, and accelerate vulnerability analysis, threat correlation and incident triage. Connecting & Influence • Build a broad internal network to influence decisions, align priorities and negotiate solutions on complex security topics with senior stakeholders. • Act as a role model within the security and IT community, supporting knowledge sharing. • Actively promotes a human‑in‑the‑loop security operating model where AI supports analysts, without eroding accountability, judgement or ethical responsibility. • Represent the security function in cross‑country forums, internal communities and external events, strengthening SD Worx’ security credibility and thought leadership. Our expectations: Thinking and Acting Outside‑In • Visibly anticipates the impact of technological, regulatory and threat evolutions and actively reshapes security approaches accordingly. • Challenges existing expertise, tools and ways of working, and actively introduces new knowledge into the organisation and value chain. • Delivers win‑win solutions that improve customer trust, service quality and organisational resilience. • Recognises that vulnerability and threat landscapes are emergent and non‑linear, and continuously adapts prioritisation and response models accordingly. Agility • Proactively identifies weaknesses in service or security delivery and drives structural improvements across teams. • Balances operational stability with innovation, adapting quickly to changing business and risk landscapes. • Continuously builds expertise through learning, experimentation and collaboration with other senior experts. • Actively experiments with automation and AI‑driven workflows to improve speed, accuracy and scalability of SecOps without increasing operational risk. Connecting • Builds and leverages strong cross‑functional and international networks to influence outcomes at scale. • Enables understanding of complex security themes to colleagues and stakeholders effectively, including management level. • Acts with authority and credibility in internal and external interactions. What do you have to offer? Essential • Proven 5 to 7 years of experience in cybersecurity engineering and operations, with deep hands‑on expertise in security tooling and platforms (SIEM, detection/response, IAM, hardening). • Strong understanding of infrastructure, cloud and workplace security architectures and security operations concepts. • Ability to translate technical risk into business‑relevant insights for diverse stakeholders. • Solid knowledge of network protocols, identity technologies and Active Directory. • Professional English proficiency (additional European languages are an asset). • Demonstrated experience with vulnerability management programmes, including risk‑based prioritisation, remediation governance and stakeholder alignment. Desirable • Recognized security certifications or clear ambition to obtain them. • Scripting and automation skills to improve security efficiency and scalability. • Demonstrated drive to shape secure engineering practices and influence beyond own technical scope. • Comfortable operating autonomously and communicating with confidence at senior level. • Experience or strong interest in applying AI or machine‑learning techniques to security operations, detection engineering, vulnerability analysis or automation. Please be informed that upon successful completion of the interview process, you will be required to submit a recent Certificate of Character, and you will undergo a background check as part of our standard legal procedures. From many places, we work as one, moving from better to best together. SD Worx embraces diversity in the workplace. Diversity brings inspiration and innovation to our company. We particularly welcome applications from qualified talent, regardless of origin, nationality, gender, skin color, ethnic and social background, religion, age, disability, sexual orientation, or stage of life.
Security Engineer Annotator (Maurice)
Job Summary: We are looking for a Security Engineer Annotator to evaluate cybersecurity datasets used in AI model training. The ideal candidate will analyze, security related datasets, code samples, architectural designs. The Security Engineer role involves identifying vulnerabilities, labeling security scenarios, and validating AI-generated security recommendations. Job Responsibilities • Annotate cybersecurity datasets and threat scenarios. • Evaluate secure coding practices and vulnerability assessments. • Label datasets involving penetration testing and risk analysis. • Review authentication, encryption, and access control implementations. • Assess AI responses related to security threats and mitigation. • Provide structured feedback aligned with security standards. Job Requirements • Minimum 3 years’ experience in Cybersecurity or Security Engineering. • Strong understanding of secure software development. • Knowledge of network security, cryptography, and vulnerability management. • Experience with penetration testing tools. • Experience in identifying and mitigating common vulnerabilities of OWASP security principles like Injection attacks, Authentication and authorization flaws, Cross-site Scripting (XSS) • Understanding of security frameworks and compliance standards such as ISO 27001, NIST , SOC 2, Zero Trust Architecture concepts. • Preferred certifications: Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), CompTIA Security Certified Cloud Security Professional (CCSP)