Cognizant

Splunk Cybersecurity Architect

Cognizant
Apply
19 days ago
Vancouver, CanadaSenior / Staff+

Responsibilities

  • Design and architect enterprise Splunk SIEM solutions, including data onboarding, CIM architecture, correlation searches, risk-based alerting, dashboards, and performance tuning.
  • Develop advanced SPL queries, detection use cases, threat analytics, and MITRE ATT&CK detection coverage assessments.
  • Architect SOAR workflows, playbooks, threat-intelligence and incident-management integrations, and automated response capabilities.
  • Develop and tune detection content using Microsoft Defender EDR telemetry, Cisco Umbrella, and Cisco Secure Email.
  • Provide architectural guidance for threat hunting, incident investigations, phishing and BEC analysis, DNS-based threats, endpoint monitoring, and major incident response.
  • Establish cybersecurity architecture standards, operational processes, and optimization strategies for security monitoring technologies.
  • Support ISO 27001 and PCI-DSS audits with architecture documentation, control evidence, and remediation recommendations.
  • Mentor SOC analysts, engineers, and security stakeholders while driving cybersecurity program improvements.

Requirements

  • Advanced Splunk experience, including SPL, correlation rule authoring, risk-based alerting, CIM and data model architecture, dashboards, reporting, and performance tuning.
  • Hands-on SOAR experience with Splunk SOAR/Phantom, XSOAR, or similar platforms, including playbook authorship, enrichment configuration, and API or application integrations.
  • Advanced Microsoft Defender EDR telemetry analysis, custom detection rules, and threat and vulnerability management experience.
  • Experience with Cisco Umbrella DNS tunneling and DGA detection and policy engineering.
  • Experience with Cisco Secure Email phishing and BEC forensics, DLP, and policy tuning.
  • Strong understanding of MITRE ATT&CK for detection mapping and security gap analysis.
  • Working knowledge of memory, disk, and network digital forensics fundamentals.
  • Python and PowerShell scripting or automation experience for SOAR application development or SPL automation is a strong plus.
  • Understanding of ISO 27001 ISMS controls and PCI-DSS requirements.
  • 8–12 years of SOC or security operations experience, including demonstrated L1-to-L2 progression or equivalent, preferred.
  • Preferred certifications include Splunk Certified Power User/Admin, GCIH, GCIA, Microsoft SC-200, CySA+, CEH, or equivalent.
  • Exposure to formal ISO 27001 or PCI-DSS audit cycles is preferred.

Benefits

  • Hybrid work requiring three days per week in a client or Cognizant office in Vancouver, BC.
  • Occasional travel may be required for client meetings, workshops, project activities, and business-critical needs.
  • Medical, dental, vision, and life insurance, subject to eligibility.
  • Paid holidays and paid time off.
  • Long-term and short-term disability coverage.
  • Paid parental leave.
  • Eligible for a discretionary annual incentive program based on performance and applicable plan terms.

Tech Stack

PowerShellPythonSplunk

Categories

Cognizant

About Cognizant

10,000+ employees

Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, bridging the gap between AI investment and enterprise value. We build full-stack AI solutions powered by deep industry, process and engineering expertise — embedding an organization's unique context into technology systems that amplify human potential and drive tangible outcomes. From strategy to deployment, we help global enterprises move from AI ambition to AI impact and stay ahead in a fast-changing world. See how at cognizant.ai | Follow us @cognizant

Contact me