跳到主要內容

Splunk UBA Engineer (Tier II / Tier III)

00068950775

This role is part of Cognizant's engagement with one of our most strategic global technology clients — a world leader in enterprise cybersecurity and behavioural analytics. You will work on sophisticated UBA environments, contributing to insider threat detection and security analytics at enterprise scale.


About the Role

We are seeking a Splunk UBA Engineer to investigate and resolve complex behavioural analytics and insider threat detection issues. This is a specialist role for a security-focused engineer with deep knowledge of anomaly detection, threat modelling, and user entity behaviour analytics.


What You Will Do

  • Investigate and resolve issues related to anomaly detection failures, threat model misconfigurations, missing or delayed risk events, and data ingestion inconsistencies
  • Analyse UBA logs, system diagnostics, data pipelines, and ingestion flows
  • Monitor and optimise user and entity behaviour models, threat detection algorithms, and risk scoring
  • Investigate suspicious activities and insider threats; validate and tune anomaly detection thresholds
  • Ensure accurate ingestion of authentication logs, network data, and endpoint data
  • Troubleshoot data mapping and normalisation issues
  • Optimise UBA performance through model fine-tuning, scoring mechanisms, and bottleneck resolution
  • Develop Python/Shell scripts to automate tasks and enhance data processing and alerting workflows
  • Collaborate with engineering teams to enhance detection coverage and improve UBA configurations
  • Create and maintain technical documentation, SOPs, runbooks, and troubleshooting playbooks

What You Bring

  • Strong understanding of security analytics, anomaly detection, threat modelling, and behavioural analytics
  • Splunk administration knowledge and log analysis skills
  • Linux fundamentals and basic networking knowledge (TCP/IP, DNS, HTTP/S)
  • Experience with cloud platforms (AWS/Azure/GCP) and scripting (Python/Shell)

Technical Skills Splunk UBA · Splunk Admin · Linux · AWS/Azure/GCP · Python · Shell · JIRA · Git

Certifications (Preferred) Splunk Certified Admin


About us
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, building the bridge between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, realize tangible returns and keep global enterprises ahead in a fast-changing world. See how at www.cognizant.com or @cognizant.

Additional employment information
Compensation information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.

Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government issued ID during each interview.

Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.

帮助您蓬勃发展与成长的福利

我们的福利计划以您为中心打造——帮助您享受充实、平衡且健康的生活。
有葉子的植物的藍色線條圖

财务健康

我们会定期审查市场数据,确保薪酬体现您所带来的价值。您的福利不仅限于薪资,还可能包括退休计划、财务教育等。

Stay Healthy Midnight Blue RGB

身心健康

我们通过带薪休假、在条件允许下的灵活工作安排、医疗保障计划、心理咨询、心理健康盟友计划等,赋能您将身心健康放在首位。

Build The Career You Want Midnight Blue RGB

您的职业发展,由您做主

在 Cognizant 提供的 35 万多个岗位中,您将有机会探索新的技术、行业和工作地点,并打造推动职业发展的关键技能。

Making A Meaningful Impact Midnight Blue RGB

现实世界的影响力

想想您所依赖的那些知名品牌。很可能,他们也依赖我们来帮助强化其业务。在这里,您将把大胆的想法转化为改善全球生活的解决方案。

还没有找到合适的机会吗?

获取为您量身定制的最新职位机会、招聘活动和公司新闻!

掌握最新动态