This role is part of Cognizant's strategic engagement with one of our most marquee global technology clients — a world leader in enterprise networking, cybersecurity, and observability platforms. As a Splunk Tech Lead, you will be a senior pillar of Cognizant's Splunk centre of excellence, driving platform engineering, team capability, and delivery excellence at enterprise scale.
About the Role
We are seeking an experienced and technically exceptional Splunk Tech Lead to lead the design, implementation, and optimisation of Splunk solutions across our enterprise environment. This is a high-visibility role that blends deep technical ownership with team leadership — you will be the highest level of Splunk technical escalation while shaping how the platform is built, governed, and scaled.
What You Will Do
Platform Architecture & Engineering
- Architect, manage, and support distributed Splunk environments including indexers, search heads, deployment servers, cluster masters, license masters, and forwarders
- Lead the implementation and ongoing support of Indexer Clustering and Search Head Clustering to ensure high availability and disaster recovery
- Perform Splunk upgrades, patches, and migrations including version upgrades and on-premises to cloud transitions, ensuring minimal service disruption
- Conduct regular Splunk health checks, audits, and capacity assessments to ensure platform stability and scalability
- Participate in capacity planning, system scaling, and performance tuning activities
Data Onboarding & Integration
- Manage data onboarding and ingestion pipelines including Universal and Heavy Forwarders, HTTP Event Collector (HEC), syslog, and API-based integrations
- Configure and maintain Splunk knowledge objects including field extractions, event types, tags, lookups, macros, and CIM compliance
- Ensure data quality and consistency by validating timestamping, parsing rules, sourcetypes, and index configurations across all data sources
- Integrate Splunk with SIEM, SOAR, ITSM tools, cloud platforms (AWS/Azure/GCP), and third-party monitoring and security solutions
- Collaborate with cross-functional teams to gather requirements and ensure effective integration of Splunk with other tools and systems
Search, Dashboards & Reporting
- Design, implement, and optimise Splunk searches, dashboards, alerts, and reports to support business operations
- Develop advanced SPL queries with a strong focus on performance optimisation and complex query design
- Develop and maintain custom Splunk apps, add-ons, and configurations to meet organisational requirements
Security & Compliance
- Implement and maintain role-based access control (RBAC), authentication (LDAP/SAML), and authorisation models in alignment with security policies
- Ensure adherence to industry standards, security policies, and best practices for Splunk configuration and data handling
- Implement Splunk-based solutions for security monitoring, data analysis, and log aggregation
Operations & Governance
- Monitor, analyse, and optimise Splunk platform performance including indexing throughput, search performance, resource utilisation, and licence usage
- Lead troubleshooting and root cause analysis for critical incidents, serving as the highest level of Splunk technical escalation
- Establish and maintain operational runbooks, SOPs, and support processes for Splunk platform operations
- Prepare and present detailed technical documentation, reports, and recommendations to stakeholders
Team Leadership & Mentorship
- Manage and mentor a team of Splunk engineers, providing guidance and training to enhance their skills and capabilities
- Stay current on the latest developments and best practices in Splunk technologies and security
- Foster a culture of technical excellence, accountability, and continuous improvement
What You Bring
- Deep expertise in distributed Splunk architectures including indexer clustering, search head clustering, and deployment server management
- Strong proficiency in SPL including performance optimisation and complex query design
- Hands-on experience with data ingestion, data normalisation, and integrating external data sources with Splunk
- In-depth knowledge of Splunk architecture, cluster management, and scaling
- Experience managing and troubleshooting large-scale distributed Splunk environments
- Strong understanding of log management, monitoring, and data analytics concepts
- Familiarity with ITIL processes and security best practices
- Excellent problem-solving, analytical, and communication skills
- Proven ability to lead, mentor, and coach technical teams effectively
Technical SkillsSplunk Enterprise/Cloud · SPL · Indexer Clustering · Search Head Clustering · HEC · LDAP/SAML · RBAC · CIM · AWS/Azure/GCP · SIEM/SOAR · ITSM Tools · Python · Shell Scripting · JIRA · Git
关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。
补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。







