跳到主要內容

Principal Technical Lead — Splunk Enterprise & Cloud Platform

00069052941

This role is part of a high-impact engagement with one of our most strategic global technology clients — a world leader in enterprise networking, cybersecurity, and observability platforms. As a Principal Technical Lead, you will be a cornerstone of Cognizant's centre of excellence for Splunk, shaping delivery standards and driving platform excellence at scale.


About the Role

We are seeking a Principal Technical Lead to own critical escalations, drive platform reliability, and lead a high-performing team of Splunk engineers. This is a senior leadership role that combines deep technical expertise with strategic influence — you will shape how the team operates, how customers are served, and how the platform evolves.


What You Will Do

  • Lead critical technical escalations across Splunk platform environments, ensuring timely and effective resolution of customer-impacting incidents
  • Provide hands-on technical support to Senior Engineers, Technical Leads, and cross-functional teams for complex infrastructure and cloud issues
  • Engage directly with enterprise customers and stakeholders to drive incident resolution and maintain confidence
  • Conduct deep-dive RCA for high-severity incidents and develop corrective and preventive action plans
  • Analyse diagnostic logs, telemetry, traces, packet captures, and performance metrics
  • Validate product updates, patches, and feature enhancements; revise enablement agendas accordingly
  • Drive automation, process optimisation, and proactive monitoring initiatives
  • Develop and maintain technical runbooks, SOPs, and escalation handling guidelines
  • Collaborate with Product Engineering, SRE, DevOps, and Operations teams to improve platform stability
  • Organise technical enablement sessions, knowledge-sharing workshops, and escalation review meetings
  • Mentor engineers and foster a culture of technical excellence and operational discipline

What You Bring

  • Deep expertise in search performance, indexing, federated search, search heads, and indexers
  • Strong knowledge of data onboarding, parsing, dashboards, field extractions, lookups, and event correlation
  • Proficiency in Python and Shell scripting for automation
  • Experience with incident response, escalation management, and RCA methodologies
  • Strong stakeholder communication and customer management skills

Technical Skills Splunk Enterprise · SPL · Linux · AWS/Azure/GCP · Python · Shell Scripting · Monitoring & Observability Tools · JIRA · Git

Certifications (Preferred) Splunk Certified Architect/Admin · AWS Certified Solutions Architect · Azure Administrator/Architect


Job Summary

This senior infrastructure developer role focuses on designing administering and optimizing Splunk platforms to support enterprise

Good experience in Python monitoring observability and analytics needs in a hybrid work environment. The profile involves implementing robust logging standards maintaining platform reliability and collaborating with cross functional teams across industry essential domains to enable secure and data driven operations.


Responsibilities

  • Administer Splunk platform components to ensure stable indexers search heads deployment servers and forwarders that consistently support enterprise monitoring needs.

Good expireince in Python

  • Configure data onboarding pipelines in Splunk by designing efficient sourcetypes field extractions and indexing strategies that improve query performance and data quality.
  • Develop reusable Splunk searches dashboards and reports that provide actionable insights and help stakeholders monitor infrastructure health and application performance.
  • Optimize Splunk storage and retention policies by tuning index configurations and archive strategies that balance performance compliance and cost efficiency.
  • Implement proactive alerting solutions in Splunk that detect anomalies capacity risks and service degradations before they impact business operations.
  • Troubleshoot Splunk search performance issues by analyzing search patterns identifying inefficient queries and recommending tuning improvements.
  • Collaborate with infrastructure and application teams to establish logging standards naming conventions and data models that strengthen observability across environments.
  • Document Splunk configurations runbooks and operational procedures that help ensure consistent deployments and faster incident resolution.
  • Coordinate with security and compliance teams to align Splunk configurations with organizational governance requirements and audit readiness.
  • Enhance automation around Splunk administration tasks using scripts or tools that streamline onboarding configuration and maintenance activities.
  • Participate in incident investigations by using Splunk data to identify root causes verify hypotheses and recommend corrective actions.
  • Contribute to continuous improvement initiatives by analyzing usage patterns proposing new dashboards and refining metrics that support organizational goals.
  • Engage with industry essential domain stakeholders to translate operational requirements into Splunk based monitoring solutions that improve service reliability.


Qualifications

  • Demonstrate experience of at least three years as Splunk administrator managing enterprise deployments and supporting production environments.
  • Apply strong knowledge of infrastructure concepts such as servers networks and storage to design resilient Splunk architectures that operate efficiently.
  • Use understanding of industry essential domains to contextualize observability requirements and build dashboards that reflect critical business processes.
  • Show proficiency in search processing language to craft optimized queries complex alerts and meaningful visualizations that guide operational decisions.
  • Exhibit familiarity with scripting or automation tools that assist in configuration management and repetitive administrative tasks within Splunk.
  • Display good communication skills to collaborate with technical and non technical partners in a hybrid work model and document outcomes clearly.
  • Utilize problem solving capabilities and analytical thinking to diagnose Splunk issues coordinate with support teams and implement sustainable fixes.

关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。

补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。

帮助您蓬勃发展与成长的福利

我们的福利计划以您为中心打造——帮助您享受充实、平衡且健康的生活。
有葉子的植物的藍色線條圖

财务健康

我们会定期审查市场数据,确保薪酬体现您所带来的价值。您的福利不仅限于薪资,还可能包括退休计划、财务教育等。

Stay Healthy Midnight Blue RGB

身心健康

我们通过带薪休假、在条件允许下的灵活工作安排、医疗保障计划、心理咨询、心理健康盟友计划等,赋能您将身心健康放在首位。

Build The Career You Want Midnight Blue RGB

您的职业发展,由您做主

在 Cognizant 提供的 35 万多个岗位中,您将有机会探索新的技术、行业和工作地点,并打造推动职业发展的关键技能。

Making A Meaningful Impact Midnight Blue RGB

现实世界的影响力

想想您所依赖的那些知名品牌。很可能,他们也依赖我们来帮助强化其业务。在这里,您将把大胆的想法转化为改善全球生活的解决方案。

还没有找到合适的机会吗?

获取为您量身定制的最新职位机会、招聘活动和公司新闻!

掌握最新动态