This role is part of Cognizant's engagement with one of our most strategic global technology clients — a world leader in enterprise cybersecurity and behavioural analytics. You will work on sophisticated UBA environments, contributing to insider threat detection and security analytics at enterprise scale.
About the Role
We are seeking a Splunk UBA Engineer to investigate and resolve complex behavioural analytics and insider threat detection issues. This is a specialist role for a security-focused engineer with deep knowledge of anomaly detection, threat modelling, and user entity behaviour analytics.
What You Will Do
- Investigate and resolve issues related to anomaly detection failures, threat model misconfigurations, missing or delayed risk events, and data ingestion inconsistencies
- Analyse UBA logs, system diagnostics, data pipelines, and ingestion flows
- Monitor and optimise user and entity behaviour models, threat detection algorithms, and risk scoring
- Investigate suspicious activities and insider threats; validate and tune anomaly detection thresholds
- Ensure accurate ingestion of authentication logs, network data, and endpoint data
- Troubleshoot data mapping and normalisation issues
- Optimise UBA performance through model fine-tuning, scoring mechanisms, and bottleneck resolution
- Develop Python/Shell scripts to automate tasks and enhance data processing and alerting workflows
- Collaborate with engineering teams to enhance detection coverage and improve UBA configurations
- Create and maintain technical documentation, SOPs, runbooks, and troubleshooting playbooks
What You Bring
- Strong understanding of security analytics, anomaly detection, threat modelling, and behavioural analytics
- Splunk administration knowledge and log analysis skills
- Linux fundamentals and basic networking knowledge (TCP/IP, DNS, HTTP/S)
- Experience with cloud platforms (AWS/Azure/GCP) and scripting (Python/Shell)
Technical Skills Splunk UBA · Splunk Admin · Linux · AWS/Azure/GCP · Python · Shell · JIRA · Git
Certifications (Preferred) Splunk Certified Admin
What we offer
- The chance to work with impact. Here, you’re empowered to bring your biggest thinking to help our company and clients improve everyday life.
- Ownership over your career. Stay at the top of your game through our award-winning learning and development ecosystem. And when your ambitions change or we offer new opportunities, we help you pivot by providing reskilling, on-the-job learning and guidance to find new roles that might be a better fit.
- The opportunity to thrive on a high caliber team with heart. We celebrate each other’s experiences and perspectives and promote a sense of belonging through our affinity groups and diversity and inclusion initiatives.
- A comprehensive total rewards package, including a competitive salary and a pension plan with matching contributions.
- Flexible health and financial benefits to support you and your eligible dependents—from day one.
- True work-life balance. Be at your best through paid time off, flexible work arrangements, volunteering opportunities, social events, and so much more.
About us
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, building the bridge between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, realize tangible returns and keep global enterprises ahead in a fast-changing world. See how at www.cognizant.com or @cognizant.
Other employment-related information
Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, provincial or local laws.
If you have a disability that requires reasonable accommodation to search for a job opening or submit an application, please email [email protected] with your request and contact information.
Language requirements vary depending on roles, but we ask that all candidates have basic English proficiency for company-wide communications purposes. For roles based in Quebec, professional English proficiency is required, as you’ll deliver services to and collaborate with stakeholders outside the province who may not speak French.










