Skip to main content

Splunk Enterprise Security Engineer (Tier II / Tier III)

00068950776

This role sits within Cognizant's strategic engagement with one of the world's foremost enterprise security and observability companies. You will work on complex enterprise SIEM environments, contributing directly to detection engineering and security platform operations at a global scale.


About the Role

We are seeking a Splunk Enterprise Security Engineer to investigate and resolve complex issues across our enterprise SIEM environment. This role requires deep hands-on expertise in Splunk ES, advanced SPL, and a strong security mindset to maintain detection accuracy, reduce false positives, and ensure platform reliability.


What You Will Do

  • Investigate and resolve complex issues including correlation search failures, missing or delayed notable events, Risk-Based Alerting (RBA) anomalies, and data model acceleration issues
  • Diagnose performance issues impacting dashboards, scheduled searches, and notable event generation
  • Utilise advanced SPL to trace the full detection lifecycle: raw data ingestion → CIM normalisation → data models → correlation searches → notable events
  • Optimise searches using tstats and data model acceleration to improve detection accuracy and efficiency
  • Manage and optimise CIM compliance, data model acceleration, and summaries
  • Ensure correct data mapping, field extraction, and normalisation
  • Design, troubleshoot, and optimise correlation searches, risk rules, and scoring mechanisms
  • Investigate and resolve Search Head Cluster issues including captain election problems, configuration sync failures, and knowledge bundle replication delays
  • Monitor and tune scheduler performance to avoid skipped searches and prevent resource contention

What You Bring

  • Strong hands-on Splunk Enterprise Security experience
  • Experience in large-scale enterprise SIEM deployments
  • Expertise in Advanced SPL, Data Model Acceleration, CIM, and correlation searches
  • Knowledge of RBA, Search Head Clustering, tstats, and scheduler tuning
  • Understanding of security frameworks and compliance standards
  • Networking fundamentals (TCP/IP, DNS, HTTP/S)

Technical Skills Splunk ES · Advanced SPL · SHC · CIM · tstats · RBA · AWS/Azure/GCP · JIRA · Git


About us
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, building the bridge between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, realize tangible returns and keep global enterprises ahead in a fast-changing world. See how at www.cognizant.com or @cognizant.

Additional employment information

Compensation information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.

Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government issued ID during each interview.

Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.

If you have a disability that requires reasonable accommodation to search for a job opening or submit an application, please email [email protected] for roles based in the Americas or [email protected] for roles based in India.

Benefits that help you thrive and grow

Our benefits program is built with you in mind—so you can enjoy a fulfilling, balanced and healthy life.

a blue line drawing of a plant with leaves

Financial wellbeing

We regularly review market data to ensure compensation reflects the value you bring. Your benefits extend beyond pay and may include retirement plans, financial education, etc.

Stay Healthy Midnight Blue RGB

Physical and mental health

We empower you to prioritize your wellbeing through paid time off, flexible working where possible, healthcare plans, counselling, our Mental Health Allyship program and more. 

Build The Career You Want Midnight Blue RGB

Your career, your way

With 350,000+ roles at Cognizant, you’ll have opportunities explore new technologies, industries and locations—and build the skills you need to grow your career.

Making A Meaningful Impact Midnight Blue RGB

Real-world impact

Think about the biggest brands you rely on. Chances are, they rely on us to help strengthen their business. Here, you’ll turn bold ideas into solutions that improve lives everywhere.

Haven't yet found the right opportunity?

Get the latest updates on job opportunities, recruitment events and company news—tailored just for you!

Be in the know