Cognizant

Splunk Cybersecurity Architect

Cognizant$78K — $124K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years of experience in cybersecurity with a focus on SIEM and SOAR technologies.
  • Advanced proficiency in Splunk, including SPL, correlation rules, and performance tuning.
  • Experience with Microsoft Defender, Cisco Umbrella, and Cisco Secure Email security solutions.
  • Solid understanding of MITRE ATT&CK for threat detection and incident response mapping.
  • Knowledge of compliance frameworks such as ISO 27001 and PCI-DSS related to cybersecurity operations.

Responsibilities

  • Design and implement enterprise-level SIEM solutions using Splunk.
  • Develop advanced detection strategies and detection use cases to enhance visibility.
  • Lead the creation of automated orchestration workflows using Splunk SOAR or similar tools.
  • Conduct assessments to identify security gaps and ensure robust monitoring practices.
  • Establish best practices and standards for security technology governance and optimization.

Benefits

  • Comprehensive medical, dental, vision, and life insurance.
  • Generous paid time off including holidays.
  • Supportive parental leave policy.
  • Long-term and short-term disability coverage.
Full Job Description
Splunk Cybersecurity Architect

About the Role

The Splunk Cybersecurity Architect is responsible for designing, architecting, and continuously enhancing enterprise-wide security monitoring, detection, automation, and response capabilities. This role provides technical leadership across Splunk SIEM, SOAR platforms, Microsoft Defender, and Cisco security technologies, ensuring scalable and effective cybersecurity operations. The Architect develops advanced detection strategies, security automation frameworks, and incident response capabilities aligned with the MITRE ATT&CK framework, ISO 27001, and PCI-DSS requirements. The role partners with SOC, Incident Response, Infrastructure, and Risk teams to improve cyber resilience, optimize security tools, and mature overall security operations capabilities.

In This Role, You Will:

1. Security Monitoring & Detection Architecture
  • Design and architect enterprise SIEM solutions using Splunk, including CIM architecture, data onboarding strategies, correlation searches, risk-based alerting, and security dashboards.
  • Develop and maintain advanced SPL queries, detection use cases, and threat analytics to improve visibility and detection effectiveness.
  • Conduct detection coverage assessments and map use cases against the MITRE ATT&CK framework to identify and address security gaps.

2. Security Automation & SOAR Strategy
  • Architect and develop automated response and orchestration workflows using Splunk SOAR (Phantom), XSOAR, or similar platforms.
  • Design integrations between security technologies, APIs, threat intelligence feeds, and incident management platforms.
  • Drive automation initiatives using Python and PowerShell to improve analyst productivity, reduce response times, and increase operational efficiency.

3. Threat Detection Engineering & Incident Response Enablement
  • Lead the development and tuning of advanced detection content leveraging Microsoft Defender EDR telemetry, Cisco Umbrella, and Cisco Secure Email solutions.
  • Provide architectural guidance for threat hunting, incident investigations, phishing and BEC analysis, DNS-based threats, and endpoint security monitoring.
  • Support major incident response activities through forensic data analysis and security telemetry correlation.

4. Security Technology Governance & Optimization
  • Establish architecture standards, best practices, and operational processes for cybersecurity platforms and monitoring technologies.
  • Ensure optimal performance, scalability, and reliability of SIEM, SOAR, EDR, email security, and cloud security solutions.
  • Collaborate with cross-functional teams to evaluate emerging threats, technologies, and security capabilities that strengthen the organization's security posture.

5. Compliance, Risk Management & Security Leadership
  • Align security monitoring and detection capabilities with ISO 27001 controls, PCI-DSS requirements, and organizational cybersecurity policies.
  • Support internal and external audits by providing security architecture documentation, control evidence, and remediation recommendations.
  • Serve as a technical mentor and trusted advisor to SOC analysts, engineers, and security stakeholders while driving continuous improvement initiatives across the cybersecurity program.

Work Model

We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role's business requirements, this is a hybrid position requiring 3 days a week in a client or Cognizant office in Vancouver, BC. Regardless of your working arrangement, we are here to support a healthy work-life balance though our various wellbeing programs.

The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations. Occasional travel may be required for client meetings, workshops, project activities, and business-critical needs.

What You Need to Have to Be Considered
Splunk: Advanced SPL, correlation rule authoring, risk-based alerting, CIM/data model architecture, dashboard/report building, performance tuning
SOAR (Splunk SOAR/Phantom, XSOAR, or similar): Playbook design/authorship (not just execution), enrichment configuration, API/app integration basics
Microsoft Defender: Advanced EDR telemetry analysis, custom detection rules, threat & vulnerability management
Cisco Umbrella: DNS tunneling/DGA detection, policy engineering
Cisco Secure Email: BEC/phishing forensics, DLP and policy tuning
• Strong grasp of MITRE ATTACK for detection mapping and gap analysis
• Working knowledge of digital forensics fundamentals (memory, disk, network forensics basics)
• Scripting/automation exposure (Python, PowerShell) for SOAR app development or SPL automation is a strong plus
• Solid understanding of ISO 27001 ISMS controls and PCI-DSS requirements as applied

These Will Help You Stand Out
• 8-12 years of SOC/security operations experience, including demonstrated L1-to-L2 progression or equivalent
• Preferred certifications: Splunk Certified Power User/Admin, GCIH/GCIA, Microsoft SC-200, CySA+, CEH, or equivalent
• Exposure to formal ISO 27001 or PCI-DSS audit cycles preferred
• to SOC/incident response

We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply, even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.

Salary and Other Compensation:

Applications will be accepted until September 18, 2026.

The annual salary for this position is between CAD 78,000 - CAD 124,000 depending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant's discretionary annual incentive program, based on performance and subject to the terms of Cognizant's applicable plans.

Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:
• Medical/Dental/Vision/Life Insurance
• Paid holidays plus Paid Time Off
• Long-term/Short-term Disability
• Paid Parental Leave

Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.

About Cognizant

TriZetto is Powering Integrated Healthcare Management. With technology solutions touching more than half the U.S. population today, TriZetto is uniquely positioned to drive the convergence of core benefit administration, care management and constituent engagement. TriZetto provides premier information technology solutions that enable payers and other constituents in the healthcare supply chain to improve the coordination of benefits and care for healthcare consumers.

Cognizant Careers

Join the vibrant team at Cognizant, a leading provider of information technology, consulting, and business process services. Cognizant is not just a company; it's a community where innovation, leadership, and diversity are valued and where every team member is encouraged to thrive.

Work You’ll Do

At Cognizant, we are dedicated to helping the world's leading companies build stronger businesses — not just for today but for the future. This commitment to growth and sustainability is what makes Cognizant a unique place to advance your career.

Explore Job Opportunities

Whether you're looking for an entry-level position or a more senior role, Cognizant offers a plethora of job opportunities that could be perfect for you. Our hiring process is designed to be transparent and engaging, ensuring that every candidate is able to showcase their skills and potential fully.

Innovative Work

Join a team where innovation is at the core of everything we do. Cognizant’s professionals are not just part of a company; they're part of a groundbreaking environment that combines technology, insights, and leadership to foster innovation across global industries.

Internship Programs

Kickstart your career with Cognizant’s internship programs. These opportunities allow you to gain hands-on experience, develop your professional skills, and network with experts in your field. An internship at Cognizant is a stepping stone to full-time employment and a chance to see how your studies apply in the real world.

Professional Growth and Development

Cognizant is committed to the professional growth of its employees. With access to cutting-edge training, leadership programs, and diversity initiatives, you can build a career that’s equipped for the demands of tomorrow’s business landscape.

Benefits and Culture

Our employees enjoy a range of benefits designed to support their physical, financial, and emotional well-being. Cognizant’s culture is built on a foundation of respect and inclusivity, where everyone’s contribution is valued. Join us and be part of a team that celebrates diversity and is driven to make a positive impact on the world.

Stay Connected

Join Our Team Search open positions that match your skills and interests. We look for passionate, curious, creative, and solution-driven team players. Ready to take the next step in your career journey? Explore the exciting employment and career opportunities waiting for you at Cognizant.

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the rewarding opportunities that await at Cognizant.

Networking and Interviews

Enhance your career prospects at Cognizant through our robust networking events. Prepare your resume, sharpen your interview skills, and connect with leaders across the industry to unlock new career paths. At Cognizant, we don’t just offer jobs; we offer career journeys. Be part of a team that’s committed to your long-term career growth and professional development. Join Cognizant today and be a part of our success story.
Learn more about Cognizant
Size
340,400 employees
Market Cap
$28.7 billion
Industry
Net Income
$1.3 billion
Founded
1994
5 Year Trend
+6.5%
Revenue
$16.6 billion
NASDAQ

Similar Jobs

More Jobs at Cognizant

More Information Technology Jobs

Find similar Splunk Cybersecurity Architect jobs: