Splunk Cybersecurity Architect

Cognizant

Vancouver

Hybrid

CAD 78,000 - 124,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
Long-term/Short-term Disability
Paid Parental Leave

Job summary

Cognizant in Vancouver, BC is seeking a Splunk Cybersecurity Architect to design and enhance enterprise security monitoring, detection, automation, and response capabilities.

You will lead across Splunk SIEM, SOAR, Microsoft Defender, and Cisco security tools, shaping detection strategies aligned with MITRE ATT&CK, ISO 27001, and PCI-DSS.

This hybrid role requires 3 days per week at a Cognizant office in Vancouver, with travel as needed and a focus on improving cyber resilience.

Qualifications

  • Splunk advanced SPL and CIM/data model architecture, dashboards, data onboarding, and performance tuning.
  • SOAR playbooks design/authorship, enrichment and API integrations.
  • Microsoft Defender EDR telemetry analysis and threat management.
  • Cisco Umbrella DNS/T tunnels detection and Cisco Secure Email for phishing/BEC.
  • Knowledge of MITRE ATT&CK mapping for detection coverage and gap analysis.
  • ISO 27001 ISMS controls and PCI-DSS requirements applied.

Responsibilities

  • Design and architect enterprise SIEM solutions using Splunk, including CIM architecture, data onboarding strategies, correlation searches, risk-based alerting, and dashboards.
  • Develop and maintain advanced SPL queries, detection use cases, and threat analytics for visibility and detection effectiveness.
  • Architect and develop automated response and orchestration workflows using Splunk SOAR (Phantom), XSOAR, or similar.
  • Lead development and tuning of detection content leveraging Defender, Cisco Umbrella, and Secure Email solutions.
  • Establish architecture standards, best practices, and governance for cybersecurity platforms and monitoring technologies.

Skills

Splunk SIEM
SPL queries
Threat detection
Python/PowerShell
MITRE ATT&CK
ISO 27001/PCI-DSS
SOAR orchestration
Cisco security

Tools

Splunk Phantom
XSOAR
Python tooling
PowerShell tooling
Microsoft Defender EDR
Cisco security tools

Job description

Splunk Cybersecurity Architect
About the Role

The Splunk Cybersecurity Architect is responsible for designing, architecting, and continuously enhancing enterprise-wide security monitoring, detection, automation, and response capabilities. This role provides technical leadership across Splunk SIEM, SOAR platforms, Microsoft Defender, and Cisco security technologies, ensuring scalable and effective cybersecurity operations. The Architect develops advanced detection strategies, security automation frameworks, and incident response capabilities aligned with the MITRE ATT&CK framework, ISO 27001, and PCI-DSS requirements. The role partners with SOC, Incident Response, Infrastructure, and Risk teams to improve cyber resilience, optimize security tools, and mature overall security operations capabilities.

In This Role, You Will:
1. Security Monitoring & Detection Architecture
  • Design and architect enterprise SIEM solutions using Splunk, including CIM architecture, data onboarding strategies, correlation searches, risk-based alerting, and security dashboards.
  • Develop and maintain advanced SPL queries, detection use cases, and threat analytics to improve visibility and detection effectiveness.
  • Conduct detection coverage assessments and map use cases against the MITRE ATT&CK framework to identify and address security gaps.
2. Security Automation & SOAR Strategy
  • Architect and develop automated response and orchestration workflows using Splunk SOAR (Phantom), XSOAR, or similar platforms.
  • Design integrations between security technologies, APIs, threat intelligence feeds, and incident management platforms.
  • Drive automation initiatives using Python and PowerShell to improve analyst productivity, reduce response times, and increase operational efficiency.
3. Threat Detection Engineering & Incident Response Enablement
  • Lead the development and tuning of advanced detection content leveraging Microsoft Defender EDR telemetry, Cisco Umbrella, and Cisco Secure Email solutions.
  • Provide architectural guidance for threat hunting, incident investigations, phishing and BEC analysis, DNS-based threats, and endpoint security monitoring.
  • Support major incident response activities through forensic data analysis and security telemetry correlation.
4. Security Technology Governance & Optimization
  • Establish architecture standards, best practices, and operational processes for cybersecurity platforms and monitoring technologies.
  • Ensure optimal performance, scalability, and reliability of SIEM, SOAR, EDR, email security, and cloud security solutions.
  • Collaborate with cross-functional teams to evaluate emerging threats, technologies, and security capabilities that strengthen the organization’s security posture.
5. Compliance, Risk Management & Security Leadership
  • Align security monitoring and detection capabilities with ISO 27001 controls, PCI-DSS requirements, and organizational cybersecurity policies.
  • Support internal and external audits by providing security architecture documentation, control evidence, and remediation recommendations.
  • Serve as a technical mentor and trusted advisor to SOC analysts, engineers, and security stakeholders while driving continuous improvement initiatives across the cybersecurity program.
Work Model

We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role’s business requirements, this is a hybrid position requiring 3 days a week in a client or Cognizant office in Vancouver, BC. Regardless of your working arrangement, we are here to support a healthy work-life balance though our various wellbeing programs.

The working arrangements for this role are accurate as of the date of posting. This may change based on the project you’re engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations. Occasional travel may be required for client meetings, workshops, project activities, and business-critical needs.

What You Need to Have to Be Considered
  • Splunk: Advanced SPL, correlation rule authoring, risk-based alerting, CIM/data model architecture, dashboard/report building, performance tuning
  • SOAR (Splunk SOAR/Phantom, XSOAR, or similar): Playbook design/authorship (not just execution), enrichment configuration, API/app integration basics
  • Microsoft Defender: Advanced EDR telemetry analysis, custom detection rules, threat & vulnerability management
  • Cisco Umbrella: DNS tunneling/DGA detection, policy engineering
  • Cisco Secure Email: BEC/phishing forensics, DLP and policy tuning
  • Strong grasp of MITRE ATTACK for detection mapping and gap analysis
  • Working knowledge of digital forensics fundamentals (memory, disk, network forensics basics)
  • Scripting/automation exposure (Python, PowerShell) for SOAR app development or SPL automation is a strong plus
  • Solid understanding of ISO 27001 ISMS controls and PCI-DSS requirements as applied
These Will Help You Stand Out
  • 8-12 years of SOC/security operations experience, including demonstrated L1-to-L2 progression or equivalent
  • Preferred certifications: Splunk Certified Power User/Admin, GCIH/GCIA, Microsoft SC-200, CySA+, CEH, or equivalent
  • Exposure to formal ISO 27001 or PCI-DSS audit cycles preferred
  • to SOC/incident response

We're excited to meet people who share our mission and can make an impact in a variety of ways. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.

Salary and Other Compensation

Applications will be accepted until September 18, 2026.

The annual salary for this position is between CAD 78,000 - CAD 124,000 depending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.

Benefits
  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • Long-term/Short-term Disability
  • Paid Parental Leave

Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Splunk Cybersecurity Architect
Hybrid Splunk Cybersecurity Architect

Cognizant • Vancouver

Hybrid
CAD 78,000 - 124,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
Long-term/Short-term Disability
+1
Splunk Engineer
Splunk Engineer

Tata Consultancy Services • Toronto

On-site
CAD 90,000 - 120,000
Security Engineer - Snyk
Security Engineer - Snyk

Cognizant • Toronto

On-site
CAD 100,000 - 115,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
Long-term/Short-term Disability
+1
Splunk Engineer
Splunk Engineer

Tata Consultancy Services Limited • Toronto

On-site
CAD 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

fispan • Vancouver

On-site
CAD 130,000 - 160,000
Extended health and dental benefits
Paid time off
Savings and retirement plan matching
+5
Senior Offensive Security – Penetration Testing & Red Team Engineer
Senior Offensive Security – Penetration Testing & Red Team Engineer

Cognizant • Toronto

On-site
CAD 147,000 - 172,000
Medical/Dental/Vision/Life Insurance
Paid holidays and PTO
Long-term/Short-term Disability
+1
Senior .NET Application Security Developer
Senior .NET Application Security Developer

Cognizant • Halifax

On-site
CAD 61,000 - 100,000
Medical Insurance
Paid Holidays
401(k) Plan
+2
Security Platform Developer, Security Automation (Python, Splunk SOAR)
Security Platform Developer, Security Automation (Python, Splunk SOAR)

Sun Life • Toronto

Hybrid
CAD 65,000 - 105,000
Hybrid work model
Security Operations Analyst - Copperleaf
Security Operations Analyst - Copperleaf

IFS • Toronto

Hybrid
CAD 70,000 - 80,000
Flexible paid time off
Medical, dental, & vision insurance
RRSP with company contribution
+1
Enterprise Chief Architect, AWS Platform
Enterprise Chief Architect, AWS Platform

Cognizant • Dover

On-site
USD 165,000 - 192,000
Medical/Dental/Vision/Life Insurance
Paid holidays and PTO
401(k) plan and contributions
+3