Get more replies from employers
Send a job-specific resume in minutes.
FC Global Services India LLP (First Citizens India) in Bengaluru seeks a Principal Infrastructure Engineer to lead enterprise observability efforts. The role demands advanced Splunk administration, data modeling, and automated onboarding pipelines using Git and Ansible.
You will work with cross‑functional teams to scale onboarded data across Splunk Cloud and on‑premise environments. Ideal candidates will have 10+ years in infrastructure, strong scripting skills, and experience with SIEM
FC Global Services India LLP (First Citizens India), a part of First Citizens BancShares, Inc., a top 20 U.S. financial institution, is a global capability center (GCC) based in Bengaluru. Our India-based teams benefit from the company’s over 125-year legacy of strength and stability. First Citizens India is responsible for delivering value and managing risks for our lines of business. We are particularly proud of our strong, relationship-driven culture and our long-term approach, which are deeply ingrained in our talented workforce. This is evident across all key areas of our operations, including Technology, Enterprise Operations, Finance, Cybersecurity, Risk Management, and Credit Administration. We are seeking talented individuals to join us in our mission of providing solutions fit for our clients’ greatest ambitions.
Principal Infrastructure Engineer
P4
Assistant Vice President
Hybrid
Bangalore
Seeking expert Splunk Admins for a critical enterprise-wide observability and monitoring initiative. This role is essential in designing, building, and implementing standardized data onboarding pipelines and configurations to bring applications into Splunk Enterprise and Splunk Enterprise Security platforms. Success demands both technical depth and the ability to work at a rapid pace while maintaining high quality and consistency.
Design and implement standardized data onboarding procedures and configurations for applications; establish repeatable patterns and templates. Conduct technical onboarding of applications into Splunk Cloud: configure data inputs, create parsing rules, establish field extractions, and build data models. Map application data and security events to Splunk Common Information Model (CIM); identify and document relevant SIEM use cases. Build and optimize data models, lookups, and knowledge objects to support reporting, alerting, alerting rule creation, and compliance requirements. Design and implement automated onboarding pipelines using Git-based configuration management, Ansible playbooks, and CI/CD workflows to reduce manual effort and improve consistency. Establish and enforce standardized tagging conventions, naming standards, and data organization principles across all onboarded applications. Collaborate with Business Analysts to translate requirements into technical specifications; support requirements clarification and feasibility assessment. Work alongside Splunk Data Admins to execute onboarding at scale; establish code review and peer collaboration practices to maintain quality. Provide consultation to Splunk users and stakeholder teams on best practices, use cases, and guidance for creating and maintaining knowledge objects. Deliver training and knowledge-sharing sessions to Enterprise Monitoring Team and partner IT teams on standardized onboarding procedures and platform capabilities. Integrate Splunk with complementary monitoring and infrastructure platforms (Dynatrace, SolarWinds) to ensure cohesive observability workflows. Serve as primary technical point of contact for complex Splunk platform issues during the engagement period; support incident response as needed in collaboration with client's operations team. Monitor Splunk platform health and performance; proactively identify and resolve bottlenecks, optimization opportunities, and infrastructure constraints. Correlate and reconcile disparate events and data sources from multiple monitoring platforms to ensure consistent, reliable alerting and reporting. Troubleshoot and resolve complex data integration challenges; identify data quality issues, reconciliation gaps, and root causes. Document technical architecture, configuration decisions, onboarding procedures, and lessons learned to enable knowledge transfer and future maintenance. Participate in ongoing optimization and performance tuning as volume and complexity increase throughout the engagement.
Advanced Splunk Enterprise and Splunk Cloud administration. Strong knowledge of data models, data model accelerations, and knowledge objects. Deep understanding of Common Information Model (CIM) and data normalization principles. Experience with advanced search optimization, lookup tables, and automated lookups. Proficiency with Splunk Enterprise Security (ES) platform and SIEM use cases. Knowledge of Splunk Cloud-specific features, limitations, and best practices. Understanding of Splunk licensing, data ingestion pipelines, and performance tuning. Hands‑on experience designing and implementing data ingestion pipelines. Expertise in log parsing, data transformation, and field extraction. Strong proficiency with Git version control and collaborative development workflows (branching, pull requests, code reviews). Hands‑on experience with Ansible for infrastructure automation and configuration management. Experience with CI/CD pipelines and automated deployment processes. Scripting and automation using Python, Bash, or similar languages. Understanding of SIEM platforms and security event management workflows. Knowledge of common security use cases (authentication, access control, threat detection, incident response). Familiarity with compliance frameworks (SOX, PCI‑DSS, HIPAA) and audit trail requirements. Desired to have knowledge of complementary observability platforms (Dynatrace, SolarWinds, Prometheus, Elastic). Minimum 3+ years of hands‑on Splunk Enterprise administration and implementation experience. Minimum 10+ years of infrastructure, platform engineering, systems administration, or related technical domain experience. Splunk Certified Admin (SCA), Splunk Certified Power User (SCPU) and Splunk ES certification or coursework completed required; additional Splunk certifications (e.g., SCS, Developer) preferred. Excellent oral and written communication skills as well as positive, customer‑focused interpersonal skills and attitude. Excellent collaboration skills, ownership & accountability. Financial Services/Banking experience, Large Financial Institution (LFI) (or similarly complex environment) preferred. BE or MCA Degree in computer science or related field.
Reports to: Associate Director. Partners: Cross‑functional teams across geographies ( US team).
We are committed to providing an inclusive and accessible hiring process. If you require accommodations at any stage (e.g. application, interviews, onboarding) please let us know, and we will work with you to ensure a seamless experience.
FC Global Services India LLP (First Citizens India) is an Equal Employment Opportunity Employer. We are committed to fostering an inclusive and accessible environment and prohibit all forms of discrimination on the basis of gender, religion, caste, disability, sexual orientation, economic status or any other characteristics protected by the law. We strive to foster a safe and respectful environment in which all individuals are treated with respect and dignity. Our EEO policy ensures fairness throughout the employee life cycle.
FC Global Services India LLP (First Citizens India), a part of First Citizens BancShares, Inc., a top 20 U.S. financial institution, is a global capability center (GCC) based in Bengaluru. Our India-based teams benefit from the company’s over 125-year legacy of strength and stability. First Citizens India is responsible for delivering value and managing risks for our lines of business. We are particularly proud of our strong, relationship‑driven culture and our long‑term approach, which are deeply ingrained in our talented workforce. This is evident across all key areas of our operations, including Technology, Enterprise Operations, Finance, Cybersecurity, Risk Management, and Credit Administration. We are seeking talented individuals to join us in our mission of providing solutions fit for our clients’ greatest ambitions.
First Citizens BancShares, Inc., a top 20 U.S. financial institution with more than $200 billion in assets and a member of the Fortune 500™, is the financial holding company for First-Citizens Bank & Trust Company ("First Citizens Bank"). Headquartered in Raleigh, N.C., First Citizens Bank has built a unique legacy of strength, stability and long‑term thinking that has spanned generations. Visit: https://www.firstcitizens.com/