Overview
About Cognizant Corporate Cognizant Corporate is a global community united by a shared purpose: to make a meaningful impact. We are committed to excellence and driven by outcomes that matter. Collaboration is at the heart of how we work, and our forward-thinking mindset fuels continuous learning, innovation, and growth. At Cognizant, careers transcend titles. We empower our people to think strategically, inspire others, and lead with purpose – always guided by our core values. Join us in shaping the future of business.
About The Role As a SOD Senior Associate, you will drive impactful contributions and focus on outcomes. You will be a key member of the Cyber Security team, collaborating with Arulanandakumar N. You will be part of Corporate Security (CS) Global Cyber Operations (GCO). The Log Onboarding Engineer is responsible for the integration, routing, transformation, and optimization of log data using Cribl Stream and Cribl Edge platforms. The engineer builds and maintains pipelines, implements data shaping logic, ensures metadata normalization, and supports compliance-driven retention or masking policies. As a team of self-starters, you can work with impact with our vibrant people and culture while enjoying opportunities for learning.
Responsibilities
- Design and implement Cribl pipelines for routing, filtering, enriching, and transforming logs from diverse log sources.
- Onboard new log sources from infrastructure, cloud, applications, and security tooling (e.g., firewalls, proxies, EDR, cloud APIs).
- Create source-specific configurations and route logs to designated destinations like Splunk, Elastic, S3, Kafka, or data lakes.
- Develop parsing, metadata tagging, masking, and enrichment logic to normalize log events across formats and vendors.
- Manage Cribl Worker Groups, Edge Nodes, and Stream routes for scalable ingestion performance.
- Implement logic to drop noisy events, reduce duplication, and optimize license usage in downstream SIEM platforms.
- Troubleshoot ingestion issues, pipeline errors, source latency, and message drops with Cribl diagnostics.
- Coordinate onboarding activities with detection engineers, platform engineers, and asset owners.
- Build dashboards or logging metrics to monitor onboarding status, coverage, completeness, and success/failure rates.
- Maintain up-to-date documentation of data flows, onboarding configurations, and source dictionaries.
- Support audits, compliance requests, and secure handling policies by applying redaction, masking, or suppression logic where needed.
- Embrace our vibrant culture by striving for excellence, focusing on meaningful outcomes, and collaborating effectively. Take ownership, build relationships, and focus on personal growth to drive business strategy and foster an inclusive culture, creating unmatched career opportunities and impactful work.
Qualifications
- 4+ years in cybersecurity, with 2+ years in security operations or detection engineering.
- Strong understanding of SIEM platforms and detection engineering.
- Familiarity with MITRE ATT&CK, D3FEND, Cyber Kill Chain, and threat modeling.
- Scripting (Python), query languages (SPL, KQL), and automation tools.
- Certifications like GCIA, GCTI, GDSA, CISSP, CEH, Security+, or MITRE ATT&CK Defender.
- Hands-on experience with Cortex XSIAM for detection content development and incident lifecycle management.
Additional
- A strong sense of ownership, desire to create meaningful outcomes, and passion for work that serves a greater good for customers, communities, or global challenges.
- Experience in globally distributed teams.
- Strong analytical and problem-solving skills, ability to develop hypotheses and analyze subtle anomalies.
- Effective communication and reporting skills, familiarity with cyber risk frameworks, and flexibility for cross-timezone collaboration.
- Experience in integrating Cortex XSIAM with threat intelligence and SOC workflows.