Splunk UBA Engineer (Tier II / Tier III)
Bengaluru, Karnataka, India · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Any graduate
- Eligibility
- Any graduate is eligible to apply.
- Resume
- Required to apply
Where you'll work
Job description
Role overview
This position sits within Cognizant’s work for a major global technology client known for enterprise cybersecurity and behavioural analytics. The job centers on supporting sophisticated user and entity behavior analytics environments that help identify insider threats and improve security intelligence at scale.
Key responsibilities
- Look into and fix problems such as failed anomaly detection, incorrect threat model setups, missing or delayed risk events, and unreliable data ingestion.
- Review UBA logs, platform diagnostics, data pipelines, and ingestion paths to find root causes.
- Track and improve user/entity behaviour models, detection logic, and risk scoring outcomes.
- Examine suspicious activity and insider threat indicators, then calibrate anomaly thresholds as needed.
- Make sure authentication, network, and endpoint data are brought in correctly.
- Resolve issues in data mapping, parsing, and normalisation.
- Improve platform performance by tuning models, refining scoring, and removing operational bottlenecks.
- Build Python and shell scripts to automate routine tasks and strengthen alerting and data-processing workflows.
- Work with engineering teams to expand detection coverage and strengthen UBA configurations.
- Prepare and maintain SOPs, technical documentation, runbooks, and troubleshooting guides.
Required background
- Solid knowledge of security analytics, anomaly detection, threat modelling, and behavioural analysis.
- Hands-on familiarity with Splunk administration and log investigation.
- Basic Linux knowledge and an understanding of networking fundamentals such as TCP/IP, DNS, and HTTP/S.
- Experience working with cloud platforms like AWS, Azure, or GCP.
- Ability to script with Python and shell languages.
Technical focus
- Splunk UBA administration and support
- Security operations and security analytics
- Log analysis and troubleshooting
- Behavioural modelling and risk scoring
- Network and protocol fundamentals
- Linux system basics
- Cloud platform familiarity
- Automation using Python and shell scripting
- Documentation and runbook creation
Eligibility
Any graduate can apply.
Additional information
The role is based in Bengaluru, India.
A Splunk Certified Admin credential is preferred.
No openings, salary, stipend, duration, or start-date details were provided.