×
Register Here to Apply for Jobs or Post Jobs. X

Splunk Cybersecurity Architect

Job in Vancouver, BC, Canada
Listing for: Cognizant
Part Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 78000 - 124000 CAD Yearly CAD 78000.00 124000.00 YEAR
Job Description & How to Apply Below

Splunk Cybersecurity Architect About the Role

The Splunk Cybersecurity Architect is responsible for designing, architecting, and continuously enhancing enterprise-wide security monitoring, detection, automation, and response capabilities. This role provides technical leadership across Splunk SIEM, SOAR platforms, Microsoft Defender, and Cisco security technologies, ensuring scalable and effective cybersecurity operations. The Architect develops advanced detection strategies, security automation frameworks, and incident response capabilities aligned with the MIT&CK framework, ISO 27001, and PCI-DSS requirements.

The role partners with SOC, Incident Response, Infrastructure, and Risk teams to improve cyber resilience, optimize security tools, and mature overall security operations capabilities.

In This Role, You Will:
1. Security Monitoring & Detection Architecture
  • Design and architect enterprise SIEM solutions using Splunk, including CIM architecture, data onboarding strategies, correlation searches, risk-based alerting, and security dashboards.
  • Develop and maintain advanced SPL queries, detection use cases, and threat analytics to improve visibility and detection effectiveness.
  • Conduct detection coverage assessments and map use cases against the MIT&CK framework to identify and address security gaps.
2. Security Automation & SOAR Strategy
  • Architect and develop automated response and orchestration workflows using Splunk SOAR (Phantom), XSOAR, or similar platforms.
  • Design integrations between security technologies, APIs, threat intelligence feeds, and incident management platforms.
  • Drive automation initiatives using Python and Power Shell to improve analyst productivity, reduce response times, and increase operational efficiency.
3. Threat Detection Engineering & Incident Response Enablement
  • Lead the development and tuning of advanced detection content leveraging Microsoft Defender EDR telemetry, Cisco Umbrella, and Cisco Secure Email solutions.
  • Provide architectural guidance for threat hunting, incident investigations, phishing and BEC analysis, DNS-based threats, and endpoint security monitoring.
  • Support major incident response activities through forensic data analysis and security telemetry correlation.
4. Security Technology Governance & Optimization
  • Establish architecture standards, best practices, and operational processes for cybersecurity platforms and monitoring technologies.
  • Ensure optimal performance, scalability, and reliability of SIEM, SOAR, EDR, email security, and cloud security solutions.
  • Collaborate with cross-functional teams to evaluate emerging threats, technologies, and security capabilities that strengthen the organization's security posture.
5. Compliance, Risk Management & Security Leadership
  • Align security monitoring and detection capabilities with ISO 27001 controls, PCI-DSS requirements, and organizational cybersecurity policies.
  • Support internal and external audits by providing security architecture documentation, control evidence, and remediation recommendations.
  • Serve as a technical mentor and trusted advisor to SOC analysts, engineers, and security stakeholders while driving continuous improvement initiatives across the cybersecurity program.
Work Model

We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role’s business requirements, this is a hybrid position requiring 3 days a week in a client or Cognizant office in Vancouver, BC. Regardless of your working arrangement, we are here to support a healthy work-life balance though our various wellbeing programs.

The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations. Occasional travel may be required for client meetings, workshops, project activities, and business-critical needs.

What You Need to Have to Be Considered
  • Splunk: Advanced SPL, correlation rule authoring, risk-based alerting, CIM/data model architecture, dashboard/report building, performance tuning
  • SOAR (Splunk SOAR/Phantom, XSOAR, or similar): Playbook design/authorship (not just execution), enrichment configuration, API/app integration basics
  • Microsoft Defender: Advanced EDR telemetry analysis, custom detection rules, threat & vulnerability management
  • Cisco Umbrella: DNS tunneling/DGA detection, policy engineering
  • Cisco Secure Email: BEC/phishing forensics, DLP and policy tuning
  • Strong grasp of MITRE ATTACK for detection mapping and gap analysis
  • Working knowledge of digital forensics fundamentals (memory, disk, network forensics basics)
  • Scripting/automation exposure (Python, Power Shell) for SOAR app development or SPL automation is a strong plus
  • Solid understanding of ISO 27001 ISMS controls and PCI-DSS requirements as applied
These Will Help You Stand Out
  • 8–12 years of SOC/security operations experience, including demonstrated L1-to-L2 progression or…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary