Job Description
Job Title:  SECURITY ARCHITECT L1
City:  Melbourne
State/Province:  Victoria
Posting Start Date:  5/21/26
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.
Job Description: 

Job Description

Role Purpose

The purpose of this role is to design the organisation’s computer and network security infrastructure and protect its systems and sensitive information from cyber threats

͏

Job Title

Splunk Data Administrator (Mid–Senior) – CIM / Data Onboarding / Hybrid Architecture

 

Role Summary

We are seeking a mid to senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on‑prem and cloud).

The ideal candidate is hands-on with CIM alignment, data source onboarding, field extractions (regex/props/transforms/ingest actions), TA deployment, and end-to-end operational management of Splunk data pipelines.

 

You will act as the key point of contact for ensuring log sources are onboarded correctly, parsed and normalized consistently, and made usable for security/IT operations, dashboards, correlation searches, and reporting.

͏

Key Responsibilities

 

Data Onboarding & Lifecycle Management

 

• Lead onboarding of new log sources end-to-end: requirements gathering, source validation, parsing strategy, TA selection/deployment, CIM alignment, testing, and release.

• Partner with Security/IT teams to translate use-cases into data requirements, ensuring sources deliver the right fidelity, timeliness, and coverage.

• Manage onboarding at scale using best practices for source types, metadata strategy, index & sourcetype governance, and naming conventions.

• Define and enforce data quality standards (field completeness, timestamps, event consistency, parsing accuracy, duplication control).

 

CIM Normalization & Data Modelling

 

• Normalize data to Splunk Common Information Model (CIM) with strong understanding of data models (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).

• Ensure fields are aligned to CIM requirements to support Splunk Enterprise Security (ES) and other CIM-based content.

• Validate normalization using SPL and develop reusable onboarding checklists.

 

Field Extraction, Parsing & Enrichment

 

• Design and implement robust field extractions using:

- props.conf / transforms.conf, REPORT/TRANSFORMS stanzas

- regex and structured parsing (KV_MODE, JSON, XML)

- ingest-time vs search-time extraction strategy

- sourcetype / timestamp / line breaking configuration

• Implement enrichment and routing using event breaking, host/source normalization, lookups, and tagging.

• Troubleshoot parsing issues (timestamp drift, multi-line events, encoding, truncation, duplicate ingestion, broken extractions).

͏

TA Installation & Configuration (Complex / Hybrid)

 

• Install, configure, and maintain Splunk Add-ons (TAs) and apps across:

- Heavy Forwarders / Universal Forwarders

- Indexers / Search Heads / SHC

- Deployment Server / Cluster Manager (where applicable)

• Maintain version compatibility and upgrade strategies for:

- Splunk Enterprise / Splunk Cloud

- Add-ons, apps, and content packs

• Package and deploy TAs using deployment pipelines and change management controls.

• Ensure fields are aligned to CIM requirements

 

Hybrid Splunk Architecture Operations

 

• Operate and support Splunk in complex environments:

- On-prem Indexer Cluster, Search Head Cluster, Forwarder tiers

- Splunk Cloud integrations where applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)

• Configure and troubleshoot data ingestion pipelines:

- Syslog (UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloud sources

• Ensure performance and reliability across the pipeline, including indexing throughput, parsing overhead, and search impact

͏

Monitoring, Troubleshooting & Governance

 

• Monitor ingestion health and pipeline performance:

- Forwarder health, queue saturation, parsing/indexing delays, dropped events

• Maintain governance for indexes, sourcetypes, retention, RBAC and data access boundaries (as required).

• Contribute to operational runbooks, SOPs, and documentation; drive continuous improvement in onboarding and normalization standards.

 

Required Skills & Experience (Mid–Senior)

 

• 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).

• Strong practical knowledge of:

- CIM normalization, tags/eventtypes, datamodel alignment

- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues

- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking

- TA installation/configuration and deployment patterns across Splunk tiers

• Experience with complex Splunk architectures:

- Indexer clusters, SH/SHC, forwarder management, deployment server

- Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies

• Comfortable writing and validating SPL for data quality and CIM compliance.

• Strong log source knowledge across common domains:

- Security: EDR, firewall, proxy, IAM/auth, VPN, email security

- Infrastructure: Windows, Linux, network devices, virtualization

- Cloud: AWS/Azure/GCP logging patterns (nice-to-have)

 

Preferred / Nice-to-Have

 

• Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.

• Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).

• Familiarity with:

- HEC, API ingestion, message queues

- ITSI / Observability (bonus)

• Splunk certifications (preferred):

- Splunk Core Certified Power User / Admin

- Splunk Enterprise Certified Admin

- Splunk ES Admin (bonus)

Mandatory Skills: SPLUNK Security Analytics .

 

Experience: 8-10 Years .

 

Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.
Information at a Glance

Get Job Alerts

Receive notifications when we have open roles and get other relevant career news


Register >
 

Join Us

Explore open roles that match your interests and skills


Search Jobs >
 

If you encounter any suspicious mail, advertisements, or persons who offer jobs at Wipro, please email us at helpdesk.recruitment@wipro.com. Do not email your resume to this ID as it is not monitored for resumes and career applications.

Any complaints or concerns regarding unethical/unfair hiring practices should be directed to our Ombuds Group at ombuds.person@wipro.com.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, caste, creed, religion, gender, marital status, age, ethnic and national origin, gender identity, gender expression, sexual orientation, political orientation, disability status, protected veteran status, or any other characteristic protected by law.

Wipro is committed to creating an accessible, supportive, and inclusive workplace. Reasonable accommodation will be provided to all applicants including persons with disabilities, throughout the recruitment and selection process. Accommodations must be communicated in advance of the application, where possible, and will be reviewed on an individual basis. Wipro provides equal opportunities to all and values diversity.