About the Role
Splunk's Threat Response SOC operates globally, 24/7, at the intersection of incident response, detection engineering, and automation. We protect Splunk's enterprise and product environments and are constantly building better ways to do it. This role combines hands-on security operations with AI-enabled investigation workflows and human-supervised agentic tooling to reduce analyst toil, aiming for faster incident response, less noise, and a sharper SOC.
Responsibilities
- Own the full arc of security incidents from first alert to documented resolution.
- Triage, investigate, and respond to security alerts across Splunk's enterprise and product environments.
- Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
- Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
- Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
- Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight.
- Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.
Requirements
- Bachelor's Degree and 4+ years' of experience in security operations, incident response, or related technical role.
- Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
- Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
- Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
- Experience with automation scripts, and make updates to playbooks, pipeline configurations, or modular tooling.
- Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
- Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.
- Must be a U.S. Person (U.S. citizen).
- May perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.
Skills
- Splunk Enterprise Security
- Splunk SPL
- SOAR platforms
- Python
- Bash
- Go
- JavaScript
- Git/GitLab workflows
- CI/CD
- AI-assisted development
- AI-powered security tooling
- Agentic workflows
- MITRE ATT&CK
- Threat hunting methodology
- Malware triage
- Phishing analysis
- Vulnerability exploitation
- Attacker infrastructure analysis
- SOC performance metrics
- Cloud security concepts
- Container security concepts
- Kubernetes security concepts
- CI/CD runner security concepts
- Artifact registry security concepts
- Package management security concepts
- Software supply chain security concepts
Location
- Remote
- On U.S. soil
Work Type
- 24 x 7 Global Operations
- Full-time
Experience Level
- 4+ years of experience
Education Level
- Bachelor's Degree
Salary/Compensations
- $102,300.00 - $135,900.00
- $128,500.00 - $188,200.00 (New York City Metro Area)
- $114,700.00 - $169,000.00 (Non-Metro New York state & Washington state)
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k) plan with Cisco matching contribution
- Paid parental leave
- Short-term disability coverage
- Long-term disability coverage
- Basic life insurance
- 10 paid holidays per full calendar year
- 1 floating holiday for non-exempt employees
- 1 paid day off for employee’s birthday
- Paid year-end holiday shutdown
- 4 paid days off for personal wellness
- 16 days of paid vacation time per full calendar year (non-exempt employees)
- Flexible vacation time off program (exempt employees)
- 80 hours of sick time off provided on hire date and each January 1st thereafter
- Up to 80 hours of unused sick time carried forward
- Additional paid time away for critical or emergency issues for family members
- Optional 10 paid days per full calendar year to volunteer
- Annual bonuses (non-sales roles)
- Performance-based incentive pay (sales roles)
About the Company
- At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond.
- We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds.
- Our solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
- Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions.
- We work as a team, collaborating with empathy to make really big things happen on a global scale.
- Our power starts with you.
