7 days ago
Base Salary
$161k - $204k/yr
Responsibilities
- Deliver actionable threat intelligence during active incidents, including indicators, TTPs, behavioral patterns, and threat actor context.
- Produce recurring and ad hoc intelligence products that inform hunts, detections, and business decisions.
- Plan and conduct retrospective, project-based, and reusable threat hunts.
- Build and maintain scripts, API integrations, and automation for threat-data ingestion, processing, enrichment, and scalable hunting use cases.
- Apply AI to accelerate intelligence analysis, threat hunting, and tooling development.
- Identify adversary activity missed by existing detection rules and provide findings to Detection Engineering.
- Create written products, presentations, and RFI responses for technical and non-technical audiences.
- Mentor analysts and engineers across threat intelligence, hunting, and engineering.
- Participate in an on-call rotation and provide after-hours support during major incidents.
Requirements
- 8+ years of professional cybersecurity experience, including demonstrable experience in cyber threat intelligence and/or threat hunting.
- Experience with sophisticated searching and reporting in Splunk and fluent use and interpretation of SPL.
- Ability to translate large datasets into meaningful information and persist through complex hunts.
- Understanding of attacker behavior and ability to convert intelligence and hunt findings into repeatable, automated capabilities.
- Experience applying AI to accelerate development and analysis.
- Preferred: experience leading threat actor and campaign attribution.
- Preferred: strong programming proficiency in one or more languages for scripts and API automation.
- Preferred: experience delivering tactical threat intelligence for incident response.
- Preferred: hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling.
- Preferred: experience uncovering activity missed by industry detection rules.
- Preferred: experience with network and host-based logs and common services such as DNS, DHCP, email, proxy, VPN, and firewall.
- Preferred: proficiency with AWS, GCP, or Azure and a strong understanding of Linux.
- Must be a U.S. Person and, where required, a U.S. citizen able to work on U.S. soil in classified environments.
Benefits
- Medical, dental, and vision insurance, 401(k) with Cisco matching contribution, paid parental leave, disability coverage, and basic life insurance.
- Potential eligibility for Cisco restricted stock unit grants and annual bonuses for non-sales roles.
- Paid holidays, floating holiday, birthday leave, year-end shutdown, wellness days, vacation or flexible time off, and sick time.
- Additional paid time away for critical or emergency family issues and up to 10 paid volunteer days annually.
- The application window is expected to close October 26, 2026, though the posting may be removed earlier if filled or if sufficient applications are received.
- The role involves classified U.S. Government environments, an on-call rotation, and possible after-hours incident support.
Tech Stack
Categories
About Cisco
Cisco is the worldwide technology leader that is revolutionizing the way organizations connect and protect in the AI era. For more than 40 years, Cisco has securely connected the world. With its industry leading AI-powered solutions and services, Cisco enables its customers, partners and communities to unlock innovation, enhance productivity and strengthen digital resilience. With purpose at its core, Cisco remains committed to creating a more connected and inclusive future for all.