Cisco

Cisco

Senior Security Engineer

RTP, North Carolina, US · Senior · Full-time

Sponsorship not specified$137k-$201kDetected 8 hours ago
GitCloud PlatformsCI/CDPlatform EngineeringCybersecuritySIEMSOC OperationsDetection EngineeringIncident ResponseCiscoCollaboration

About the role

  • The application window is expected to close on: 10/21/2026 Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.
  • This is a hybrid role at the RTP, NC office.

Responsibilities

  • This role will focus on developing, maintaining, and improving Splunk knowledge objects, detection content, validation dashboards, and operational standards that enable reliable security incident detection and response.
  • Build and maintain Splunk Enterprise Security correlation searches, notable events, risk-based alerts, and detection content that directly power security incident visibility across the Webex cloud environment.
  • Validate data onboarding quality across cloud services covering source types, indexes, field normalization, timestamp accuracy, and parsing consistency.
  • Partner with SOC and incident response teams to improve alert fidelity, reduce false positives, and ensure detections provide clear investigative context.

Requirements

  • Hands-on experience operating Splunk Enterprise and Splunk Enterprise Security at scale, including deep knowledge of full ES feature enablement for SOC/SIEM use cases.
  • Familiarity with cloud security logging, incident detection, threat detection logic, and SOC operations.
  • Develop detection build out and maintain validation dashboards aligned to telemetry ingestion contracts, ensuring required security events are present, accurate, timely, and CIM-compliant.

Nice to have

  • Experience with risk-based alerting in Splunk Enterprise Security.
  • Familiarity with Git-based development workflows for Splunk apps and detection content.
  • Experience supporting security monitoring in large-scale SaaS, cloud, or production service environments.
  • Knowledge of MITRE ATT&CK, NIST SP 800-53, ISO/IEC 27001, COBIT, or similar control frameworks.
  • Experience with detection-as-code practices, automated validation, or CI/CD pipelines for Splunk content.
  • Splunk certifications are a plus.
  • We work as a team, collaborating with empathy to make really big things happen on a global scale.
  • Because our solutions are everywhere, our impact is everywhere.

Compensation

  • The starting salary range posted for this position is $137,000.00 to $200,500.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benef

Benefits

  • Please see the Cisco careers site to discover more benefits and perks.
  • Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.
  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
  • 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
  • Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees
  • Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next
  • Collaborate with platform and service engineering teams to define and improve security logging requirements, and support detection coverage mapping against MITRE ATT&CK and relevant compliance frameworks.
  • Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.

Company info

  • We are seeking a Security Incident Detection Engineer with deep Splunk and Splunk Enterprise Security experience to support detection engineering, incident visibility, and security monitoring across the Webex cloud service environment.

This listing is sourced directly from Cisco's careers page and normalized into a canonical job model.