Incident Response Analyst
24×7 Global Operations shift: 10:00 AM – 8:00 PM Pacific Time, Wednesday – Saturday. On-call rotation: one week every two months from 11:00 PM – 8:00 AM Eastern Time.
About the role
Splunk’s Threat Response SOC operates globally, 24/7, at the intersection of incident response, detection engineering, and automation. We protect Splunk’s enterprise and product environments and constantly build better ways to do it. Our team of analysts and engineers turns repetitive manual work into documented, version-controlled, AI-augmented workflows. We’re builders and defenders.
Responsibilities
- Own the full arc of security incidents from first alert to documented resolution.
- Triage, investigate, and respond to security alerts across Splunk’s enterprise and product environments.
- Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
- Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
- Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
- Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight at every step.
- Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.
Requirements
- Bachelor’s Degree and 4+ years of experience in security operations, incident response, or related technical role.
- Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
- Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
- Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
- Experience with automation scripts and updating playbooks, pipeline configurations, or modular tooling.
- Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
- Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.
- Must be a U.S. Person (U.S. citizen) to maintain services in a FedRAMP-compliant environment.
Preferred Qualifications
- Strong written and verbal communication skills, including documenting investigations, writing clear runbooks, and explaining technical findings.
- Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
- Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
- Experience with GitLab CI/CD or similar pipeline systems, including pipeline configuration, automated testing, validation, deployment workflows, or approval gates.
- Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management, or software supply chain security concepts.
- Scripting or automation experience in Python, Bash, Go, or JavaScript.
Pay
The starting salary range for this position is $104,000 – $138,100 USD, with the following location-based adjustments:
- New York City Metro Area: $130,600 – $191,200
- Non-Metro New York State & Washington State: $116,600 – $170,100
For sales roles, the ranges include base pay and sales target incentive compensation combined.
Benefits
- Medical, dental, and vision insurance
- 401(k) plan with Cisco matching contribution
- Paid parental leave
- Short- and long-term disability coverage
- Basic life insurance
- 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
- 1 paid day off for employee’s birthday
- Paid year-end holiday shutdown
- 4 paid days off for personal wellness
- Non-exempt employees: 16 days of paid vacation time per full calendar year, accrued at 4.92 hours per pay period
- Exempt employees: Flexible vacation time off with no defined limit (subject to business limitations)
- 80 hours of sick time off provided on hire date and each January 1st thereafter, with up to 80 hours carried forward annually
- Additional paid time away for critical or emergency family issues
- Optional 10 paid days per full calendar year to volunteer
- Eligibility for annual bonuses (non-sales roles) or performance-based incentive pay (sales roles)
- Eligibility for grants of Cisco restricted stock units, vesting over time with continued employment
Schedule
- Shift: 10:00 AM – 8:00 PM Pacific Time, Wednesday – Saturday
- On-call rotation: one week every two months from 11:00 PM – 8:00 AM Eastern Time