Jobs · Management · Georgia

Incident Response Analyst (Security Operations)

Cisco · Atlanta, GA · 1 mo ago
Management$102k–$136k/yrFull-time

The application window is expected to close on: 07/31/2026. Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.

About the role

Splunk's Threat Response SOC operates globally, 24/7, at the intersection of incident response, detection engineering, and automation. We protect Splunk's enterprise and product environments — and we're constantly building better ways to do it. Our team of analysts and engineers turns repetitive manual work into documented, version-controlled, AI-augmented workflows. We're builders and defenders. Come help us reinvent the modern SOC!

Responsibilities

  • Own the full arc of security incidents from first alert to documented resolution.
  • Combine hands-on security operations with AI-enabled investigation workflows and human-supervised agentic tooling to reduce analyst toil.
  • Triage, investigate, and respond to security alerts across Splunk's enterprise and product environments.
  • Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
  • Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
  • Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
  • Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight at every step.
  • Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.

Requirements

  • Bachelor's Degree and 4+ years' of experience in security operations, incident response, or related technical role.
  • Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
  • Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
  • Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
  • Experience with automation scripts, and make updates to playbooks, pipeline configurations, or modular tooling.
  • Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
  • Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.

Preferred Qualifications

  • Strong written and verbal communication skills, including the ability to document investigations, write clear runbooks, and explain technical findings.
  • Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
  • Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
  • Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management, or software supply chain security concepts.
  • Scripting or automation experience in Python, Bash, Go, or JavaScript.

Benefits

U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks.

Pay

The starting salary range posted for this position is $102,300.00 to $135,900.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.

Schedule

On call rotation 1 week every 2 months from 11:00pm – 8:00am eastern standard time.

Similar jobs

Incident Response Analyst

Peterson Technology PartnersArlington Heights, PA· 2 wk ago
Manufacturing$45–$60/hrapply on ptechpartners.com