Incident Response Analyst (Security Operations)
The application window is expected to close on: 07/31/2026. Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.
About the role
Splunk's Threat Response SOC operates globally, 24/7, at the intersection of incident response, detection engineering, and automation. We protect Splunk's enterprise and product environments — and we're constantly building better ways to do it. Our team of analysts and engineers turns repetitive manual work into documented, version-controlled, AI-augmented workflows. We're builders and defenders. Come help us reinvent the modern SOC!
Responsibilities
- Own the full arc of security incidents from first alert to documented resolution.
- Combine hands-on security operations with AI-enabled investigation workflows and human-supervised agentic tooling to reduce analyst toil.
- Triage, investigate, and respond to security alerts across Splunk's enterprise and product environments.
- Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
- Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
- Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
- Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight at every step.
- Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.
Requirements
- Bachelor's Degree and 4+ years' of experience in security operations, incident response, or related technical role.
- Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
- Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
- Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
- Experience with automation scripts, and make updates to playbooks, pipeline configurations, or modular tooling.
- Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
- Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.
Preferred Qualifications
- Strong written and verbal communication skills, including the ability to document investigations, write clear runbooks, and explain technical findings.
- Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
- Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
- Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management, or software supply chain security concepts.
- Scripting or automation experience in Python, Bash, Go, or JavaScript.
Benefits
U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks.
Pay
The starting salary range posted for this position is $102,300.00 to $135,900.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.
Schedule
On call rotation 1 week every 2 months from 11:00pm – 8:00am eastern standard time.