Incident Response Analyst (Security Operations)
Application window closes on July 31, 2026, or earlier if the position is filled.
Schedule
- 24x7 Global Operations Shift: 10:00 AM – 8:00 PM Pacific Time, Sunday – Wednesday
- On-call rotation: 1 week every 2 months from 11:00 PM – 8:00 AM Eastern Standard Time
About the Team
Splunk's Threat Response SOC operates globally, 24/7, at the intersection of incident response, detection engineering, and automation. We protect Splunk's enterprise and product environments — and we're constantly building better ways to do it. Our team of analysts and engineers turns repetitive manual work into documented, version-controlled, AI-augmented workflows. We're builders and defenders.
Responsibilities
- Own the full arc of security incidents from first alert to documented resolution. This role combines hands-on security operations with AI-enabled investigation workflows and human-supervised agentic tooling to reduce analyst toil.
- Triage, investigate, and respond to security alerts across Splunk's enterprise and product environments.
- Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
- Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
- Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
- Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight at every step.
- Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.
Requirements
- Bachelor's Degree and 4+ years of experience in security operations, incident response, or related technical role.
- Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
- Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
- Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
- Experience with automation scripts, and make updates to playbooks, pipeline configurations, or modular tooling.
- Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
- Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.
- Must be a U.S. Person (U.S. citizen) to maintain services in a FedRAMP-compliant environment. This position may perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.
Preferred Qualifications
- Strong written and verbal communication skills, including the ability to document investigations, write clear runbooks, and explain technical findings.
- Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
- Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
- Experience with GitLab CI/CD or similar pipeline systems, including pipeline configuration, automated testing, validation, deployment workflows, or approval gates.
- Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management, or software supply chain security concepts.
- Scripting or automation experience in Python, Bash, Go, or JavaScript.
Pay
The starting salary range for this position is $102,300.00 to $135,900.00 for new hires in U.S. and/or Canada locations, not including incentive compensation, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.
Full salary ranges for specific locations:
- New York City Metro Area: $128,500.00 - $188,200.00
- Non-Metro New York State & Washington State: $114,700.00 - $169,000.00
Benefits
- Medical, dental, and vision insurance
- 401(k) plan with Cisco matching contribution
- Paid parental leave
- Short and long-term disability coverage
- Basic life insurance
- 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
- 1 paid day off for employee’s birthday
- Paid year-end holiday shutdown
- 4 paid days off for personal wellness
- Non-exempt employees receive 16 days of paid vacation time per full calendar year, accrued at a rate of 4.92 hours per pay period for full-time employees
- Exempt employees participate in Cisco’s flexible vacation time off program, with no defined limit on vacation time (subject to availability and business limitations)
- 80 hours of sick time off provided on hire date and each January 1st thereafter, with up to 80 hours of unused sick time carried forward
- Additional paid time away may be requested to deal with critical or emergency issues for family members
- Optional 10 paid days per full calendar year to volunteer
- Eligibility for annual bonuses (subject to Cisco’s policies)
- Eligibility to earn performance-based incentive pay for sales roles, split between quota and non-quota components
- Eligibility to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods