Jobs · Management · Texas

Incident Response Analyst (Security Operations)

Cisco · Austin, TX · 1 mo ago
Management$102k–$136k/yrFull-time

Application window closes on July 31, 2026, or earlier if the position is filled.

Schedule

  • 24x7 Global Operations Shift: 10:00 AM – 8:00 PM Pacific Time, Sunday – Wednesday
  • On-call rotation: 1 week every 2 months from 11:00 PM – 8:00 AM Eastern Standard Time

About the Team

Splunk's Threat Response SOC operates globally, 24/7, at the intersection of incident response, detection engineering, and automation. We protect Splunk's enterprise and product environments — and we're constantly building better ways to do it. Our team of analysts and engineers turns repetitive manual work into documented, version-controlled, AI-augmented workflows. We're builders and defenders.

Responsibilities

  • Own the full arc of security incidents from first alert to documented resolution. This role combines hands-on security operations with AI-enabled investigation workflows and human-supervised agentic tooling to reduce analyst toil.
  • Triage, investigate, and respond to security alerts across Splunk's enterprise and product environments.
  • Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
  • Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
  • Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
  • Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight at every step.
  • Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.

Requirements

  • Bachelor's Degree and 4+ years of experience in security operations, incident response, or related technical role.
  • Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
  • Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
  • Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
  • Experience with automation scripts, and make updates to playbooks, pipeline configurations, or modular tooling.
  • Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
  • Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.
  • Must be a U.S. Person (U.S. citizen) to maintain services in a FedRAMP-compliant environment. This position may perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.

Preferred Qualifications

  • Strong written and verbal communication skills, including the ability to document investigations, write clear runbooks, and explain technical findings.
  • Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
  • Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
  • Experience with GitLab CI/CD or similar pipeline systems, including pipeline configuration, automated testing, validation, deployment workflows, or approval gates.
  • Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management, or software supply chain security concepts.
  • Scripting or automation experience in Python, Bash, Go, or JavaScript.

Pay

The starting salary range for this position is $102,300.00 to $135,900.00 for new hires in U.S. and/or Canada locations, not including incentive compensation, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.

Full salary ranges for specific locations:

  • New York City Metro Area: $128,500.00 - $188,200.00
  • Non-Metro New York State & Washington State: $114,700.00 - $169,000.00

Benefits

  • Medical, dental, and vision insurance
  • 401(k) plan with Cisco matching contribution
  • Paid parental leave
  • Short and long-term disability coverage
  • Basic life insurance
  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • Paid year-end holiday shutdown
  • 4 paid days off for personal wellness
  • Non-exempt employees receive 16 days of paid vacation time per full calendar year, accrued at a rate of 4.92 hours per pay period for full-time employees
  • Exempt employees participate in Cisco’s flexible vacation time off program, with no defined limit on vacation time (subject to availability and business limitations)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter, with up to 80 hours of unused sick time carried forward
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • Eligibility for annual bonuses (subject to Cisco’s policies)
  • Eligibility to earn performance-based incentive pay for sales roles, split between quota and non-quota components
  • Eligibility to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods

Similar jobs

Incident Response Analyst

Peterson Technology PartnersArlington Heights, PA· 2 wk ago
Manufacturing$45–$60/hrapply on ptechpartners.com