Senior Security Engineer
About the role
The application window is expected to close on: 10/21/2026. The job posting may be removed earlier if the position is filled or if a sufficient number of applications are received. This is a hybrid role at the RTP, NC office.
Meet the Team
We are the CCPS IDR (Intrusion Detection & Response) team. A security engineering group within Cisco's Webex & Collaboration Cloud Platform Security organization. Our mission is to ensure every meaningful security event across the Webex platform is captured, normalized, and delivered to the right hands before it becomes a problem. Our work sits at the intersection of platform engineering and security operations. We own the log ingestion, parsing, and data fidelity pipelines and operational detection effectiveness that power Webex's enterprise SIEM, directly supporting FedRAMP compliance, SOC effectiveness, and executive risk reporting. We are a lean team engineers and a delivery manager. If you care about security engineering that has real, measurable impact at scale and building the foundational observability layer for one of Cisco's largest cloud platforms, this is the team to be on.
Your Impact
We are seeking a Security Incident Detection Engineer with deep Splunk and Splunk Enterprise Security experience to support detection engineering, incident visibility, and security monitoring across the Webex cloud service environment. This role will focus on developing, maintaining, and improving Splunk knowledge objects, detection content, validation dashboards, and operational standards that enable reliable security incident detection and response. The engineer will work closely with security operations, cloud security, platform engineering, and service teams to ensure security telemetry is properly ingested, normalized, validated, and actionable.
Responsibilities
- Build and maintain Splunk Enterprise Security correlation searches, notable events, risk-based alerts, and detection content that directly power security incident visibility across the Webex cloud environment.
- Develop detection build out and maintain validation dashboards aligned to telemetry ingestion contracts, ensuring required security events are present, accurate, timely, and CIM-compliant.
- Validate data onboarding quality across cloud services covering source types, indexes, field normalization, timestamp accuracy, and parsing consistency.
- Partner with SOC and incident response teams to improve alert fidelity, reduce false positives, and ensure detections provide clear investigative context.
- Collaborate with platform and service engineering teams to define and improve security logging requirements, and support detection coverage mapping against MITRE ATT&CK and relevant compliance frameworks.
Qualifications
- Bachelor’s degree plus 7 years of related experience, or Master’s degree plus 4 years of related experience
- Hands-on experience operating Splunk Enterprise and Splunk Enterprise Security at scale, including deep knowledge of full ES feature enablement for SOC/SIEM use cases
- Advanced SPL development skills, including efficient search design, macros, lookups, stats/tstats, data models, accelerated searches, and dashboard queries
- Experience developing and maintaining Splunk knowledge objects in a managed app or source-controlled environment
- Understanding of Splunk CIM, data normalization, field extractions, props/transforms, event types, tags, and source type design
- Experience building, tuning, and maintaining ES correlation searches and notable event workflows
- Familiarity with cloud security logging, incident detection, threat detection logic, and SOC operations
- Experienced in documentation, architecture review, and cross-functional collaboration skills
Preferred Qualifications
- Experience with risk-based alerting in Splunk Enterprise Security
- Familiarity with Git-based development workflows for Splunk apps and detection content
- Experience supporting security monitoring in large-scale SaaS, cloud, or production service environments
- Knowledge of MITRE ATT&CK, NIST SP 800-53, ISO/IEC 27001, COBIT, or similar control frameworks
- Experience with detection-as-code practices, automated validation, or CI/CD pipelines for Splunk content
- Splunk certifications are a plus
Pay
The starting salary range posted for this position is $137,000.00 to $200,500.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.
Schedule
This is a hybrid role at the RTP, NC office.