Threat Hunting Investigator
Application window closes on: 09/15/2026
About the Role
Join a highly niche security unit dedicated to proactive defense and high‑stakes investigation within a secure, onsite environment. The team serves as a critical shield for the organization, executing sophisticated hunt campaigns that stay ahead of evolving adversary tradecraft. The culture emphasizes technical difficulty, collaboration, mentorship, and continuous improvement in detection and forensics capabilities.
Your Impact
- Build and execute hypothesis‑driven hunt campaigns based on adversary tradecraft to identify and neutralize hidden threats.
- Develop durable detection logic in Splunk and map coverage against the MITRE ATT&CK framework to ensure detailed security visibility.
- Perform end‑to‑end host and network forensics to determine root causes and drive effective incident containment and eradication.
- Brief technical findings to engineering peers and leadership, translating sophisticated investigation data into actionable organizational insights.
- Mentor junior analysts and develop robust playbooks to improve the collective maturity and readiness of the security team.
Minimum Qualifications
- Active TS/SCI clearance, in scope, at time of hire.
- 4+ years of combined experience in threat hunting, incident response, detection engineering, or Tier 2+ SOC analysis.
- Proficiency querying and building content in an enterprise SIEM, specifically Splunk (SPL).
- Practical knowledge of Windows and Linux internals, TCP/IP, and common application‑layer protocols.
- Scripting proficiency in Python, PowerShell, or Bash for enrichment and automation.
Preferred Qualifications
- Experience with network forensics and traffic analysis using tools like Zeek, Wireshark, or NetFlow.
- Proficiency in detection‑as‑code practices, including version control, peer review, and unit‑tested logic.
- Prior experience in DoD, Intelligence Community (IC), or federal SOC environments.
- Relevant security certifications such as GCFA, GCIA, GCTI, GDAT, GNFA, GREM, or OSCP.
- Ability to produce meticulous investigation records and brief findings to compliance and non‑technical collaborators.
Why Cisco?
Cisco is revolutionizing how data and infrastructure connect and protect organizations in the AI era and beyond. With 40 years of innovation, Cisco delivers solutions that provide unparalleled security, visibility, and insights across the entire digital footprint. Employees collaborate with empathy, creating meaningful solutions that have global impact.
Pay
Starting salary range: $130,500 – $175,000 (U.S. and/or Canada locations, excluding incentive compensation, equity, or benefits). Specific ranges include:
- New York City Metro Area: $161,400 – $241,100
- Non‑Metro New York State & Washington State: $141,500 – $214,400
Benefits
- Medical, dental, and vision insurance.
- 401(k) plan with Cisco matching contribution.
- Paid parental leave.
- Short‑ and long‑term disability coverage.
- Basic life insurance.
- Eligibility for Cisco restricted stock unit grants.
- Paid time off: 10 holidays + 1 floating holiday, birthday day off, year‑end shutdown, 4 wellness days, 16 vacation days for non‑exempt employees (accrued at 4.92 hours per pay period), flexible vacation for exempt employees, 80 hours of sick time on hire and each January 1, with carry‑forward.
- Optional 10 paid volunteer days per year.
- Eligibility for annual bonuses (non‑sales roles) and performance‑based incentive pay (sales roles).