Cisco

Detection Engineering Technical Leader

Cisco$150K — $190K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 8 years experience, Master's with 6+ years, or PhD with 3+ years in related roles
  • Experience deploying Splunk Enterprise Security content in operational SOC environments
  • Proficiency in building detection queries in SPL across high-volume data
  • Ability to integrate AI/ML techniques into detection engineering for improved efficacy
  • Experience translating threat intelligence into actionable detection requirements

Responsibilities

  • Collaborate with cross-functional teams to enhance Splunk's security posture
  • Design and implement scalable detection systems and automation
  • Mentor team members on detection standards and best practices
  • Build data processing pipelines for security telemetry
  • Lead complex initiatives to improve detection capabilities across the organization

Benefits

  • Hybrid work model allowing for dynamic role engagement
  • Opportunity to work with cutting-edge AI/ML technologies in cybersecurity
  • Mentorship opportunities to grow within the team
  • Participation in complex, cross-org initiatives for holistic security improvements
  • Engagement with a team driven by engineering excellence and continuous learning
Full Job Description
The application window is expected to close on: 09/20/2026

The successful applicant will be performing work in FedRAMP High or IL-5 environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.

Meet the Team

This role works within Splunk's internal security organization as a member of the Detection Engineering team responsible for securing the Splunk portfolio. The role will partner fluidly with our multi-functional peer teams: Threat Hunting & Intelligence, SOC, Advanced Response, and others, to ensure that Splunk is always prepared for emergent threats. This is a true hybrid role. You will move dynamically between building new scalable detection content, collaborating with incident response organizations, mentoring teammates on detection standards and design patterns, as well designing the future of engineering threat detection solutions at Splunk.

Your Impact

You'll be joining a team of like-minded engineers focused on securing our enterprise and building for the future - together, we engineer scalable detection systems and automation that power 24x7 monitoring operations and rapid response to cybersecurity threats. We sit at the intersection of deep security expertise, strong engineering rigor, and data science: you'll design and build data processing pipelines that efficiently transform high-volume security telemetry into actionable alert signals for downstream agentic and human triage, and we lean hard into AI/ML to stay ahead of adversaries rather than chasing them.

Beyond the technical craft, we drive complex, cross-organizational initiatives with business partners to continuously expand visibility and close detection gaps - working across boundaries to make the whole security program better. We bring our experience to bear through code reviews and technical mentorship, helping elevate detection engineers and security content developers around us, and we hold ourselves to a standard where engineering excellence isn't aspirational...it's how we work.

Minimum Qualifications:

  • Bachelor's + 8 years of related experience or a Master's degree with 6+ years of related experience, or a PhD + 3 years of related experience as a Security Engineer, Detection Engineer, Security Content Developer, SOC Analyst, or Security Operations professional


  • Deployed and maintained Splunk Enterprise Security content in a production SOC environment, including detections, data models, and data management


  • Built detection queries in SPL at scale, including risk-based alerting, statistical baselining, and optimized searches across high-volume data sources


  • Integrated AI/ML techniques (e.g., anomaly detection, LLM-assisted workflows) into detection engineering pipelines to reduce false positive rates and accelerate content development


  • Translated threat intelligence and ATT&CK-mapped adversary behaviors into detection requirements with defined coverage metrics and measurable success criteria


Preferred Qualifications:

  • Contributed to collaborative development workflows using Git-based platforms (GitHub, GitLab, or Bitbucket), including branch strategy, code review, and CI/CD integration


  • Built or tuned security monitoring coverage across AWS, GCP, or Azure, including native logging services (e.g., CloudTrail, GCS audit logs, Azure Monitor) and cloud-native threat detection


  • Tracked and responded to emerging threats and attacker techniques through ongoing research, published work, conference participation, or contributions to detection content


  • Wrote production Python (or equivalent) with unit tests, code reviews, and version-controlled deployments in an operational security environment


  • Applied statistical methods or ML techniques (e.g., threshold baselining, clustering, anomaly scoring) to security data to improve detection signal quality


  • Identified and delivered automation that measurably reduced manual toil or cycle time in detection, triage, or response workflows


  • Produced technical documentation, runbooks, or presentations tailored to both engineering and non-technical security stakeholders


  • Partnered with SOC, IR, threat intel, and product teams to drive multi-functional detection initiatives from requirement to deployment

About Cisco

Cisco Careers

Join the vibrant team at Cisco, a global leader in networking and cybersecurity solutions, where innovation and leadership thrive. Cisco offers a plethora of job opportunities that cater to a range of skills and experiences, making it an ideal place for both seasoned professionals and those seeking an internship to jumpstart their career. Work You’ll Do At Cisco, you’ll be part of a culture that values diversity, leadership, and professional growth. Engage in work that matters with a team that combines technology, creativity, and the power of human connection to redefine networking. Cisco’s commitment to innovation isn’t just about technology, but also about transforming the way we work and collaborate. Cisco’s employment philosophy supports career advancement and nurtures a leadership pipeline that is equipped with diversity training and opportunities for growth. Whether you’re applying your skills to drive our latest innovations or using our vast networking capabilities to solve complex problems, at Cisco, every role is impactful. Join Our Dynamic Team Explore job opportunities in areas ranging from engineering to marketing, sales to cybersecurity. Cisco is hiring individuals who are passionate, curious, and ready to drive change. Positions at Cisco offer competitive benefits, a supportive culture, and the chance to work with cutting-edge technology. Internship Programs Kickstart your career with a Cisco internship. Gain invaluable industry experience, enhance your resume, and build professional networks that last a lifetime. Our internships provide hands-on experience and the chance to work on projects that matter. Leadership and Development Cisco is committed to fostering leadership skills and providing employees with the training needed to succeed. Our leadership programs help you develop new skills, manage teams effectively, and lead with confidence. Cisco’s commitment to professional development ensures that your career path is as dynamic as our technologies. Benefits and Culture Cisco understands the importance of a balanced life. Our benefits package is designed to ensure that our team members are healthy, happy, and secure. At Cisco, you’ll find a supportive culture that encourages open communication, teamwork, and mutual respect. Stay Connected Join Cisco’s Talent Network Stay informed about new positions that match your skills and interests. At Cisco, we value the curiosity and unique perspectives of our team members. Subscribe to receive personalized job alerts and insider tips directly from our hiring managers. Explore Cisco Jobs Ready to advance your career at Cisco? Search open positions, prepare your resume, and get ready for an interview that could lead to your next big opportunity. At Cisco, we’re not just filling positions—we’re investing in leaders. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. READ CAREERS BLOG Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await you at Cisco.
Learn more about Cisco
Size
79,500 employees
Market Cap
$194.5 billion
Industry
Net Income
$10.1 billion
Founded
2014
5 Year Trend
+1.4%
Revenue
$48 billion
NASDAQ

Similar Jobs

More Jobs at Cisco

More Information Technology Jobs

Find similar Detection Engineering Technical Leader jobs: