Cisco

Incident Response Analyst (Security Operations)

Cisco$102K — $135K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree with 4+ years in security operations or incident response.
  • Knowledge of incident response, alert triage, and threat hunting.
  • Hands-on experience with SIEM, EDR, or cloud security tools.
  • Skilled in Git/GitLab workflows and CI/CD practices.
  • Experience automating scripts and updating security playbooks.
  • Familiarity with AI-assisted security tooling and operational methodologies.
  • Knowledge of MITRE ATT&CK framework and SOC performance metrics.

Responsibilities

  • Triage and respond to security alerts in enterprise environments.
  • Drive response actions through evidence collection and threat scoping.
  • Collaborate with Detection Engineering to refine detection capabilities.
  • Automate SOC processes to minimize repetitive tasks.
  • Apply AI tools to streamline investigations and analyst workflows.
  • Lead threat hunting and incident reviews to enhance SOC processes.

Benefits

  • Dynamic work environment promotes continuous learning and growth.
  • Opportunity to work with cutting-edge AI security technology.
  • Participation in a supportive, collaborative team culture.
  • Engagement in influencing the effectiveness of security practices.
  • Access to a wide range of professional development opportunities.
Full Job Description
The application window is expected to close on: 07/31/2026
Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.

24 x 7 Global Operations

Shift time: 10:00am - 8:00pm pacific time

Sunday - Wednesday

On call rotation 1 week every 2 months from 11:00pm - 8:00am eastern standard time

Your Impact

Own the full arc of security incidents from first alert to documented resolution. This role combines hands-on security operations with AI-enabled investigation workflows and human-supervised agentic tooling to reduce analyst toil. Success looks like faster incident response, less noise, and a SOC that gets sharper every sprint!
  • Triage, investigate, and respond to security alerts across Splunk's enterprise and product environments.
  • Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
  • Partner with Detection Engineering to tune detections, cut false positives, and close coverage gaps.
  • Build and maintain SOC automation to eliminate repetitive work including scripts, playbooks, and enrichment workflows.
  • Apply AI-assisted and agentic tooling to accelerate investigation, enrichment, summarization, and repeatable analyst workflows with human oversight at every step.
  • Hunt threats, lead incident reviews, and contribute to cross-team investigations that raise SOC-wide quality.

Minimum Qualifications
  • Bachelor's Degree and 4+ years' of experience in security operations, incident response, or related technical role.
  • Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
  • Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
  • Experience with Git/GitLab workflows: branching, merge requests, code review, and CI/CD.
  • Experience with automation scripts, and make updates to playbooks, pipeline configurations, or modular tooling.
  • Experience with AI-assisted development, AI-powered security tooling, or agentic workflows, and ability to critically evaluate tool output before taking action.
  • Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.

Preferred Qualifications
  • Strong written and verbal communication skills, including the ability to document investigations, write clear runbooks, and explain technical findings.
  • Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
  • Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
  • Experience with GitLab CI/CD or similar pipeline systems, including pipeline configuration, automated testing, validation, deployment workflows, or approval gates.
  • Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management, or software supply chain security concepts.
  • Scripting or automation experience in Python, Bash, Go, or JavaScript.


Note: As part of this role, you will be responsible for maintaining services in a FedRAMP-compliant environment and must be a U.S. Person (U.S. citizen). This position may perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.

About Cisco

Cisco Careers

Join the vibrant team at Cisco, a global leader in networking and cybersecurity solutions, where innovation and leadership thrive. Cisco offers a plethora of job opportunities that cater to a range of skills and experiences, making it an ideal place for both seasoned professionals and those seeking an internship to jumpstart their career. Work You’ll Do At Cisco, you’ll be part of a culture that values diversity, leadership, and professional growth. Engage in work that matters with a team that combines technology, creativity, and the power of human connection to redefine networking. Cisco’s commitment to innovation isn’t just about technology, but also about transforming the way we work and collaborate. Cisco’s employment philosophy supports career advancement and nurtures a leadership pipeline that is equipped with diversity training and opportunities for growth. Whether you’re applying your skills to drive our latest innovations or using our vast networking capabilities to solve complex problems, at Cisco, every role is impactful. Join Our Dynamic Team Explore job opportunities in areas ranging from engineering to marketing, sales to cybersecurity. Cisco is hiring individuals who are passionate, curious, and ready to drive change. Positions at Cisco offer competitive benefits, a supportive culture, and the chance to work with cutting-edge technology. Internship Programs Kickstart your career with a Cisco internship. Gain invaluable industry experience, enhance your resume, and build professional networks that last a lifetime. Our internships provide hands-on experience and the chance to work on projects that matter. Leadership and Development Cisco is committed to fostering leadership skills and providing employees with the training needed to succeed. Our leadership programs help you develop new skills, manage teams effectively, and lead with confidence. Cisco’s commitment to professional development ensures that your career path is as dynamic as our technologies. Benefits and Culture Cisco understands the importance of a balanced life. Our benefits package is designed to ensure that our team members are healthy, happy, and secure. At Cisco, you’ll find a supportive culture that encourages open communication, teamwork, and mutual respect. Stay Connected Join Cisco’s Talent Network Stay informed about new positions that match your skills and interests. At Cisco, we value the curiosity and unique perspectives of our team members. Subscribe to receive personalized job alerts and insider tips directly from our hiring managers. Explore Cisco Jobs Ready to advance your career at Cisco? Search open positions, prepare your resume, and get ready for an interview that could lead to your next big opportunity. At Cisco, we’re not just filling positions—we’re investing in leaders. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. READ CAREERS BLOG Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await you at Cisco.
Learn more about Cisco
Size
79,500 employees
Market Cap
$194.5 billion
Industry
Net Income
$10.1 billion
Founded
2014
5 Year Trend
+1.4%
Revenue
$48 billion
NASDAQ

Similar Jobs

More Jobs at Cisco

More Information Technology Jobs

Find similar Incident Response Analyst (Security Operations) jobs: