Cisco

Staff Threat Hunting & Intelligence Engineer

Cisco$160K — $203K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of professional cybersecurity experience in cyber threat intelligence and/or threat hunting
  • Proficient in Splunk and capable of building and interpreting SPL
  • Ability to analyze large datasets for actionable insights
  • Strong understanding of attacker behavior and automation of threat intelligence capabilities
  • Experience applying AI for enhancing intelligence development and analysis

Responsibilities

  • Deliver actionable threat intelligence during active incidents
  • Produce regular and ad-hoc threat intelligence products
  • Plan and conduct a variety of threat hunts
  • Build and maintain scripts and automation for intelligence processes
  • Utilize AI to speed up intelligence analysis and tooling creation
  • Identify adversary activities missed by existing detection methods
  • Develop comprehensive written reports and presentations for various audiences
  • Mentor junior analysts and engineers in threat intelligence and hunting

Benefits

  • Opportunity to work in a hybrid role that combines threat intelligence, hunting, and engineering
  • Participation in an on-call rotation for incident response
  • Engagement with a diverse and skilled team across security operations
  • Access to advanced tools and environments to develop impactful security strategies
  • Encouragement of learning and professional growth through mentorship opportunities
Full Job Description
The application window is expected to close on: 10/26/2026
Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.

The successful applicant will be performing work on US Government classified environments, and therefore, must be a U.S. Person (i.e., U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.

Meet the Team

This role reports to the Senior Manager, Threat Hunting and Intelligence in our Global Security Operations organization. As a member of THI, you will work with our multi-functional peer teams: Detection Engineering, SOC, Advanced Response, and others, to ensure that Splunk is always prepared for emergent threats. This is a true hybrid role. You will move fluidly between producing tactical threat intelligence, leading threat hunts, and building the automation that supports both.
Your Impact:

This role brings together threat intelligence, threat hunting, and engineering. You will track the sophisticated adversaries Splunk may face, deliver timely intelligence that supports incident response, hunt for adversary activity across very large datasets, and build the automation and tooling that turns intelligence and hunt findings into repeatable, scalable capabilities. You are self-motivated and passionate about tracking threat actors, love the rush of uncovering previously unknown activity, and have the development chops to automate and improve the mission. This role participates in an on-call rotation, and the nature of the work may include afterhours support during major incidents. We are a hard-working team who has fun, enjoys a good laugh, but above all else thinks security first.

  • Deliver actionable threat intelligence during active incidents, including timely indicators, TTPs, behavioral patterns, and threat actor context
  • Produce cadenced and ad-hoc intelligence products that inform hunts, detections, and business decisions
  • Plan and conduct threat hunts, including retrospective, project-based, and an ad-hoc hunt library other teams can use daily
  • Build and maintain scripts, API integrations, and automation that scale THI's intelligence and hunting use cases, improving threat-data ingestion, processing, and enrichment while reducing cycle time
  • Apply AI to accelerate intelligence analysis, hunting, and tooling development
  • Uncover adversary activity missed by current detection rules and hand findings to Detection Engineering to close the gap
  • Craft compelling written products, presentations, and RFI responses that give decision advantage to technical and non-technical audiences
  • Mentor analysts and engineers growing across threat intelligence, hunting, and engineering
Minimum Qualifications:
  • 8+ years of professional cybersecurity experience, with demonstrable time across cyber threat intelligence and/or threat hunting
  • Experience with sophisticated searching and reporting in Splunk, and the ability to build and interpret SPL fluidly
  • Experience translating large datasets into meaningful information, with the relentless focus to continue a hunt when there are no easy wins
  • Understanding of attacker behavior and the ability to translate intelligence and hunt findings into repeatable, automated capabilities
  • Experience applying AI to accelerate development and analysis
Preferred Qualifications:
  • Experience leading threat actor and campaign attribution
  • Strong programming proficiency in one or more languages to build scripts and API automation for threat-data ingestion and processing
  • Experience delivering tactical threat intelligence in support of incident response
  • Hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling
  • Willingness to participate in an on-call rotation, including afterhours support during major incidents
  • Expertise in uncovering adversary activity missed by industry detection rules
  • Experience with network and host-based logs, and a solid understanding of common services (DNS, DHCP, email, proxy, VPN, firewall, etc.)
  • Proficiency in cloud technologies (AWS, GCP, or Azure) and a robust understanding of Linux

About Cisco

Cisco Careers

Join the vibrant team at Cisco, a global leader in networking and cybersecurity solutions, where innovation and leadership thrive. Cisco offers a plethora of job opportunities that cater to a range of skills and experiences, making it an ideal place for both seasoned professionals and those seeking an internship to jumpstart their career. Work You’ll Do At Cisco, you’ll be part of a culture that values diversity, leadership, and professional growth. Engage in work that matters with a team that combines technology, creativity, and the power of human connection to redefine networking. Cisco’s commitment to innovation isn’t just about technology, but also about transforming the way we work and collaborate. Cisco’s employment philosophy supports career advancement and nurtures a leadership pipeline that is equipped with diversity training and opportunities for growth. Whether you’re applying your skills to drive our latest innovations or using our vast networking capabilities to solve complex problems, at Cisco, every role is impactful. Join Our Dynamic Team Explore job opportunities in areas ranging from engineering to marketing, sales to cybersecurity. Cisco is hiring individuals who are passionate, curious, and ready to drive change. Positions at Cisco offer competitive benefits, a supportive culture, and the chance to work with cutting-edge technology. Internship Programs Kickstart your career with a Cisco internship. Gain invaluable industry experience, enhance your resume, and build professional networks that last a lifetime. Our internships provide hands-on experience and the chance to work on projects that matter. Leadership and Development Cisco is committed to fostering leadership skills and providing employees with the training needed to succeed. Our leadership programs help you develop new skills, manage teams effectively, and lead with confidence. Cisco’s commitment to professional development ensures that your career path is as dynamic as our technologies. Benefits and Culture Cisco understands the importance of a balanced life. Our benefits package is designed to ensure that our team members are healthy, happy, and secure. At Cisco, you’ll find a supportive culture that encourages open communication, teamwork, and mutual respect. Stay Connected Join Cisco’s Talent Network Stay informed about new positions that match your skills and interests. At Cisco, we value the curiosity and unique perspectives of our team members. Subscribe to receive personalized job alerts and insider tips directly from our hiring managers. Explore Cisco Jobs Ready to advance your career at Cisco? Search open positions, prepare your resume, and get ready for an interview that could lead to your next big opportunity. At Cisco, we’re not just filling positions—we’re investing in leaders. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. READ CAREERS BLOG Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await you at Cisco.
Learn more about Cisco
Size
79,500 employees
Market Cap
$194.5 billion
Industry
Net Income
$10.1 billion
Founded
2014
5 Year Trend
+1.4%
Revenue
$48 billion
NASDAQ

Similar Jobs

More Jobs at Cisco

More Information Technology Jobs

Find similar Staff Threat Hunting & Intelligence Engineer jobs: