Customer Delivery Architect | 10+ years, SOC transformation

Cisco

Maharashtra

On-site

INR 350,000 - 750,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cisco is seeking a Security Consulting Architect to lead SOC modernization for large enterprise clients. You will design multi-tier SOC architectures, optimize Splunk Cloud/ES deployments, and architect high-throughput telemetry pipelines using Cribl and MinIO.

You will craft automation playbooks in Splunk SOAR and guide engineering pods through complex integration challenges. You will collaborate with CISOs, SOC Directors, and Enterprise Architects to define TOMs and roadmaps, while mentoring

Qualifications

  • 10+ years of technical cybersecurity engineering and architecture experience designing and deploying enterprise SOC environments and SIEM/SOAR platforms.
  • 5+ years of hands-on architecture with Splunk Enterprise, Splunk Cloud, and Splunk ES, including correlation search engineering, DMA, and Risk-Based Alerting.
  • 3+ years of security telemetry pipeline engineering with Cribl Stream, log routing/normalization, and object storage/SmartStore tiering with MinIO or S3-compatible storage.
  • 3+ years of security orchestration and automation with Splunk SOAR (Phantom), REST APIs, and Python.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical industry experience.

Responsibilities

  • Lead architectural design and TOM for multi-tier enterprise SOCs and SIEM/SOAR modernization.
  • Architect Splunk Cloud deployments with ROI-driven data enrichment, DMA, and alerting optimizations.
  • Design high-throughput telemetry pipelines using Cribl Stream and MinIO/S3 storage for compliant data archiving.
  • Define incident triage workflows and production-grade playbooks in Splunk SOAR with automation.
  • Provide governance and mentorship to engineering pods; own complex SPL optimization and API integrations.

Skills

SOC architecture
Splunk ES
Splunk Cloud
Python scripting
Threat modeling

Education

Bachelor’s degree in CS or related

Tools

Splunk Enterprise
Splunk Cloud
Cribl Stream
MinIO/S3 storage
ServiceNow

Job description

Meet the Team

Cisco Customer Experience (CX) Security Services is a global team of elite security practitioners, architects, and trusted advisors who help our largest enterprise and service provider customers defend against sophisticated threats, achieve operational cyber resilience, and accelerate digital transformation. As part of our specialized Security Operations Center (SOC) Transformation & Advanced Analytics practice, you will work alongside top-tier consulting engineers, automation developers, and solution architects to design and deliver next-generation SOC architectures, SIEM modernization, behavioral analytics, and end-to-end security automation.

Your Impact

As a Security Consulting Architect for SOC Transformation & Splunk, you will be the chief technical authority and visionary guiding our enterprise customers through complex SOC modernization journeys. You will translate customer business outcomes, risk profiles, and operational strategies into scalable, high-fidelity security architectures powered by Splunk Cloud, Splunk Enterprise Security (ES), Splunk SOAR, User & Entity Behavior Analytics (UEBA), Cribl Stream, and modern object storage (MinIO). This is a high-impact, hands-on leadership role. You will engage with customer CISOs, SOC Directors, and Enterprise Architects to define target operating models and modernization roadmaps, while also leading implementation pods, troubleshooting deep technical roadblocks, optimizing search pipelines, and setting the engineering standards for multi-terabyte security analytics.

  • Target SOC Architecture & Transformation Strategy: Lead the architectural design, Target Operating Model (TOM), and delivery strategy for multi-tier enterprise SOCs, SIEM modernizations, and security automation frameworks aligned with MITRE ATT&CK and Cisco Validated Designs.
  • Splunk Cloud & Enterprise Security (ES) Mastery: Architect enterprise-scale Splunk Cloud deployments; design Risk-Based Alerting (RBA) frameworks, Data Model Acceleration (DMA) strategies, optimized tstats search pipelines, Asset & Identity (A&I) contextual enrichment, and ESCU detection updates to eliminate alert fatigue.
  • Modern Telemetry Ingestion & Storage Architecture: Architect high-throughput, resilient security data collection pipelines leveraging Cribl Stream for edge transformation, filtering, and routing, combined with MinIO / S3-compatible object storage for high-performance SmartStore tiering and compliance data archiving.
  • Security Automation & SOAR Engineering: Define incident triage and response workflows, designing modular, production-grade Python playbooks in Splunk SOAR for automated threat enrichment (Talos, VirusTotal), endpoint containment (EDR isolation), firewall mitigation, and bidirectional ITSM (ServiceNow) synchronization.
  • Technical Pod Leadership & Governance: Provide technical direction, architectural governance, and mentorship to specialized engineering execution pods (Data Ingestion/GDI, Detection Engineering, UEBA, SOAR); serve as the hands‑on escalation authority for complex SPL optimization, CIM normalization, and API integrations.
Minimum Qualifications
  • 10+ years of technical cybersecurity engineering and architecture experience designing and deploying enterprise Security Operations Center (SOC) environments and SIEM/SOAR platforms.
  • 5+ years of dedicated, hands‑on architecture and engineering experience with Splunk Enterprise, Splunk Cloud, and Splunk Enterprise Security (ES), including correlation search engineering, Data Model Acceleration, and Risk-Based Alerting (RBA).
  • 3+ years of hands‑on experience in security telemetry pipeline engineering, including log routing and normalization with Cribl Stream, data parsing (props.conf / transforms.conf), and object storage/SmartStore tiering with MinIO or S3-compatible cloud storage.
  • 3+ years of security orchestration and automation experience designing and building automated response playbooks using Splunk SOAR (Phantom), REST APIs, and Python
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical industry engineering experience.
Preferred Qualifications
  • Splunk & Pipeline Certifications: Splunk Enterprise Certified Architect, Splunk Enterprise Security Certified Admin, Splunk SOAR Certified Automation Developer, or Cribl Certified Observability Engineer (CCOE).
  • Industry Security Credentials: CISSP, CCIE Security, CISM, or GIAC certifications (GCIH, GCIA, GDSA, GMON).
  • Advanced Behavioral Analytics & Threat Modeling: Practical experience deploying Splunk UEBA, implementing machine learning models for anomaly detection, and conducting atomic detection testing against the MITRE ATT&CK matrix.
  • Executive Advisory & Technical Consulting: Exceptional C-suite consulting, presentation, and technical leadership skills with a proven track record of advising CISOs, leading technical workshops, and driving organizational change.
  • Hybrid Cloud & Multi-Vendor Ecosystem Integration: Deep knowledge of multi-cloud security logging, Next-Gen Firewalls (Palo Alto, Cisco Secure Firewall), EDR platforms (CrowdStrike, Microsoft Defender), and Cisco Security Cloud integrations.
Why Cisco?

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.

We are Cisco, and our power starts with you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Customer Delivery Architect | 10+ years, SOC transformation
Customer Delivery Architect | 10+ years, SOC transformation

Cisco • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Customer Delivery Architect | 10+ years, SOC transformation
Customer Delivery Architect | 10+ years, SOC transformation

Cisco Systems, Inc. • Pune District

On-site
INR 2,500,000 - 3,500,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

Cisco Systems • Mumbai

On-site
INR 1,800,000 - 3,200,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

Cisco • Chennai District

On-site
INR 1,800,000 - 2,500,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

Cisco • New Delhi

On-site
INR 4,000,000 - 6,000,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

Cisco • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

Cisco • India

On-site
INR 2,500,000 - 4,500,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

Cisco Systems, Inc. • Mumbai

On-site
INR 1,800,000 - 3,000,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

123 Cisco Systems (India) Private Limited • Mumbai

Hybrid
INR 900,000 - 1,400,000
Consulting Engineer - Security
Consulting Engineer - Security

Cisco • Gurugram District

On-site
INR 2,500,000 - 4,000,000