Customer Delivery Architect | 10+ years, SOC transformation

123 Cisco Systems (India) Private Limited

Pune District

On-site

INR 4,000,000 - 7,000,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cisco is seeking a Security Consulting Architect to lead SOC transformation and Splunk deployments for enterprise customers in India. You will design target operating models, guide multi-tier SOCs, and mentor engineering pods while delivering scalable security architectures.

Responsibilities span Splunk Cloud, ES, UEBA, Cribl Stream, and MinIO storage, with a focus on risk-based alerting and automation using Splunk SOAR.

Qualifications

  • 10+ years of technical cybersecurity engineering and architecture experience designing and deploying enterprise Security Operations Center (SOC) environments and SIEM/SOAR platforms.
  • 5+ years of dedicated, hands-on architecture and engineering experience with Splunk Enterprise, Splunk Cloud, and Splunk Enterprise Security (ES), including correlation search engineering, Data Model Acceleration, and Risk-Based Alerting (RBA).
  • 3+ years of hands-on experience in security telemetry pipeline engineering, including log routing and normalization with Cribl Stream, data parsing (props.conf / transforms.conf), and object storage/SmartStore tiering with MinIO or S3-compatible cloud storage.
  • 3+ years of security orchestration and automation experience designing and building automated response playbooks using Splunk SOAR (Phantom), REST APIs, and Python.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical industry engineering experience.

Responsibilities

  • Lead architectural design for multi-tier enterprise SOCs and SIEM modernizations.
  • Define Target Operating Model (TOM) and delivery strategy aligned with MITRE ATT&CK and Cisco Validated Designs.
  • Architect enterprise-scale Splunk Cloud deployments; design Risk-Based Alerting (RBA) frameworks, Data Model Acceleration (DMA) strategies, optimized tstats pipelines, and UEBA enrichment.
  • Architect high-throughput telemetry pipelines using Cribl Stream and MinIO/ S3 storage for SmartStore and archival needs.
  • Define incident triage and response workflows; design modular Python playbooks in Splunk SOAR for automated threat enrichment and containment; synchronize with ServiceNow.
  • Provide technical direction and governance to engineering pods; mentor staff and resolve complex SPL optimization and API integrations.

Skills

Security architecture
Splunk design
Threat analytics
Python scripting
Leadership

Education

Bachelor’s degree in Computer Science / Cybersecurity / IT

Tools

Splunk Enterprise
Splunk Cloud
Splunk Enterprise Security
Cribl Stream
MinIO / S3 storage
ServiceNow
REST APIs

Job description

Meet the Team

Cisco Customer Experience (CX) Security Services is a global team of elite security practitioners, architects, and trusted advisors who help our largest enterprise and service provider customers defend against sophisticated threats, achieve operational cyber resilience, and accelerate digital transformation.

Your Impact

As a Security Consulting Architect for SOC Transformation & Splunk, you will be the chief technical authority and visionary guiding our enterprise customers through complex SOC modernization journeys. You will translate customer business outcomes, risk profiles, and operational strategies into scalable, high-fidelity security architectures powered by Splunk Cloud, Splunk Enterprise Security (ES), Splunk SOAR, User & Entity Behavior Analytics (UEBA), Cribl Stream, and modern object storage (MinIO). This is a high-impact, hands-on leadership role. You will engage with customer CISOs, SOC Directors, and Enterprise Architects to define target operating models and modernization roadmaps, while also leading implementation pods, troubleshooting deep technical roadblocks, optimizing search pipelines, and setting the engineering standards for multi-terabyte security analytics.

Target SOC Architecture & Transformation Strategy

Lead the architectural design, Target Operating Model (TOM), and delivery strategy for multi-tier enterprise SOCs, SIEM modernizations, and security automation frameworks aligned with MITRE ATT&CK and Cisco Validated Designs.

Splunk Cloud & Enterprise Security (ES) Mastery

Architect enterprise-scale Splunk Cloud deployments; design Risk-Based Alerting (RBA) frameworks, Data Model Acceleration (DMA) strategies, optimized tstats search pipelines, Asset & Identity (A&I) contextual enrichment, and ESCU detection updates to eliminate alert fatigue.

Modern Telemetry Ingestion & Storage Architecture

Architect high-throughput, resilient security data collection pipelines leveraging Cribl Stream for edge transformation, filtering, and routing, combined with MinIO / S3-compatible object storage for high-performance SmartStore tiering and compliance data archiving.

Security Automation & SOAR Engineering

Define incident triage and response workflows, designing modular, production-grade Python playbooks in Splunk SOAR for automated threat enrichment (Talos, VirusTotal), endpoint containment (EDR isolation), firewall mitigation, and bidirectional ITSM (ServiceNow) synchronization.

Technical Pod Leadership & Governance

Provide technical direction, architectural governance, and mentorship to specialized engineering execution pods (Data Ingestion/GDI, Detection Engineering, UEBA, SOAR); serve as the hands-on escalation authority for complex SPL optimization, CIM normalization, and API integrations.

Minimum Qualifications
  • 10+ years of technical cybersecurity engineering and architecture experience designing and deploying enterprise Security Operations Center (SOC) environments and SIEM/SOAR platforms.
  • 5+ years of dedicated, hands-on architecture and engineering experience with Splunk Enterprise, Splunk Cloud, and Splunk Enterprise Security (ES), including correlation search engineering, Data Model Acceleration, and Risk-Based Alerting (RBA).
  • 3+ years of hands-on experience in security telemetry pipeline engineering, including log routing and normalization with Cribl Stream, data parsing (props.conf / transforms.conf), and object storage/SmartStore tiering with MinIO or S3-compatible cloud storage.
  • 3+ years of security orchestration and automation experience designing and building automated response playbooks using Splunk SOAR (Phantom), REST APIs, and Python.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical industry engineering experience.
Preferred Qualifications
  • Splunk & Pipeline Certifications: Splunk Enterprise Certified Architect, Splunk Enterprise Security Certified Admin, Splunk SOAR Certified Automation Developer, or Cribl Certified Observability Engineer (CCOE).
  • Industry Security Credentials: CISSP, CCIE Security, CISM, or GIAC certifications (GCIH, GCIA, GDSA, GMON).
  • Advanced Behavioral Analytics & Threat Modeling: Practical experience deploying Splunk UEBA, implementing machine learning models for anomaly detection, and conducting atomic detection testing against the MITRE ATT&CK matrix.
  • Executive Advisory & Technical Consulting: Exceptional C-suite consulting, presentation, and technical leadership skills with a proven track record of advising CISOs, leading technical workshops, and driving organizational change.
  • Hybrid Cloud & Multi-Vendor Ecosystem Integration: Deep knowledge of multi-cloud security logging, Next-Gen Firewalls (Palo Alto, Cisco Secure Firewall), EDR platforms (CrowdStrike, Microsoft Defender), and Cisco Security Cloud integrations.
Why Cisco?

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you.

Cisconians power the future. We make impact as a team, innovating fast and fearlessly to create meaningful solutions on a large scale. The depth and breadth of our technology doesn't just benefit our customers – it also means limitless opportunities for us to experiment and learn. We understand the power each of our unique backgrounds bring when we work together. Because of that, we have a global network of thinkers, doers, experts, and curious creators who help one another do their life’s best work.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Customer Delivery Architect | 10+ years, SOC transformation
Customer Delivery Architect | 10+ years, SOC transformation

Cisco Systems, Inc. • Pune District

On-site
INR 2,500,000 - 3,500,000
Siftware Engineering Technical Leader - SRE | Security Architect, Kubernetes,AWS,Terraform | 13+ years | Bangalore
Siftware Engineering Technical Leader - SRE | Security Architect, Kubernetes,AWS,Terraform | 13+ years | Bangalore

123 Cisco Systems (India) Private Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Consulting Engineer - Security
Consulting Engineer - Security

Cisco • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Security Consulting Engineer
Security Consulting Engineer

Cisco • Bengaluru

On-site
INR 2,600,000 - 4,200,000
Software Engineer – Golang | Kubernetes | Distributed Systems | Cloud | Splunk Enterprise Security (4- 8 Years)
Software Engineer – Golang | Kubernetes | Distributed Systems | Cloud | Splunk Enterprise Security (4- 8 Years)

123 Cisco Systems (India) Private Limited • Bengaluru

On-site
INR 900,000 - 1,500,000
Senior Software Engineer – Golang | Kubernetes | Cloud | Distributed Systems | Splunk Enterprise Security (8 - 12 Years)
Senior Software Engineer – Golang | Kubernetes | Cloud | Distributed Systems | Splunk Enterprise Security (8 - 12 Years)

123 Cisco Systems (India) Private Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Consulting Engineer - Security
Consulting Engineer - Security

Cisco • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Consulting Engineer - Security
Consulting Engineer - Security

Cisco • Maharashtra

On-site
INR 4,000,000 - 7,000,000
Software EngineerSoftware Engineer, Data & Scalability Platform
Software EngineerSoftware Engineer, Data & Scalability Platform

123 Cisco Systems (India) Private Limited • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Security Consulting Engineer
Security Consulting Engineer

Cisco Systems, Inc. • Bengaluru

On-site
INR 3,000,000 - 4,200,000