Senior Threat Hunting & Intelligence Engineer

Jobtailor

California (MO)

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cisco is seeking an experienced threat intelligence and hunting leader to join the Global Security Operations team. You will translate intelligence into actionable hunts, detections, and automation, while mentoring engineers across threat intelligence, hunting, and engineering.

Responsibilities include delivering intel during incidents, building automation, applying AI to speed analysis, and participating in on-call rotations after hours. Strong Splunk and cloud skills are required.

Qualifications

  • 8+ years of professional cybersecurity experience, with demonstrable time across cyber threat intelligence and/or threat hunting.
  • Experience with sophisticated searching and reporting in Splunk.
  • Ability to build and interpret SPL fluidly.
  • Experience translating large datasets into meaningful information.
  • Understanding of attacker behavior.
  • Ability to translate intelligence and hunt findings into repeatable, automated capabilities.
  • Experience applying AI to accelerate development and analysis.
  • Experience leading threat actor and campaign attribution.
  • Strong programming proficiency in one or more languages for scripts and API automation.
  • Experience delivering tactical threat intelligence in support of incident response.
  • Hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling.
  • Willingness to participate in an on-call rotation, including afterhours support during major incidents.
  • Expertise in uncovering adversary activity missed by industry detection rules.
  • Experience with network and host-based logs.
  • Understanding of common services including DNS, DHCP, email, proxy, VPN, and firewall.
  • Proficiency in AWS, GCP, or Azure.
  • Robust understanding of Linux.
  • Must be a U.S. Person for work on U.S. Government classified environments.
  • Some work may require being a U.S. citizen on U.S. soil

Responsibilities

  • Deliver actionable threat intelligence during active incidents, including indicators, TTPs, behavioral patterns, and threat actor context.
  • Produce cadenced and ad-hoc intelligence products informing hunts, detections, and business decisions.
  • Plan and conduct retrospective, project-based, and ad-hoc threat hunts.
  • Build and maintain scripts, API integrations, and automation for intelligence and hunting use cases.
  • Improve threat-data ingestion, processing, and enrichment while reducing cycle time.
  • Apply AI to accelerate intelligence analysis, hunting, and tooling development.
  • Identify adversary activity missed by current detection rules and provide findings to Detection Engineering.
  • Create written products, presentations, and RFI responses for technical and non-technical audiences.
  • Mentor analysts and engineers developing across threat intelligence, hunting, and engineering.
  • Participate in an on-call rotation and provide afterhours support during major incidents.

Skills

SPL Interpretation
Data Analysis
AI in Cybersecurity
Incident Response Support
DevOps Practices
Infrastructure-as-Code
CI/CD Tooling
Linux Proficiency
Adversary Activity Detection

Tools

Splunk
AWS
GCP
Azure
API Integrations

Job description

Cisco is seeking an experienced threat intelligence and hunting leader to join the Global Security Operations team. You will translate intelligence into actionable hunts, detections, and automation, while mentoring engineers across threat intelligence, hunting, and engineering.

Responsibilities include delivering intel during incidents, building automation, applying AI to speed analysis, and participating in on-call rotations after hours. Strong Splunk and cloud skills are required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Threat Hunting, Intelligence Engineer
Staff Threat Hunting, Intelligence Engineer

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Senior Detection Engineering Lead - AI-Driven Security
Senior Detection Engineering Lead - AI-Driven Security

Cisco • Knoxville (TN)

Hybrid
USD 151,000 - 191,000
Threat Hunter: Exec Protection & IP Security
Threat Hunter: Exec Protection & IP Security

020 Cisco Systems, Inc. • Maryland

Remote
USD 161,000 - 204,000
Senior Cyber Threat Intelligence & Threat Hunting Lead
Senior Cyber Threat Intelligence & Threat Hunting Lead

cFocus Software Incorporated • Washington

On-site
USD 180,000 - 230,000
Senior Threat Hunter: Executive Protection & IP Security
Senior Threat Hunter: Executive Protection & IP Security

Cisco Systems, Inc. • Annapolis (MD), Northern (KY)

Hybrid
USD 158,000 - 200,000
Medical, dental, vision insurance
401(k) retirement plan with company 2:
Restricted stock units
Lead Detection Engineer, AI-Driven Security
Lead Detection Engineer, AI-Driven Security

Cisco Systems, Inc. • Denver (CO)

Hybrid
USD 150,000 - 191,000
Paid holidays
Birthday off
Vacation time
+2
Lead Detection Engineer, Security Analytics
Lead Detection Engineer, Security Analytics

Socket.dev • Denver (CO)

Hybrid
USD 151,000 - 191,000
AOUSC - Cyber Threat Intelligence & Threat Hunting Lead
AOUSC - Cyber Threat Intelligence & Threat Hunting Lead

cFocus Software Incorporated • Washington

On-site
USD 180,000 - 230,000
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Threat Hunting Engineer
Threat Hunting Engineer

RK Management Consultants, Inc. • Milwaukee (WI)

On-site
USD 70,000 - 90,000