Staff Threat Hunting, Intelligence Engineer

Jobtailor

California (MO)

On-site

USD 150,000 - 210,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cisco is seeking an experienced threat intelligence and hunting leader to join the Global Security Operations team. You will translate intelligence into actionable hunts, detections, and automation, while mentoring engineers across threat intelligence, hunting, and engineering.

Responsibilities include delivering intel during incidents, building automation, applying AI to speed analysis, and participating in on-call rotations after hours. Strong Splunk and cloud skills are required.

Qualifications

  • 8+ years of professional cybersecurity experience, with demonstrable time across cyber threat intelligence and/or threat hunting.
  • Experience with sophisticated searching and reporting in Splunk.
  • Ability to build and interpret SPL fluidly.
  • Experience translating large datasets into meaningful information.
  • Understanding of attacker behavior.
  • Ability to translate intelligence and hunt findings into repeatable, automated capabilities.
  • Experience applying AI to accelerate development and analysis.
  • Experience leading threat actor and campaign attribution.
  • Strong programming proficiency in one or more languages for scripts and API automation.
  • Experience delivering tactical threat intelligence in support of incident response.
  • Hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling.
  • Willingness to participate in an on-call rotation, including afterhours support during major incidents.
  • Expertise in uncovering adversary activity missed by industry detection rules.
  • Experience with network and host-based logs.
  • Understanding of common services including DNS, DHCP, email, proxy, VPN, and firewall.
  • Proficiency in AWS, GCP, or Azure.
  • Robust understanding of Linux.
  • Must be a U.S. Person for work on U.S. Government classified environments.
  • Some work may require being a U.S. citizen on U.S. soil

Responsibilities

  • Deliver actionable threat intelligence during active incidents, including indicators, TTPs, behavioral patterns, and threat actor context.
  • Produce cadenced and ad-hoc intelligence products informing hunts, detections, and business decisions.
  • Plan and conduct retrospective, project-based, and ad-hoc threat hunts.
  • Build and maintain scripts, API integrations, and automation for intelligence and hunting use cases.
  • Improve threat-data ingestion, processing, and enrichment while reducing cycle time.
  • Apply AI to accelerate intelligence analysis, hunting, and tooling development.
  • Identify adversary activity missed by current detection rules and provide findings to Detection Engineering.
  • Create written products, presentations, and RFI responses for technical and non-technical audiences.
  • Mentor analysts and engineers developing across threat intelligence, hunting, and engineering.
  • Participate in an on-call rotation and provide afterhours support during major incidents.

Skills

SPL Interpretation
Data Analysis
AI in Cybersecurity
Incident Response Support
DevOps Practices
Infrastructure-as-Code
CI/CD Tooling
Linux Proficiency
Adversary Activity Detection

Tools

Splunk
AWS
GCP
Azure
API Integrations

Job description

  • Report to the Senior Manager, Threat Hunting and Intelligence within Cisco’s Global Security Operations organization
  • Collaborate with Detection Engineering, SOC, Advanced Response, and other multifunctional peer teams
  • Deliver actionable threat intelligence during active incidents, including indicators, TTPs, behavioral patterns, and threat actor context
  • Produce cadenced and ad-hoc intelligence products informing hunts, detections, and business decisions
  • Plan and conduct retrospective, project-based, and ad-hoc threat hunts
  • Build and maintain scripts, API integrations, and automation for intelligence and hunting use cases
  • Improve threat-data ingestion, processing, and enrichment while reducing cycle time
  • Apply AI to accelerate intelligence analysis, hunting, and tooling development
  • Identify adversary activity missed by current detection rules and provide findings to Detection Engineering
  • Create written products, presentations, and RFI responses for technical and non-technical audiences
  • Mentor analysts and engineers developing across threat intelligence, hunting, and engineering
  • Participate in an on-call rotation and provide afterhours support during major incidents
Requirements
  • 8+ years of professional cybersecurity experience, with demonstrable time across cyber threat intelligence and/or threat hunting
  • Experience with sophisticated searching and reporting in Splunk
  • Ability to build and interpret SPL fluidly
  • Experience translating large datasets into meaningful information
  • Understanding of attacker behavior
  • Ability to translate intelligence and hunt findings into repeatable, automated capabilities
  • Experience applying AI to accelerate development and analysis
  • Experience leading threat actor and campaign attribution
  • Strong programming proficiency in one or more languages for scripts and API automation
  • Experience delivering tactical threat intelligence in support of incident response
  • Hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling
  • Willingness to participate in an on-call rotation, including afterhours support during major incidents
  • Expertise in uncovering adversary activity missed by industry detection rules
  • Experience with network and host-based logs
  • Understanding of common services including DNS, DHCP, email, proxy, VPN, and firewall
  • Proficiency in AWS, GCP, or Azure
  • Robust understanding of Linux
  • Must be a U.S. Person for work on U.S. Government classified environments
  • Some work may require being a U.S. citizen on U.S. soil
Core Competencies

Demonstrates extensive experience in Cybersecurity, particularly in Threat Intelligence and Threat Hunting, with a strong ability to analyze and automate intelligence processes. Proficient in utilizing AI for intelligence analysis and capable of delivering actionable insights to enhance incident response and detection capabilities.

Highest-signal resume keywords
  • Cyber Threat Intelligence
  • Threat Hunting
  • Splunk Proficiency
  • Programming for Automation
  • Cloud Proficiency (AWS, GCP, Azure)
Hard Skills
  • Cybersecurity Experience
  • SPL Interpretation
  • Data Analysis
  • AI Application in Cybersecurity
  • Incident Response Support
  • DevOps Practices
  • Infrastructure-as-Code
  • CI/CD Tooling
  • Linux Proficiency
  • Adversary Activity Detection
Soft Skills
  • Collaboration
  • Mentoring
  • Communication
Industry Keywords
  • Threat Actor Attribution
  • TTPs
  • Behavioral Patterns
  • Threat Intelligence Products
  • Network Logs
  • Host-Based Logs
  • DNS
  • DHCP
  • Email
  • Firewall
Tools & Technologies
  • Splunk
  • AWS
  • GCP
  • Azure
  • API Integrations
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunting Engineer
Threat Hunting Engineer

RK Management Consultants, Inc. • Milwaukee (WI)

On-site
USD 70,000 - 90,000
Senior Security Engineer – Threat Intelligence, Detection
Senior Security Engineer – Threat Intelligence, Detection

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Senior Threat Hunting & Intelligence Engineer
Senior Threat Hunting & Intelligence Engineer

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Security Analyst
Security Analyst

Resolve Tech Solutions • Irving (TX)

On-site
USD 95,000 - 140,000
Cybersecurity Threat Analyst I
Cybersecurity Threat Analyst I

Jobtailor • Sioux Falls (SD)

On-site
USD 45,000 - 65,000
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Open Systems Technologies Corporation • Huntsville (AL)

On-site
USD 110,000 - 150,000
PTO 3 weeks
Holiday pay 2 weeks
Medical/dental/vision coverage
+5
Cyber Threat Hunter
Cyber Threat Hunter

cFocus Software Incorporated • Washington

On-site
USD 90,000 - 120,000
Senior Director, Cyber Threat Intellignece
Senior Director, Cyber Threat Intellignece

Kroll • Northern (KY)

Hybrid
USD 150,000 - 200,000
Threat Intelligence Analyst
Threat Intelligence Analyst

Resolve Tech Solutions • Irving (TX)

On-site
USD 120,000 - 180,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000