Incident Response Analyst

Cisco
Austin, Atlanta, Phoenix
Workplace: RemoteFull timeUSD 104,000 - 138,100 annuallyFunction: Solutions Engineering & Sales EngineeringExperience: 4+ yearsEducation: bachelorsSkills: ["Written communication","Verbal communication","Documentation","Critical evaluation"]

Own the full incident-response lifecycle, triaging and investigating security alerts across Splunk enterprise and product environments. Scope threats, collect evidence, and execute response actions using Splunk and other security platforms while partnering with Detection Engineering to improve detections and reduce false positives. Build and maintain SOC automation (scripts, playbooks, enrichment workflows) and apply AI/agentic investigation tooling with human oversight, contributing to threat hunting and incident reviews.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cisco
Cisco
1 hour ago

Incident Response Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own the full incident-response lifecycle, triaging and investigating security alerts across Splunk enterprise and product environments. Scope threats, collect evidence, and execute response actions using Splunk and other security platforms while partnering with Detection Engineering to improve detections and reduce false positives. Build and maintain SOC automation (scripts, playbooks, enrichment workflows) and apply AI/agentic investigation tooling with human oversight, contributing to threat hunting and incident reviews.
Location: Austin, Atlanta, Phoenix
Workplace: Remote
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Own the full arc of security incidents from first alert through documented resolution.
  • •Triage, investigate, and respond to security alerts across Splunk enterprise and product environments.
  • •Scope threats, collect evidence, and drive response actions using Splunk tooling and security platforms.
  • •Partner with Detection Engineering to tune detections, reduce false positives, and close coverage gaps.
  • •Build and maintain SOC automation and apply AI/agentic tooling to accelerate investigations with human oversight.

Pay and Benefits

Salary: USD 104,000 - 138,100 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kPaid Parental

Key Requirements

  • •Bachelor's degree and 4+ years of experience in security operations, incident response, or a related technical role.
  • •Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and common attacker techniques.
  • •Hands-on experience triaging and investigating alerts using SIEM, EDR, cloud, or network security tooling.
  • •Experience using Git/GitLab workflows, including branching, merge requests, code review, and CI/CD.
  • •Experience with automation scripts and AI-assisted/agentic investigation workflows, with the ability to critically evaluate tool output before taking action.
Experience:4+ years
Education:Bachelor's
Skills:Written communicationVerbal communicationDocumentationCritical evaluation
Tech Stack:SplunkSplunk Enterprise SecuritySplunk SPLSIEMEDRSOARGitGitLabCI/CDGitLab CI/CDPythonBashGoJavaScriptMITRE ATT&CKKubernetesCloudNetwork securityPhishingMalware triage

Eligibility

Nationality:US National

Company Brief

Cisco
Global technology company that designs, manufactures, and sells networking hardware, telecommunications equipment, and high-technology services and products for enterprises, service providers, and governments worldwide.
Industry: Networking Equipment
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Jose, United States
Founded: 1984
Glassdoor
Glassdoor: 4.0
WebsiteLinkedInGlassdoor