Data Engineer, Incident response

  • Location:
    Offsite, RTP, North Carolina, US
  • Alternate Location
    Anywhere in the USA
  • Area of Interest
    Information Technology
  • Compensation Range
    128400 USD - 172300 USD
  • Job Type
    Professional
  • Technology Interest
    Cloud & AI (DCN & Compute), Security, Security and Observability
  • Job Id
    1445073

The application window is expected to close on: October 16th, 2025


NOTE: Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.


The successful applicant will provide ownership of and be performing work in FedRAMP or IL-5 type environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.


Meet the Team

The Security Visibility & Incident Command (SVIC) team provides visibility into security and compliance, performs incident response, and drives root cause analysis to improve Cisco's security posture. SVIC serves Cisco and its business entities by detecting, responding to, and mitigating security incidents, improving compliance and security posture, and ensuring Cisco meets its regulatory and contractual obligations for data loss notification.


Your Impact

You will design and optimize data pipelines to provide actionable intelligence for security and compliance operations. You’ll work with large-scale data across diverse sources, using Splunk as a primary platform for storage, transformation, and analysis. This is a high-impact role where your ability to ensure performance, scalability, and reliability will directly strengthen Cisco’s security capabilities.

Responsibilities include:

  • Designing, building, and maintaining scalable data pipelines for ingesting, transforming, and storing large volumes of data in Splunk.
  • Using Splunk Enterprise, SPL (Search Processing Language), and technical add-ons to perform advanced data transformations and enrichments.
  • Collaborating with partners to define requirements and ensure seamless integration of new data sources.
  • Ensuring compliance with data governance and security standards in all engineering work.
  • Implementing and monitoring data quality and validation processes for accuracy and reliability.
  • Solving Splunk ingestion pipeline issues and performance bottlenecks.
  • Working with security engineering teams to define and enforce logging standards.
  • Staying up to date with Splunk features, add-ons, and protocols to bring innovation to the SVIC team.


Minimum Qualifications

  • 3–4 years of experience in Splunk administration (either on-prem or cloud).
  • Experience with Splunk SOAR (formerly Phantom), Search Head Clustering, and Indexer Clustering.
  • Ability to design, implement, and maintain data pipelines at scale in Splunk.
  • Familiarity with other SIEM platforms such as ELK or Exabeam.
  • Proficiency in Linux/UNIX administration for deploying and supporting data systems.


Preferred Qualifications

  • Experience working with cloud platforms – AWS strongly preferred, with exposure to Azure and GCP beneficial.
  • Strong understanding of security operations and incident response workflows.
  • Ability to drive metrics and analytics for operational improvements.
  • Experience automating operational tasks using scripting and orchestration tools.
  • Strong communication skills .


WHY CISCO?

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Simply put – we power the future.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.

We are Cisco, and our power starts with you. 

Message to applicants applying to work in the U.S. and/or Canada:

When available, the salary range posted for this position reflects the projected hiring range for new hire, full-time salaries in U.S. and/or Canada locations, not including equity or benefits. For non-sales roles the hiring ranges reflect base salary only; employees are also eligible to receive annual bonuses. Hiring ranges for sales positions include base and incentive compensation target. Individual pay is determined by the candidate's hiring location and additional factors, including but not limited to skillset, experience, and relevant education, certifications, or training. Applicants may not be eligible for the full salary range based on their U.S. or Canada hiring location. The recruiter can share more details about compensation for the role in your location during the hiring process.

U.S. employees have access to quality medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, short and long-term disability coverage, basic life insurance and numerous wellbeing offerings.

Employees receive up to twelve paid holidays per calendar year, which includes one floating holiday (for non-exempt employees), plus a day off for their birthday. Non-Exempt new hires accrue up to 16 days of vacation time off each year, at a rate of 4.92 hours per pay period. Exempt new hires participate in Cisco’s flexible Vacation Time Off policy, which does not place a defined limit on how much vacation time eligible employees may use, but is subject to availability and some business limitations. All new hires are eligible for Sick Time Off subject to Cisco’s Sick Time Off Policy and will have eighty (80) hours of sick time off provided on their hire date and on January 1st of each year thereafter.  Up to 80 hours of unused sick time will be carried forward from one calendar year to the next such that the maximum number of sick time hours an employee may have available is 160 hours. Employees in Illinois have a unique time off program designed specifically with local requirements in mind. All employees also have access to paid time away to deal with critical or emergency issues. We offer additional paid time to volunteer and give back to the community.

Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components. For quota-based incentive pay, Cisco typically pays as follows:

.75% of incentive target for each 1% of revenue attainment up to 50% of quota;

1.5% of incentive target for each 1% of attainment between 50% and 75%;

1% of incentive target for each 1% of attainment between 75% and 100%; and once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.

For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.

Share