Startups

Detection Engineering Technical Leader

Cisco · 16 Locations · On-site

← All jobs
About Cisco

Cisco is a worldwide technology leader powering an inclusive future for all. Learn more about our products, services, solutions, and innovations. Backed by Sequoia and Menlo.

About the role

You'll be joining a team of like-minded engineers focused on securing our enterprise and building for the future — together, we engineer scalable detection systems and automation that power 24x7 monitoring operations and rapid response to cybersecurity threats.

What they're looking for

  • Deployed and maintained Splunk Enterprise Security content in a production SOC environment, including detections , data models, and data management
  • Built detection queries in SPL at scale, including risk- based alerting , statistical baselining, and optimized searches across high-volume data sources
  • Integrated AI/ML techniques (e.g., anomaly detection, LLM-assisted workflows) into detection engineering pipelines to reduce false positive rates and accelerate content development
  • Translated threat intelligence and ATT&CK-mapped adversary behaviors into detection requirements with defined coverage metrics and measurable success criteria
  • Contributed to collaborative development workflows using Git-based platforms (GitHub, GitLab, or Bitbucket), including branch strategy, code review, and CI/CD integration
  • Built or tuned security monitoring coverage across AWS, GCP, or Azure, including native logging services (e.g., CloudTrail, GCS audit logs, Azure Monitor) and cloud-native threat detection
More about this role

The application window is expected to close on: 10/06/2026

The successful applicant will be performing work in FedRAMP High or IL-5 environments, and therefore, must be a U.S. Person ( i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.

This role works within Splunk’s internal security organization as a member of the Detection Engineering team responsible for securing the Splunk portfolio . The rol e will partner fluidly with our multi-functional peer teams: Threat Hunting & Intelligence, SOC, Advanced Response, and others, to ensure that Splunk is always prepared for emergent threats . This is a true hybrid role. You will move dynamically between building new scalable detection content, collaborating with incident response organizations, mentoring teammates on detection standards and design patterns, as well designing the future of engineering threat detection solutions at Splunk.

You'll be joining a team of like-minded engineers focused on securing our enterprise and building for the future — together, we engineer scalable...

Read the full posting on Cisco's site ↗

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.