
10,000+ employees
Founded 1984
🔧 Hardware
🔐 Security
🏢 Enterprise
Hardware • Security • Enterprise
Cisco is a multinational technology company that provides networking hardware, software, and services to enterprises, service providers, and governments. It builds routers, switches, optical transceivers, programmable silicon, and edge computing platforms, and offers security, collaboration (Webex), observability, and AI-enabled software and support services to help organizations design, operate, and secure large-scale networks and data centers. Cisco also delivers professional services, training, and cloud-managed solutions to support digital transformation and AI-ready infrastructure.
🔥 0 minutes ago
🌵 Arizona, Texas – Remote
💵 $104k - $138.1k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚨 Incident Response Analyst
🦅 H1B Visa Sponsor
Improve your chances of getting an interview by checking your resume score before you apply.

10,000+ employees
Founded 1984
🔧 Hardware
🔐 Security
🏢 Enterprise
Hardware • Security • Enterprise
Cisco is a multinational technology company that provides networking hardware, software, and services to enterprises, service providers, and governments. It builds routers, switches, optical transceivers, programmable silicon, and edge computing platforms, and offers security, collaboration (Webex), observability, and AI-enabled software and support services to help organizations design, operate, and secure large-scale networks and data centers. Cisco also delivers professional services, training, and cloud-managed solutions to support digital transformation and AI-ready infrastructure.
• Triage, investigate, and respond to security alerts across enterprise and product environments • Scope threats, collect evidence, and drive response actions using Splunk and security platforms • Partner with Detection Engineering to tune detections, reduce false positives, and close coverage gaps • Build and maintain SOC automation, including scripts, playbooks, and enrichment workflows • Apply AI-assisted and agentic tooling to investigations with human oversight • Hunt threats and lead incident reviews • Contribute to cross-team investigations and improve SOC-wide quality • Own security incidents from initial alert through documented resolution • Work Wednesday through Saturday, 10:00am–8:00pm Pacific time • Participate in an on-call rotation one week every two months, 11:00pm–8:00am Eastern Standard Time
• Bachelor's Degree • 4+ years of experience in security operations, incident response, or a related technical role • Working knowledge of incident response, alert triage, threat hunting, evidence handling, escalation workflows, and attacker techniques • Hands-on experience triaging and investigating alerts with SIEM, EDR, cloud, or network security tools • Experience with Git/GitLab workflows, including branching, merge requests, code review, and CI/CD • Experience with automation scripts and updating playbooks, pipeline configurations, or modular tooling • Experience with AI-assisted development, AI-powered security tooling, or agentic workflows • Ability to critically evaluate AI/tool output before taking action • Experience with MITRE ATT&CK, threat hunting methodology, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics • Strong written and verbal communication skills • Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments • Experience building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows • Experience with GitLab CI/CD or similar pipeline systems • Familiarity with cloud, containers, Kubernetes, CI/CD runners, artifact registries, package management, or software supply chain security • Scripting or automation experience in Python, Bash, Go, or JavaScript • Must be a U.S. Person (U.S. citizen) • Must be able to perform work restricted to a U.S. citizen on U.S. soil
• Medical, dental and vision insurance • 401(k) plan with Cisco matching contribution • Paid parental leave • Short- and long-term disability coverage • Basic life insurance • Cisco restricted stock unit grants may be available • 10 paid holidays per full calendar year • 1 floating holiday for non-exempt employees • 1 paid day off for employee’s birthday • Paid year-end holiday shutdown • 4 paid days off for personal wellness • 16 days of paid vacation time per full calendar year for non-exempt employees • Flexible vacation time off program with no defined limit for eligible exempt employees • 80 hours of sick time off provided on hire date and each January 1st thereafter • Up to 80 hours of unused sick time carried forward • Additional paid time away for critical or emergency family issues • Optional 10 paid days per full calendar year to volunteer • Annual bonuses may be available for non-sales roles • Sales employees may earn performance-based incentive pay • Professional growth and development opportunities • Global network and team collaboration
Apply Now🕒 July 15
Senior Incident Handler at Allstate leading critical incident response and investigations. Driving modern security operations with a focus on automation and AI.
🇺🇸 United States – Remote
💵 $120k - $193.7k / year
💰 Post-IPO Equity on 2014-01
⏰ Full Time
🟠 Senior
🚨 Incident Response Analyst
🦅 H1B Visa Sponsor