Demo

Threat Hunting Analyst (TS/SCI)

Cisco Systems, Inc.
Raleigh, NC Full Time
POSTED ON 4/23/2025
AVAILABLE BEFORE 6/22/2025

Application window is expected to close by 04/30/2025.

Job posting may be removed earlier if the position is filled or if enough applications are received.



Existing or previous Government Security Clearance is required with ability to obtain TS/SCI.

Work must be completed onsite in a secure space at our RTP office. No Hybrid or Remote.





Meet the Team

Cisco's Security Visibility and Incident Command (SVIC) forms part of the investigative branch of Cisco's Security and Trust Organization (S&TO) and is Cisco's cyber investigations and forensics team. It provides Cisco with tailored security monitoring services in order to protect Cisco from cyber-attacks and the loss of its intellectual assets. The primary mission of SVIC is to help ensure company, system, and data preservation by performing comprehensive investigations into computer security incidents, and to give to the prevention of such incidents by engaging in dedicated threat assessment, mitigation planning, incident trend analysis, and security architecture review.

The SVIC is a highly-functioning, diverse, and globally distributed group of best-in-class professionals from various technical backgrounds. We're Open-Source Software contributors, technical authors, tool builders, DFIR community members, lock pickers, makers, and breakers.



Your Impact

SVIC is looking for an experienced security professional to join the Computer Security Incident Response Team. This is an opportunity to contribute to a highly transparent security operations function with global impact upon Cisco, its diversified business, business units, service ventures, partners, and customers. We are looking for a motivated individual with good team fit and the ability to focus on data security and incident analysis. You have a very strong interest in complex problem solving, ability to challenge assumptions, consider alternative perspectives, nimble thinking and perform in high-stress situations, while operating exceedingly well in a strong, tight-knit, collaborative team environment.

Responsibilities Include

  • Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation).
  • Assist with setup and tuning of multiple security monitoring products and data feeds
  • Collaborate with data source SMEs in SVIC and InfoSec to enhance, improve, or modify cloud (IaaS, SaaS, etc) based security detection and response.
  • Update, modify, and enhance existing programs used for security detection and response.
  • Develop documentation on all custom solutions.
  • Identify attackers and their methods but also use your IT and networking expertise to improve detection logic.
  • Occasional travel (<10%)

Attack Analysis

  • Attacker Tools, TTPs
  • Log Analysis (System, Firewall, Application

Cyber Threat Intelligence

  • Threat Hunting
  • Intelligence Analysis
  • Attacker Methodology
  • Industry Peer Collaboration & Information Sharing

Incident/Investigations Handling

  • CyberSecurity Impact Assessment
  • CyberSecurity Problem Management
  • Automation/SOAR
  • Root Cause ID / LTF



Minimum Qualifications

  • 4 years of Cybersecurity or IT security related work experience.
  • Python scripting/coding experience
  • Experience with any three or more of the following tools: Splunk, CSE(AMP4E), Network AMP, WSA, Firepower IPS, NGFW, ESA, CTA, Threat-Grid, Stealthwatch, Umbrella, SecureX, OSQuery, Threat-Quotient, MISP, Recorded-Future, Volatility, Powershell, Wireshark, Encase, Tableau, TheHive
  • Must have Experience with Log Analysis (System, Firewall, Application)



Preferred Qualifications

  • Good technical skills in a variety of operating system, languages, and databases
  • Experience with - Go, Java, JavaScript, SQL, MySQL, STIX/TAXII AND/OR MITRE ATT&CK
  • Certifications GSEC, GCIA, GISF, GCED, GCFA, GCFE, GREM, GCTI, GASF, GCEH, CISSP, CCSP OR SSCP
  • Cloud experience with AWS or Azure.
  • Agility and willingness to deal with a high level of ambiguity and change
  • Flexibility - willingness to pitch in where needed across program and team



# WeAreCisco

#WeAreCisco where every individual brings their unique skills and perspectives together to pursue our purpose of powering an inclusive future for all.

Our passion is connection-we celebrate our employees' diverse set of backgrounds and focus on unlocking potential. Cisconians often experience one company, many careers where learning and development are encouraged and supported at every stage. Our technology, tools, and culture pioneered hybrid work trends, allowing all to not only give their best, but be their best.

We understand our outstanding opportunity to bring communities together and at the heart of that is our people. One-third of Cisconians collaborate in our 30 employee resource organizations, called Inclusive Communities, to connect, foster belonging, learn to be informed allies, and make a difference. Dedicated paid time off to volunteer-80 hours each year-allows us to give back to causes we are passionate about, and nearly 86% do!

Our purpose, driven by our people, is what makes us the worldwide leader in technology that powers the internet. Helping our customers reimagine their applications, secure their enterprise, transform their infrastructure, and meet their sustainability goals is what we do best. We ensure that every step we take is a step towards a more inclusive future for all. Take your next step and be you, with us!


 

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Threat Hunting Analyst (TS/SCI)?

Sign up to receive alerts about other jobs on the Threat Hunting Analyst (TS/SCI) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$79,909 - $105,789
Income Estimation: 
$100,705 - $130,618
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cisco Systems, Inc.

Cisco Systems, Inc.
Hired Organization Address Colorado, CO Full Time
The application window is expected to close 03 / 032025. Duo Cisco = Disco Meet the Team With the Most Loved Company in ...
Cisco Systems, Inc.
Hired Organization Address St. Louis, MO Full Time
Application window is expected to close on 2 / 25 / 2025 Ideal candidate will work onsite / hybrid in St. Louis or Kansa...
Cisco Systems, Inc.
Hired Organization Address San Francisco, CA Full Time
Who We Are The name ThousandEyes was born from two big ideas : the power to see things not ordinarily possible and the a...
Cisco Systems, Inc.
Hired Organization Address San Jose, CA Full Time
Application window is expected to close on 03 / 20 / 2025. However, the job posting may be removed earlier if the positi...

Not the job you're looking for? Here are some other Threat Hunting Analyst (TS/SCI) jobs in the Raleigh, NC area that may be a better fit.

Threat Hunting Analyst (TS/SCI)

Cisco, Raleigh, NC

AI Assistant is available now!

Feel free to start your new journey!