Threat Hunting Investigator at Cisco in RTP, NC
- Company: Cisco
- Location: RTP, North Carolina, US
- Salary: $131K – $241K
- Job type: full time
- Workplace: onsite
- Posted: 2026-09-14
Job description
The application window is expected to close on: 09/15/2026 Meet the Team Join a highly niche security unit dedicated to proactive defense and high-stakes investigation within a secure, onsite environment. We serve as a critical shield for the organization, executing sophisticated seek campaigns that stay ahead of evolving adversary tradecraft. Our culture is built on technical difficulty and a collaborative spirit where findings are documented and shared to elevate the entire team's intelligence. You will work alongside expert peers who value mentorship and continuous improvement in our detection and forensics capabilities. This is an exciting opportunity to apply deep technical expertise to protect the most sensitive layers of our infrastructure. Your Impact Build and execute hypothesis-driven hunt campaigns based on adversary tradecraft to identify and neutralize hidden threats. Build durable detection logic in Splunk and map coverage against the MITRE ATT&CK framework to ensure detailed security visibility. Perform end-to-end host and network forensics to determine root causes and drive effective incident containment and eradication. Brief technical findings to both engineering peers and leadership to translate sophisticated investigation data into actionable organizational insights. Mentor junior analysts and develop robust playbooks to improve the collective maturity and readiness of the security team. Minimum Qualifications Active TS/SCI clearance, in scope, at time of hire. 4+ years of combined experience in threat hunting, incident response, detection engineering, or Tier 2+ SOC analysis. Proficiency querying and building content in an enterprise SIEM, specifically Splunk (SPL). Practical knowledge of Windows and Linux internals, TCP/IP, and common application-layer protocols. Scripting proficiency in Python, PowerShell, or Bash for enrichment and automation. Preferred Qualifications Experience with network forensics and traffic analysis using tools like Zeek, Wireshark, or NetFlow. Proficiency in Detection-as-code practices, including version control, peer review, and unit-tested logic. Prior experience in DoD, Intelligence Community (IC), or federal SOC environments. Relevant security certifications such as GCFA, GCIA, GCTI, GDAT, GNFA, GREM, or OSCP. Ability to produce meticulous investigation records and brief findings to compliance and non-technical collaborators. Why Cisco? At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you. Message to applicants applying to work in the U.S. and/or Canada: The starting salary range posted for this position is $130,500.00 to $175,000.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process. U.S. employees are offered benefits, su
Threat Hunting Investigator on JobPost.