FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff Threat Hunting, Intelligence Engineer
CiscoStaff threat hunting engineer protecting Cisco’s global networking and security infrastructure. Delivering intelligence, hunts, and automation against sophisticated cyber adversaries.
Posted 8/27/2026full-timeSeattle • California, District of Columbia, Oregon, South Carolina, Virginia, Washington • 🇺🇸 United StatesLead💰 $160,700 - $203,500 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in Cybersecurity, particularly in Threat Intelligence and Threat Hunting, with a strong ability to analyze and automate intelligence processes. Proficient in utilizing AI for intelligence analysis and capable of delivering actionable insights to enhance incident response and detection capabilities.
Highest-signal resume keywords
Cyber Threat IntelligenceThreat HuntingSplunk ProficiencyProgramming for AutomationCloud Proficiency (AWS, GCP, Azure)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cybersecurity ExperienceSPL InterpretationData AnalysisAI Application in CybersecurityIncident Response SupportDevOps PracticesInfrastructure-as-CodeCI/CD ToolingLinux ProficiencyAdversary Activity Detection
Soft Skills
CollaborationMentoringCommunication
Tools & Technologies
SplunkAWSGCPAzureAPI Integrations
Industry Keywords
Threat Actor AttributionTTPsBehavioral PatternsThreat Intelligence ProductsNetwork LogsHost-Based LogsDNSDHCPEmailFirewall
Tech Stack
Tools & technologiesAWSAzureCyber SecurityDNSGoogle Cloud PlatformLinuxSplunk
About the role
Key responsibilities & impact- Report to the Senior Manager, Threat Hunting and Intelligence within Cisco’s Global Security Operations organization
- Collaborate with Detection Engineering, SOC, Advanced Response, and other multifunctional peer teams
- Deliver actionable threat intelligence during active incidents, including indicators, TTPs, behavioral patterns, and threat actor context
- Produce cadenced and ad-hoc intelligence products informing hunts, detections, and business decisions
- Plan and conduct retrospective, project-based, and ad-hoc threat hunts
- Build and maintain scripts, API integrations, and automation for intelligence and hunting use cases
- Improve threat-data ingestion, processing, and enrichment while reducing cycle time
- Apply AI to accelerate intelligence analysis, hunting, and tooling development
- Identify adversary activity missed by current detection rules and provide findings to Detection Engineering
- Create written products, presentations, and RFI responses for technical and non-technical audiences
- Mentor analysts and engineers developing across threat intelligence, hunting, and engineering
- Participate in an on-call rotation and provide afterhours support during major incidents
Requirements
What you’ll need- 8+ years of professional cybersecurity experience, with demonstrable time across cyber threat intelligence and/or threat hunting
- Experience with sophisticated searching and reporting in Splunk
- Ability to build and interpret SPL fluidly
- Experience translating large datasets into meaningful information
- Understanding of attacker behavior
- Ability to translate intelligence and hunt findings into repeatable, automated capabilities
- Experience applying AI to accelerate development and analysis
- Experience leading threat actor and campaign attribution
- Strong programming proficiency in one or more languages for scripts and API automation
- Experience delivering tactical threat intelligence in support of incident response
- Hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling
- Willingness to participate in an on-call rotation, including afterhours support during major incidents
- Expertise in uncovering adversary activity missed by industry detection rules
- Experience with network and host-based logs
- Understanding of common services including DNS, DHCP, email, proxy, VPN, and firewall
- Proficiency in AWS, GCP, or Azure
- Robust understanding of Linux
- Must be a U.S. Person for work on U.S. Government classified environments
- Some work may require being a U.S. citizen on U.S. soil
Benefits
Comp & perks- Medical, dental and vision insurance
- 401(k) plan with a Cisco matching contribution
- Paid parental leave
- Short- and long-term disability coverage
- Basic life insurance
- Cisco restricted stock unit grants may be available
- 10 paid holidays per full calendar year
- 1 floating holiday for non-exempt employees
- Paid birthday day off
- Paid year-end holiday shutdown
- 4 paid personal wellness days
- 16 days of paid vacation per full calendar year for non-exempt employees
- Flexible vacation time off program with no defined limit for eligible exempt employees
- 80 hours of sick time off provided on hire and each January 1st
- Up to 80 hours of unused sick time carried forward
- Additional paid time away for critical or emergency family issues
- Optional 10 paid volunteer days per full calendar year
- Annual bonuses for non-sales roles, subject to Cisco’s policies