> Markdown version of [/jobs/ext/568310-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/568310-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Cisco Systems, Inc. - **Location:** Morrisville, NC, United States - **Experience:** Expert - **Salary:** $137,000.0 - $200,500.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Data Normalization, Intrusion Detection and Prevention, Parsing, Performance Tuning, Cloud Services, Security Information and Event Management, Cisco WebEx, Data Logging, Cloud Platform System, Macros, Data Ingestion, Mitre Att&ck, Git, Splunk, Cisco - **Published:** June 16, 2026 - **Apply:** https://diversityjobs.com/career/17281243/Senior-Security-Engineer-North-Carolina-Research-Triangle-Park ## About the Role * Hands-on experience operating Splunk Enterprise and Splunk Enterprise Security at scale, including deep knowledge of full ES feature enablement for SOC/SIEM use cases. * Advanced SPL development skills, including efficient search design, macros, lookups, stats/tstats, data models, accelerated searches, and dashboard queries. * Experience developing and maintaining Splunk knowledge objects in a managed app or source-controlled environment. * Understanding of Splunk CIM, data normalization, field extractions, props/transforms, event types, tags, and source type design and Experience building, tuning, and maintaining ES correlation searches and notable event workflows. * Familiarity with cloud security logging, incident detection, threat detection logic, and SOC operations. * Experienced in documentation, architecture review, and cross-functional collaboration skills., * Experience with risk-based alerting in Splunk Enterprise Security. * Familiarity with Git-based development workflows for Splunk apps and detection content. * Experience supporting security monitoring in large-scale SaaS, cloud, or production service environments. * Knowledge of MITRE ATT&CK, NIST SP 800-53, ISO/IEC 27001, COBIT, or similar control frameworks. * Experience with detection-as-code practices, automated validation, or CI/CD pipelines for Splunk content. * Splunk certifications are a plus. ## Description life insurance, vision insurance, parental leave, paid holidays, sick time, 401(k) 7025 Kit Creek Road (Show on map) Jun 16, 2026 The application window is expected to close on: 09/14/2026 Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received. This is a hybrid role at the RTP, NC office. Meet the Team We are the CCPS IDR (Intrusion Detection & Response) team. A security engineering group within Cisco's Webex & Collaboration Cloud Platform Security organization. Our mission is to ensure every meaningful security event across the Webex platform is captured, normalized, and delivered to the right hands before it becomes a problem. Our work sits at the intersection of platform engineering and security operations. We own the log ingestion, parsing, and data fidelity pipelines and operational detection effectiveness that power Webex's enterprise SIEM, directly supporting FedRAMP compliance, SOC effectiveness, and executive risk reporting. We are a lean team engineers and a delivery manager. If you care about security engineering that has real, measurable impact at scale and building the foundational observability layer for one of Cisco's largest cloud platforms, this is the team to be on. Your Impact, We are seeking a Security Incident Detection Engineer with deep Splunk and Splunk Enterprise Security experience to support detection engineering, incident visibility, and security monitoring across the Webex cloud service environment. This role will focus on developing, maintaining, and improving Splunk knowledge objects, detection content, validation dashboards, and operational standards that enable reliable security incident detection and response. The engineer will work closely with security operations, cloud security, platform engineering, and service teams to ensure security telemetry is properly ingested, normalized, validated, and actionable. * Build and maintain Splunk Enterprise Security correlation searches, notable events, risk-based alerts, and detection content that directly power security incident visibility across the Webex cloud environment. * Develop detection build out and maintain validation dashboards aligned to telemetry ingestion contracts, ensuring required security events are present, accurate, timely, and CIM-compliant. * Validate data onboarding quality across cloud services covering source types, indexes, field normalization, timestamp accuracy, and parsing consistency. * Partner with SOC and incident response teams to improve alert fidelity, reduce false positives, and ensure detections provide clear investigative context. * Collaborate with platform and service engineering teams to define and improve security logging requirements, and support detection coverage mapping against MITRE ATT&CK and relevant compliance frameworks. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)