Detection Engineering Technical Leader

Cisco

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Denver, COSaint Paul, MNBoulder, COHouston, TXKnoxville, TN
Salary
$150,500–$190,800 / yr
Posted
11 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $206k
This role $171k
$138k most similar roles pay here $264k

This role pays less than 77% of similar roles. Most pay $176,687–$235,812 — the shaded band above. At the midpoint, this role pays about $171k versus about $206k for comparable roles.

Based on 240 similar postings.

Employer

About Cisco

Cisco Systems is the world''s leading networking technology company, designing and manufacturing networking hardware, telecommunications equipment, and cybersecurity solutions for businesses and governments. Industry: Networking Technology & Cybersecurity

Cisco currently has 196 open roles on FindRole.

Listed pay typically runs $167,700–$245,200 across 196 roles with salary data.

Most-posted roles

View all roles at Cisco

At a glance

TL;DR · Detection Engineering Technical Leader

The Detection Engineering Technical Leader joins the internal security organization to secure the Splunk portfolio. This role involves building scalable detection content, designing data processing pipelines that transform high-volume telemetry into actionable signals, and developing automation for 24x7 monitoring operations. The position requires a blend of engineering rigor and data science to address cybersecurity threats through AI/ML integration and advanced analytics. Key responsibilities include mentoring teammates on design patterns, conducting code reviews, and collaborating with threat hunting, incident response, and SOC teams to close detection gaps. Candidates must be proficient in SPL for building risk-based alerts, Python for production scripts, and Git-based workflows. The role also requires experience with cloud environments like AWS, GCP, or Azure, as well as translating ATT&CK-mapped behaviors into technical requirements to improve signal quality and reduce manual toil.

What you'll do

  • Build scalable detection content and automated systems to power 24/7 monitoring operations.
  • Design data processing pipelines to transform high-volume security telemetry into actionable alert signals.
  • Integrate AI/ML techniques into detection engineering pipelines to reduce false positives and accelerate development.
  • Translate threat intelligence and ATT&CK-mapped behaviors into technical detection requirements and coverage metrics.
  • Develop and optimize complex search queries in SPL for risk-based alerting and statistical baselining.
  • Create automated workflows to reduce manual toil in security triage and response processes.
  • Provide technical mentorship and conduct code reviews to improve team engineering standards.
  • Produce technical documentation, runbooks, and presentations for both technical and non-technical stakeholders.

What we're looking for

  • Must be a U.S. Person (citizen, national, lawful permanent resident, asylee, or refugee).
  • Bachelor's degree with 8 years of experience, Master's with 6 years, or PhD with 3 years in security roles.
  • Experience deploying and maintaining Splunk Enterprise Security content in a production SOC environment.
  • Ability to build scalable detection queries in SPL including risk-based alerting and statistical baselining.
  • Experience integrating AI/ML techniques into detection engineering pipelines to reduce false positives.
  • Ability to translate threat intelligence and ATT&CK-mapped behaviors into technical detection requirements.
  • Proficiency in Python for production scripts with unit tests and version-controlled deployments.
  • U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee.

More like this

Similar roles

Staff Threat Hunting & Intelligence Engineer

Cisco

Seattle, WA +4 15 days ago $160,700$203,500
Splunk SPL Threat Intelligence Threat Hunting API Integration CI/CD DevOps infrastructure-as-code AWS GCP Azure Linux Host-based Logs DNS DHCP Firewall VPN AI
8+ yrs exp Hybrid

Senior Software Engineer, Backend

Cisco

Remote (San Jose, CA) 7 days ago $167,700$245,200
Python Go SQL AWS Azure GCP C++ TypeScript Cypress Splunk Query Language (SPL) CI/CD Distributed Systems Data Processing Query Optimization Agile Claude Codex WPT
7+ yrs exp Remote

Senior Detection Engineer II

Instacart

Remote 18 days ago $230,000$242,500
Detection-as-Code SOAR CI/CD Python Golang AWS Azure GCP macOS Threat Hunting SaaS Machine Learning
6+ yrs exp Remote

Senior Detection Engineer II

Instacart

Remote (CA) +4 18 days ago $196,000$207,000
Detection Engineering SOAR Python Golang AWS Azure GCP CI/CD Detection-as-Code Threat Hunting TTPs macOS Machine Learning Version Control SaaS
6+ yrs exp Remote

Senior Detection Engineer

DoorDash, Inc

Remote 22 days ago $159,800$235,000
Detection Engineering Python Go SQL SPL KQL Snowflake Cortex Google SecOps MITRE ATT&CK D3FEND Data Pipelines Cloud Infrastructure Automation Threat Intelligence
7+ yrs exp Remote

Detection & Mitigation Engineer

Cloudflare, Inc

Austin, TX 8 days ago
SQL Python Data Analysis Metadata Analysis Network Traffic Analysis Threat Intelligence TTPs IOCs Scripting Rule Configuration
Hybrid