Staff Threat Hunting & Intelligence Engineer

Cisco

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Seattle, WAPortland, ORArlington, VAWashington, DCColumbia, SC
Salary
$160,700–$203,500 / yr
Posted
15 days ago
Freshness
Confirmed live yesterday
Closes
Oct 27, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $185k
This role $182k
$124k most similar roles pay here $235k

This role pays more than 52% of similar roles. Most pay $151,500–$217,625 — the shaded band above. At the midpoint, this role pays about $182k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About Cisco

Cisco Systems is the world''s leading networking technology company, designing and manufacturing networking hardware, telecommunications equipment, and cybersecurity solutions for businesses and governments. Industry: Networking Technology & Cybersecurity

Cisco currently has 196 open roles on FindRole.

Listed pay typically runs $167,700–$245,200 across 196 roles with salary data.

Most-posted roles

View all roles at Cisco

At a glance

TL;DR · Staff Threat Hunting & Intelligence Engineer

The Staff Threat Hunting & Intelligence Engineer joins the Global Security Operations team to bridge threat intelligence, hunting, and engineering. This hybrid role involves tracking sophisticated adversaries, producing tactical intelligence including TTPs and behavioral patterns, and conducting proactive hunts across large datasets. The engineer will build automation, scripts, and API integrations to scale intelligence processing while applying AI to accelerate analysis and tooling development. Key responsibilities include creating hunt libraries, identifying gaps in detection rules, and mentoring team members. Required skills include expert-level Splunk proficiency with SPL, programming for automation, and experience with network and host-based logs across cloud environments like AWS, GCP, or Azure. The role addresses the critical challenge of transforming raw threat data into repeatable, scalable capabilities to defend against advanced adversaries while providing actionable insights during active incidents.

What you'll do

  • Deliver actionable threat intelligence including indicators, TTPs, and behavioral patterns during active incidents.
  • Produce cadenced and ad-hoc intelligence products to inform hunts, detections, and business decisions.
  • Plan and conduct retrospective, project-based, and ad-hoc threat hunts across large datasets.
  • Build and maintain scripts, API integrations, and automation to scale intelligence and hunting capabilities.
  • Apply AI technologies to accelerate intelligence analysis, hunt operations, and tooling development.
  • Identify adversary activity missed by current detection rules and provide findings to the Detection Engineering team.
  • Create written products, presentations, and RFI responses for both technical and non-technical audiences.
  • Mentor analysts and engineers across threat intelligence, hunting, and engineering disciplines.

What we're looking for

  • Must be a U.S. Person (citizen, national, permanent resident, asylee, or refugee).
  • 8+ years of professional cybersecurity experience in cyber threat intelligence and/or threat hunting.
  • Ability to build and interpret SPL for sophisticated searching and reporting in Splunk.
  • Experience translating large datasets into meaningful information with a focus on persistent investigation.
  • Understanding of attacker behavior and ability to translate findings into automated capabilities.
  • Experience applying AI to accelerate development, analysis, and tooling.
  • Strong programming proficiency to build scripts and API automation (preferred).
  • U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee.

More like this

Similar roles

Senior Threat Intelligence Investigator

Oracle

Nashville, TN +3 10 days ago $114,600$234,600
Threat Intelligence Platforms Cyber Threat Intelligence (CTI) OSINT YARA Snort Suricata Bro/Zeek Malware Analysis Incident Response SOC Digital Forensics Windows Linux macOS OCI
6+ yrs exp

Senior Threat Intelligence Investigator

Oracle

Nashville, TN +1 105 days ago $104,200$234,600
Threat Intelligence Cyber Threat Intelligence (CTI) OSINT Malware Analysis YARA Snort Suricata Bro/Zeek Incident Response SOC Digital Forensics OCI Cloud Security Windows Linux macOS
3+ yrs exp

Detection Engineering Technical Leader

Cisco

Denver, CO +4 11 days ago $150,500$190,800
Splunk SPL Python AI/ML AWS GCP Azure Git CI/CD Cybersecurity Data Science Threat Intelligence CloudTrail Azure Monitor Automation
8+ yrs exp Hybrid

Threat Hunter, FedCloud

CrowdStrike

Remote 28 days ago $85,000$120,000
Threat Hunting Python Go Windows MacOS Linux Splunk Kibana LogScale AWS Azure GCP Digital Forensics Malware Analysis Cyber Threat Intelligence Incident Response Cloud Security
Remote

Threat Hunter III

CrowdStrike

Remote 36 days ago $100,000$155,000
Threat Hunting Python Go Windows MacOS Linux Splunk Kibana LogScale AWS Azure GCP Digital Forensics Malware Analysis Cyber Threat Intelligence Incident Response Cloud Security
Remote

Threat Intelligence Engineer

Take-Two Interactive

Austin, TX 32 days ago
Threat Intelligence SIEM EDR TIP Python PowerShell Bash MITRE ATT&CK Cyber Kill Chain STIX/TAXII JSON XML API Integration AWS Azure GCP Malware Analysis Firewalls
2+ yrs exp