- Location
- POL-KRAKOW, Poland
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Experience
- 5+ years
- Education
- PhD
- Source
- Workday
Description
Meet the Team
We are Cisco's Professional Services team and we build, deploy, and optimise the security platforms that enterprise teams rely on every day. Our Splunk Security practice in Krakow works directly with customers across EMEA - helping them detect threats faster, automate response, and get real value out of their security data. We are growing the team and we want engineers who are sharp, curious, and enjoy getting things done!
Your Impact
You will own end-to-end Splunk Enterprise Security deployments for enterprise customers - from day-one installation through to a fully tuned, production-ready platform. We design and build security detection content (correlation searches, risk-based alerting, adaptive response actions), onboard and normalise data sources from firewalls, EDR tools, identity systems, and cloud platforms using Splunk Add-ons and CIM, and wire up automated response workflows in Splunk SOAR. We work side-by-side with customer SOC teams and security engineers, translate requirements into working solutions, and leave customers confident they can run their platforms independently.
We also make the practice better. We contribute to pre-sales scoping, write documentation and runbooks that actually get used, share knowledge across the team, and bring compliance frameworks (PCI-DSS, ISO 27001, GDPR, NIST CSF) to life inside Splunk ES. If you enjoy variety, technical depth, and direct customer contact - this is the role!
Minimum Qualifications
We are looking for engineers with a solid security background and a track record of hands-on delivery. Specifically, you will need:
Bachelor's degree + 5 years of experience, Master's + 3 years, PhD, or equivalent hands-on experience
2+ years of hands-on experience in one or more of the following:
-->Security platform delivery or SIEM/SOAR operations
--> SOC operations, security monitoring, or incident response
--> NOC or network security monitoring (alert triage, event correlation, incident escalation workflows)
--> XDR platform administration or operations (e.g. CrowdStrike Falcon,
--> Microsoft Defender XDR, Palo Alto Cortex XDR, SentinelOne, or equivalent)
--> Security data onboarding or log source integration
Candidates from NOC or infrastructure operations backgrounds are welcome — what matters is hands-on experience with detection, alerting, or incident triage workflows and the motivation to build deep Splunk Security expertise.
Practical scripting or automation skills (Python preferred) and comfort with REST APIs
Fluent English
Clear communication skills with customer technical teams; you manage expectations and keep delivery on track
Preferred Qualifications
Splunk credentials (we will support you with getting certified):
Cybersecurity Defense Analyst, Cybersecurity Defense Engineer (CDE), Splunk Core Consultant, Splunk SOAR Certified Automation Developer
Hands-on experience with Splunk Enterprise Security or Splunk SOAR is a strong advantage
Security:
Security certifications such as CompTIA Security+, CEH, GIAC GCIH, or equivalent
Background in SOC operations, security monitoring, incident response, or log analysis
Familiarity with threat detection frameworks such as MITRE ATT&CK
Experience with security data onboarding and SIEM log source integration
Other:
Familiarity with competitor SIEM/SOAR platforms (e.g. Microsoft Sentinel, IBM QRadar, Palo Alto XSOAR)
Additional European language is an advantage (Polish, German, French, or Arabic)
Why Cisco?
At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.