- Location
- IND-HYDERABAD, India
- Workplace
- Hybrid
- Type
- Full-time
- Seniority
- Manager
- Experience
- 7+ years
- Source
- Workday
Description
Meet the Team
The Advanced Response Team (ART) leads Splunk’s response to cybersecurity incidents affecting Splunk product infrastructure. ART partners with engineering and business teams to contain incidents, determine root cause, and drive lasting remediation that reduces risk across Splunk. ART is a collaborative, security-first team that values sound judgment, clear communication, continuous learning, and a supportive work environment. In this India-based role, you will expand ART’s global coverage, lead complex incidents, mentor analysts, and shape team-wide response practices during a shift that includes periods of independent coverage.
Your Impact
Command the response to complex cybersecurity incidents affecting Splunk product infrastructure, coordinating technical and business teams from initial containment through remediation. Direct investigations to reconstruct events, identify malicious activity, determine root cause, and establish near- and long-term corrective actions. Provide technical leadership and mentor analysts to strengthen investigative judgment and response readiness across ART. Represent ART to business leaders by translating technical findings into clear assessments of incident impact, risk, and required remediation. Build ART’s response program by developing department-wide processes and repeatable playbooks that improve incident resolution, global handoffs, and long-term security outcomes.
Minimum Qualifications
- 7+ years of professional Information Technology or information security experience, including four or more years leading responses to concurrent, complex, or large-scale cybersecurity incidents.
- Practical experience investigating incidents in Linux, public cloud, and containerized or Kubernetes-orchestrated environments. Experience analyzing identity and access management (IAM) activity, CI/CD pipelines, software supply chain telemetry, and Security Information and Event Management (SIEM) data.
- Proven technical depth in at least two of the following areas: digital forensics, software supply chain security, cloud or container incident response, detection engineering, threat hunting, identity security investigations, network forensics, or malware analysis or reverse engineering.
- Experience evaluating and implementing AI-assisted workflows for cybersecurity incident triage, investigation, analysis, or reporting, including controls for output validation and sensitive data handling.
- Experience serving as a technical lead, mentoring analysts, and creating or validating department-wide incident response processes.
Preferred Qualifications
- Experience translating highly technical incident findings into clear, actionable guidance for nontechnical audiences.
- Experience prioritizing concurrent response activities, making time-sensitive decisions, and leading teams during high-pressure incidents.
- Experience responding to software supply chain incidents involving source control, CI/CD pipelines, artifact registries, or deployment systems.
- Experience building or operating Kubernetes environments and establishing the supporting cloud infrastructure, security telemetry, and forensic capabilities.
- Experience with artificial intelligence technologies in security operations, including investigating or mitigating security risks involving AI applications, models, agents, AI-generated code, or third-party AI services.
Why Cisco?
At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
Disclaimer
To ensure that we hire the best talent in the right way, we follow a strict hiring process and recently, Cisco has been made aware of fraudulent recruiters claiming to be from the company. Please be advised that any communication from Cisco about careers will:
- be in direct response to an application you have submitted through the company career site
- begin with screening or an interview
- originate from a Cisco email address, and
- be conducted across email, phone, or WebEx
Cisco will never make a job offer without conducting an interview process or ask you for money in any way. If you have been requested to apply for a role or have received an offer from a site other than https://careers.cisco.com or cisco.wd5.myworkday.com, do not provide any personal identifying information, including your Aadhaar or other personal identifying number, birth certificate, banking information, driver's license, or passport.
If you are the target of a recruiting scam, consider filing a report with your local law enforcement authorities. Cisco bears no responsibility, and cannot be held liable, for any claims, damages, expenses, or other inconvenience resulting from or in any way connected to recruiting scams.