Full-Time

Fedramp Software Engineer – Early Career

Posted on 3/25/2025

Splunk

Splunk

5,001-10,000 employees

Real-time machine data analytics for IT

No salary listed

No H1B Sponsorship

Raleigh, NC, USA + 1 more

More locations: Boulder, CO, USA

Hybrid

This position requires relocation to either Boulder, CO or Raleigh, NC.

US Citizenship Required

Bachelor's, Master's

Category
Software Engineering (1)
Required Skills
Software Testing

Get referred to Splunk

See people who can refer or advise you

Requirements
  • A Bachelors or Master's, in Computer Science, Software Engineering, Computer Engineering, Electrical Engineering, Mathematics or a related technical field.
  • This is a US-based position. US Citizenship is required and you must be working on US soil to be considered.
Responsibilities
  • Develop and deploy software to enhance the availability, performance, and reliability of Splunk’s Clustering service, while ensuring full compliance with FedRAMP.
  • Establish and maintain processes for continuous monitoring and auditing of systems to ensure compliance with FedRAMP controls.
  • Automate the deployment of our services in new provider regions, including FedRAMP environments.
  • Design, develop, code and test software systems, or applications for software improvements and new products over an extended period of time.
  • Build innovative solutions that enable rapid development, including non-functional aspects such as performance, security, globalization, and accessibility.
  • Make an impact through your recommended modifications to processes and procedures, and directly contribute to standard methodologies, architecture, and implementation.
  • Collaborate with colleagues from other teams for cross-functional collaboration, such as Security, Compliance, Support, and Education.
  • Interact with internal and external customers to identify issues and potential solutions.
  • Work on legacy implementations under the team's ownership.
  • Participate in the hiring and onboarding of incoming interns.
  • Participate in 24x7 on-call rotation
Desired Qualifications
  • 2+ years of experience with one mainstream programming language, such as GoLang / Go or C++
  • Exposure to docker, Kubernetes, or public cloud platforms (e.g. AWS, GCP, Azure)
  • Demonstrated experience working with REST APIs
  • Experience working with relational or non-relational databases.
  • Experience with test-driven development, writing various levels of automated tests, such as unit test, functional test, integration test, system test, or performance / load test
  • Understanding of CI/CD
  • Familiarity with modern version control system, such as Git
  • Experience building meaningful software applications: in a class, as a personal hobby, as a job, as part of an open source project
  • Strong communication skills, verbal and written

Splunk analyzes large sets of machine data from IT systems, IoT devices, and security tools to provide real-time insights through its Data to Everything platform. It collects, searches, analyzes, and visualizes data so teams can monitor infrastructure, detect issues, and make informed decisions quickly. It differentiates itself by ingesting diverse data sources across IT, security, and business analytics, offering cross-domain visibility and security insights at scale, with integrations to technologies like Palo Alto Networks and Cisco. Its goal is to help organizations improve operational efficiency and security posture by turning data into actionable insights.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

San Francisco, California

Founded

2003

Get referred to Splunk

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Agent Launchpad reaches general availability on Splunk Cloud Platform in Fall 2026.
  • Cisco added Federated Search for Snowflake, Azure, and S3, reducing data-movement friction.
  • RSAC 2026 SOC saved nine analyst hours using Splunk SOAR workflows.

What critics are saying

  • CVE 2026 20266 lets Splunk admins run arbitrary OS commands; patch 5.7.4 immediately.
  • CVE-2026-20253 enables unauthenticated RCE on Splunk Enterprise below 10.2.4 and 10.0.7.
  • Cisco Cloud Control can subsume Splunk's standalone identity, shrinking direct product pull by 2027.

What makes Splunk unique

  • Cisco embeds Splunk into Cisco Cloud Control, unifying security, observability, and AI workflows.
  • Splunk Enterprise Security, SOAR, and Observability Cloud span SOC, IT, and engineering teams.
  • Agent Launchpad builds governed no-code agents directly from searches, alerts, and approved tools.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental and vision insurance plans for regular, full-time U.S. employees — choose the best plans for you and your family. Plus: Health Savings Account (HSA), Life insurance and survivor benefits, Flexible Spending Accounts (FSA), Business travel and accident insurance, Voluntary Critical Illness & Hospital Indemnity

Eligible employees enjoy: 401(k) Plan with a company match, Employee Stock Purchase Plan (ESPP), Equity awards, Bonus or commission program

We support you and your family: Paid parental leave, Mother rooms and wellness rooms, Family Planning

Your work/life balance is important to us, that's why we offer: 16 company holidays, 15 vacation days, 10 sick days, 10 bereavement days, 5 volunteer days

Ensuring our employees' success goes beyond insurance plans: Education reimbursement, Electric car charging stations, Employee Assistance Program (EAP), Stocked kitchens, Gym discounts/onsite fitness centers, Pet insurance discount, Student loan resources, Cool workspace with collaborative environments, 529 College Savings Plan

Growth & Insights and Company News

Headcount

6 month growth

2%

1 year growth

2%

2 year growth

4%
Silent Push
Aug 12th, 2026
What Does preemptive cyber defense Look Like inside an AI SOC?

What Does preemptive cyber defense Look Like inside an AI SOC? August 12, 2026 An agent can move fast, but without intelligence that already knows what's coming, it can't move early. Security Operations Centers (SOCs) everywhere are being asked to do more with agentic tools. Copilots triage alerts while agents pull context, enrich indicators, and draft investigation summaries before an analyst opens the ticket. While the promise is speed, it's wise to remember that the risk of speed lies in stale or reactive data, which just produces faster wrong answers. A key concern is that adversaries operate on a timeline that security tools often don't track: the preparation phase, when infrastructure is staged weeks before an attack goes live. Silent Push preemptive cyber defense was built to cover that window, and this post explores what happens when that data feeds directly into the AI-assisted workflows SOCs are already building. The problem with feeding AI reactive data. An agent that enriches an indicator is only as reliable as the source it queries. If that source is a traditional Indicator of Compromise (IOC) feed, the agent is enriching evidence of a compromise that has already happened. And while it can move fast, it's still working the wrong end of the timeline. Silent Push Indicators of Future Attack(R)(IOFA) invert that by mapping adversary infrastructure continuously across DNS, IP ranges, behavioral fingerprints, and web content, scanning hundreds of millions of data points to surface staging infrastructure before a campaign deploys. When an agentic workflow queries that data, it isn't merely enriching faster; it's enriching earlier. Agentic enrichment, without the syntax. The Silent Push MCP Server puts that intelligence directly into the tools practitioners use, including Claude and Cursor. An analyst or an agent can ask a plain-language question about an indicator, a domain, or a pattern of infrastructure and receive a deterministic answer. There's no Silent Push Query Language (SPQL) to write out and no separate console to learn. This begins to matter more as SOCs lean on agents to do first-pass triage. An agent pulling from the Context Graph inherits clear data provenance and a queryable structure built for automated enrichment from day one, with 200+ API endpoints designed for this kind of machine-to-machine workflow. The output an analyst reviews is something they can act on, not something they have to re-verify from scratch. Plugging into your existing SOC workflow. None of this requires ripping out the stack. Given the tool sprawl analysts face, its platform is designed for where it's needed most. Silent Push integrates directly into Splunk, Palo Alto XSOAR, Swimlane, Tines, ThreatConnect, Torq, and Sumo Logic. IOC feeds, domain and IP reputation scoring, and SPQL-powered queries flow into existing SIEM and SOAR playbooks. The agentic layer sits atop infrastructure that a team has already invested in. Since preemptive defense within a SOC isn't a new operating platform, it provides earlier-validated context that feeds into playbooks and workflows already in place. What Does This Look Like by Role? | / | The SOC Manager. Your SIEM and SOAR are already ingesting pre-validated, infrastructure-level context, so your team is triaging adversary infrastructure while it's being prepared. | | / | The CTI Analyst. Agentic enrichment is only as good as the pivots behind it. Weak pivots just automate bad guesses faster. Query fingerprints, cluster infrastructure, and threat actor patterns through the same interface your agents use, then export straight to your threat intel platform (TIP). | | / | The IR Lead. When an incident opens, scope is the first question. An agent querying the Context Graph can map an adversary's full staging infrastructure from a single indicator, so your team spends the first hour scoping the actual campaign instead of reconstructing it from fragments. | | / | The CISO. Agentic tools are under scrutiny, and the defensible answer to "What is the AI actually reasoning over?" is infrastructure-level data with a clear history, rather than a black-box feed. Instead of being a mere technical distinction, it's board-ready. | Proof that's not projection. Silent Push Inc. identified staging domains tied to Salt Typhoon in May 2025. Public reporting on the first intrusions didn't emerge until July 2025. Its data provided defenders with a two-month early-warning window that existed before most SOCs had a name for the campaign. This is the gap agentic enrichment is meant to close: not faster analysis of what has already happened, but earlier visibility into what's being staged, enabling organizations to take proactive measures before a threat actor's attack can land. Feeding an AI SOC earlier data can make it faster and, more importantly, right more often. Interested in learning more? Start a conversation with one of its platform experts to learn how preemptive cyber defense can give your team more lead time on adversary infrastructure, before an attack is launched. Silent Push Inc. also offer a free Community Edition so defenders can see how its platform integrates with their existing security stack. FAQs. 1. What is the primary function of an MCP server? An MCP server provides an AI model or agent with a standardized way to access external tools and data, without custom, one-off integration work for every platform it connects to. Instead of an agent needing code to query each different data source, it connects through the same protocol regardless of what's on the other end. For the Context Graph specifically, its MCP Server puts that intelligence directly inside the tools practitioners already use, including Claude and Cursor. An analyst or an agent can ask a plain-language question about an indicator, a domain, or a pattern of infrastructure and get a deterministic answer. There's no SPQL to write and no separate console to learn. 2. What is "agentic enrichment" and how does it work? Agentic enrichment occurs when an AI agent, not an analyst, pulls context for an indicator, a domain, or a piece of infrastructure mid-investigation. Instead of an analyst pausing to run a manual lookup, the agent queries a data source directly and folds the result back into whatever it's building: an alert summary, an investigation timeline, or a triage recommendation, in real time. The mechanism is straightforward. An agent, running inside Claude, Cursor, or another MCP-compatible tool, sends a plain-language query through the MCP Server, and the Context Graph returns a deterministic answer with clear data provenance. What makes that enrichment useful rather than just fast depends on what's on the other end of the query. Enrichment pulled from a traditional IOC feed still only reflects evidence of an attack that has already happened. Enrichment pulled from IOFA data is enriching a campaign before it launches. It's essentially the same mechanism, applied to a different point on the timeline, which is key in proactive defense.

NetFlow Logic
Jul 31st, 2026
When detection moves at machine speed, your data layer decides whether you win or lose.

When detection moves at machine speed, your data layer decides whether you win or lose. For two decades, detection and response ran at human speed: an alert fired, an analyst gathered context and acted, and the whole loop was paced by how fast a person could think. Agentic AI is collapsing that timeline. Attackers are beginning to move through environments faster than any human defender can follow, and defenders are responding with agentic detection and response of their own. At Cisco Live 2026, Splunk introduced Agent Builder, a no-code way to build agentic operations that run directly from Splunk searches and alerts, triaging and investigating at machine speed. When the loop moves to machine speed, the source of advantage shifts. The bottleneck is no longer the analyst. It is the data. An autonomous system that acts in seconds is only as good as the telemetry it acts on. If that telemetry is incomplete, unenriched, or late, the system does not fail slowly the way a human would. It fails fast, and it acts on the failure. Machine speed changes the cost of bad data. At human speed, thin telemetry is an inconvenience. An analyst working from a record of IP addresses and byte counts can compensate: resolve the user, check the destination, infer the application. The human is a buffer whose judgment absorbs the gaps. At machine speed, that buffer is gone. An autonomous system acts on what it is given, immediately. If the data lacks context, the system makes the wrong call as fast as it would have made the right one, then takes an automated action on it: blocking a legitimate user, isolating a healthy system, escalating a false alarm. Announcing Cisco's intent to acquire WideField Security, Splunk SVP and GM Kamal Hathi described exactly this risk: the agentic era introduced a new class of security problem in which authorized entities take unsafe actions in the wrong context, which can cause significant damage before any human team has a chance to respond. A human acting on incomplete data fails slowly and can catch the mistake. An autonomous system acting on incomplete data fails fast and acts on it. Machine-speed detection does not reduce the need for data quality. It raises the stakes on it. What machine-speed detection needs from network data. * Pre-enriched, not enrichable. User identity, application, threat intelligence, and geographic origin have to be in the record when it arrives, not available through a lookup the agent could theoretically run. An agent acting in seconds cannot afford the round trip. * Structured and consistent. Autonomous systems reason over data with predictable shape. Telemetry in inconsistent formats, or normalized on the fly, introduces the ambiguity that produces fast wrong decisions. * Timely and sustainable at volume. Machine-speed detection is continuous, and agentic workloads generate far more traffic than the human-era baseline. The data must arrive without lag and stay affordable to collect and retain at that scale. Raw NetFlow meets none of these. It is thin, it is binary and inconsistent across device types, and at agentic volumes it is expensive to move and store. That gap has to be closed before the data reaches the decision layer. Cisco has named this requirement directly. In the same WideField announcement, Hathi wrote that for agentic security operations that enable autonomous responses, it is imperative to have deterministic data pipelines that correlate telemetry from endpoints, identity systems, networks, and cloud in a format optimized for AI consumption. Network telemetry is one of those sources, and raw NetFlow is not in a format optimized for anything. Closing the gap before the decision layer. NetFlow Optimizer (NFO) sits between the network devices that export flow data and the systems that act on it, turning raw flow into telemetry that is ready the instant it arrives. It parses binary NetFlow, normalizes it to a common information model, enriches every record with identity, application, threat intelligence, and geographic context, and reduces volume by 80 to 90% through aggregation so continuous visibility stays sustainable as agentic traffic grows. The finished, CIM-compliant records are delivered to Splunk, Sentinel, Exabeam, Kafka, or another consumer. NFO does not detect, alert, analyze, or decide. It makes the decision layer possible by ensuring the data arriving there is complete, structured, and ready. The detection logic and autonomous response live downstream, where the organization builds and owns them. Why the data layer decides. As detection moves to machine speed, the decision engines converge. Autonomous response platforms and agentic frameworks are increasingly built on shared platforms and common patterns: Splunk's Agent Builder, for instance, is scheduled for general availability on Splunk Cloud Platform in Fall 2026, putting no-code agentic operations in reach of any team on the platform. When the engines are broadly available, what differs between organizations is the quality of the data those engines run on. Two organizations can deploy the same agentic platform. The one feeding it enriched, structured, timely network telemetry catches what the other misses, and acts correctly where the other acts wrongly. The engine is the same. The data layer is what makes it win or lose, which is why it deserves attention now, before the transition completes and there is no human buffer left to absorb its weaknesses. The bottom line. At human speed, an analyst's judgment compensates for thin data. At machine speed, that buffer disappears and the data becomes the deciding factor. Autonomous systems act on what they are given, instantly, right or wrong. NFO makes sure what they are given is enriched, structured, timely, and sustainable at scale. The decision engines will converge. The data layer is where the advantage lives. Preparing your SOC for machine-speed detection and response? Start a free 60-day trial of NetFlow Optimizer or schedule a technical demo.

DIGIT.FYI
Jul 24th, 2026
Sword achieves Splunk Advise Motion Elite status.

Sword achieves Splunk Advise Motion Elite status. Elizabeth Greenberg 24 July 2026, 10.55am "Being the first regional Splunk partner in the UK and Ireland to achieve Elite status is a fantastic achievement for Sword," Kevin Moreton, CEO of Sword UK, said. Sword has become the first regional Splunk partner in the UK and Ireland to achieve Elite status within the Splunk Advise Motion programme, recognising the company's proven consulting expertise, technical capability and track record of delivering successful customer outcomes. The achievement represents the highest level of accreditation within Splunk's Advise Motion programme and places Sword among a select group of partners recognised for their ability to help organisations maximise value from their data through advisory, consulting and professional services. Elite status is awarded to partners that can demonstrate deep technical expertise, accredited skills, established consulting practices and verified industry experience. The recognition reflects Sword's continued investment in developing specialist capabilities, supporting professional development and accreditations, and building a mature consulting practice that delivers measurable outcomes for customers. Sword works with organisations in highly regulated operations across critical national infrastructure including major energy and financial services providers. Through its partnership with Splunk, the company helps customers improve operational resilience, strengthen security, increase visibility across IT and operational technology environments, and make informed, risk-based decisions. Kevin Moreton, CEO of Sword UK, said: "Being the first regional Splunk partner in the UK and Ireland to achieve Elite status is a fantastic achievement for Sword. "It reflects the expertise of our people, the strength of our partnership with Splunk, and our commitment to delivering meaningful outcomes for customers operating in some of the most demanding and highly regulated environments." Recommended reading. Alexandra Turbitt, GVP, Partner Organisation and Digital Sales, EMEA, Splunk, shared: "Achieving Elite status further strengthens Sword's partnership with Splunk, a Cisco Company, and reinforces the company's commitment to helping organisations address complex operational, security and data challenges through a combination of technical expertise, industry experience and advisory-led services." Those interested in exploring these challenges further can register for Sword's upcoming webinar, Building Resilience Through Observability, taking place on 29 July at 1pm, where experts will discuss how real-time observability can help organisations strengthen resilience, support regulatory compliance and improve decision-making across complex IT and OT environments. Registration is available at Register for the webinar.

Exabeam
Jul 23rd, 2026
Exabeam vs. Splunk: which approach improves security operations outcomes?

Exabeam vs. Splunk: which approach improves security operations outcomes? * Jul 23, 2026 * Heidi Willbanks * 3 minutes to read Table of Contents Not every SIEM solution is built for modern security operations. While Splunk is widely used for log management, many teams face unpredictable pricing, complex tuning, and slow investigations as environments scale. New-Scale Fusion takes a different approach, It combines behavioral analytics, dynamic risk scoring, and coordinated AI agents to help teams detect risk earlier and move investigations forward faster. Here are six ways Exabeam improves outcomes compared to Splunk. 1. Predictable costs and clear value. Splunk cloud workload pricing model is complex and often unpredictable. Costs scale based on ingestion, storage, compute, and add-ons, which can lead to overages and rising spend as environments grow. Exabeam includes analytics, automation, and threat intelligence within New-Scale Fusion. As data volume increases, you gain more detection coverage and automation without layering on additional modules. Outcome: More predictable cost structure with increasing value over time. 2. Less tuning and operational overhead. Splunk requires continuous tuning. Analysts must maintain Splunk Search Processing Language (SPL) queries, build correlations, and reduce false positives through manual adjustments. Behavioral analytics capabilities are bundled into higher-tier offerings, increasing cost and complexity. Migration paths between legacy and newer capabilities can introduce additional operational risk. Exabeam reduces this overhead with: * Prebuilt detection coverage * Behavioral analytics for users, entities, and agents * Contextual correlation and automated workflows Analysts move from detection to investigation in a single interface without custom scripting. Outcome: Faster time to value and less reliance on engineering resources. 3. Strong behavioral visibility across humans, devices, and agents. Most modern attacks involve credential misuse or lateral movement. Rules alone are not enough to detect these patterns. Splunk provides behavior-based detection, but it often requires extensive tuning and operates outside a unified investigation workflow. Exabeam applies: ABA extends behavioral analytics to AI agents and non-human identities. It correlates activity across users, devices, and agents into a single investigation flow so analysts can understand how behaviors interact within an attack sequence. While Splunk can monitor agent activity and assign risk scores, it approaches this from an observability perspective. Exabeam integrates agent behavior directly into the investigation workflow, so all related activity is analyzed together. Outcome: Faster identification of high-risk behavior with unified investigation context. 4. Cloud-Native architecture built for scale. Splunk Cloud is a managed version of an architecture originally designed for on-premises deployments. Scaling often requires planning for storage, compute, and performance constraints. New-Scale Fusion is cloud native. It: * Processes high event volumes at scale * Unifies ingestion, parsing, analytics, and detection * Provides real-time visibility into service health and consumption OpenAPI Standard (OAS) support enables integration with broader security and IT ecosystems. Outcome: Consistent performance and visibility as data and complexity grow. 5. AI agents that drive investigation and detection outcomes. Splunk AI Assistant focuses on generating SPL queries and summaries. Its use is limited and often dependent on specific configurations. Exabeam Nova is a coordinated system of seven AI agents embedded into the detection, investigation, and response workflow: * Advisor Agent: Provides posture insights, MITRE ATT&CK(R) alignment, and prioritized recommendations through Outcomes Navigator * Search Agent: Converts natural language into Exabeam Query Language (EQL) aligned to the Common Information Model (CIM) * Visualization Agent: Build dashboards and charts from search results * Threat Scoring Agent: Applies adaptive learning to prioritize activity with dynamic risk scores * Investigation Agent: Generates summaries and recommends next steps * Analyst Assistant Agent: Surfaces evidence and guides investigators in real time * Rule Creator Agent: Translates natural language and observed attack patterns into correlation rules aligned to CIM and ATT&CK to accelerate detection coverage These agents work together within a unified workflow, reducing manual effort and improving investigation consistency. Outcome: Faster investigations, improved prioritization, and reduced analyst workload. 6. Measurable detection coverage with Outcomes Navigator. Security teams often lack visibility into whether their SIEM is detecting meaningful threats and how gaps translate to business risk. Splunk Security Essentials (SSE) is a content library that helps teams implement security use cases and map detections to frameworks like ATT&CK. While it highlights detection gaps, it provides limited visibility into exposure and only indirect insight into business risk. Outcomes Navigator delivers: * Detection coverage mapped to ATT&CK * Visibility into gaps and exposure * Prioritized recommendations aligned to business outcomes It continuously tracks detection performance and program maturity without requiring custom dashboards. Outcome: Clear visibility into detection coverage and next steps to reduce risk. Conclusion. Log search alone can't meet the demands of modern security operations. Exabeam combines behavioral analytics, dynamic risk scoring, automated timelines, and AI agents to detect hidden risk in human, device, and agent activity. You gain a unified investigation workflow, faster response times, and measurable improvements in your security program without needing to rebuild your entire stack. Download the full comparison guide to see how to reduce cost, improve detection coverage, and accelerate investigations. Heidi Willbanks. Heidi Willbanks | Senior Product Marketing Manager, Content | Exabeam | Heidi Willbanks leads content strategy and go-to-market execution at Exabeam, focusing on product launches, cybersecurity solutions marketing, and technical alliances. She has 20+ years of marketing experience, including over a decade in information security and data privacy, and holds a Level IV certification from Pragmatic Institute. Heidi specializes in creating clear, technically accurate content for security practitioners and decision-makers. Learn about the Exabeam platform and expand your knowledge of information security with its collection of white papers, podcasts, webinars, and more.

Cisco
Jul 1st, 2026
Ten years in the SOC at RSAC: what we learned in 2026.

Ten years in the SOC at RSAC: what Cisco Systems learned in 2026. Cisco Security and Splunk Security released the Findings Report from the Security Operations Center at RSAC 2026 Conference. This year marked the 10th year of the SOC at RSAC. Since 2017, the mission has stayed consistent: protect the conference network, educate attendees about what happens on an open wireless network, and innovate with new integrations, workflows, and security operations practices. The 2026 SOC was also an important step toward something bigger. Cisco Systems were not yet operating a fully agentic SOC at RSAC 2026, but the foundation was taking shape: integrated telemetry, automated escalation, full packet evidence, AI-protected workflows, and a closed-loop operating model between Cisco XDR and Splunk Enterprise Security. Those lessons helped inform the Agentic SOC work that followed at Cisco Live Americas 2026. RSAC is a uniquely valuable environment for learning. The Moscone Center wireless network is open and unsecured, similar to the networks people use every day in hotels, airports, coffee shops, and major events. The SOC does not decrypt encrypted traffic. Instead, the team uses network telemetry, DNS visibility, packet capture, threat intelligence, and integrated security tools to identify risk, investigate suspicious activity, and help attendees better protect themselves. For RSAC 2026, the team deployed the SOC in a Box architecture, connecting Endace full packet capture, Splunk Enterprise Security, Cisco XDR, Cisco Secure Firewall, Cisco Secure Access, Cisco AI Defense, ThousandEyes, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Cisco Talos intelligence, and partner (alphaMountain, Pulsedive and StealthMole) and community threat intelligence sources. The full report includes the details, but a few themes stood out. First, integration changed how the SOC worked. Cisco XDR supported efficient triage and correlation, while Splunk Enterprise Security supported deeper investigation, hunting, enrichment, and reporting. Splunk SOAR helped connect the workflow so that context could move between systems instead of forcing analysts to manually re-enter evidence or switch consoles to understand what happened. Second, automation reduced toil. Cleartext credentials continued to appear on the network, but the team advanced the response model from standalone scripting to an integrated Splunk SOAR workflow. Detections became formal findings in Splunk Enterprise Security, and the playbook could notify affected users, update the finding, and close the case. That saved more than nine hours of analyst time during the event and created a repeatable model for future conferences. Third, encrypted traffic remained both a success and a challenge. Encryption helps protect attendee privacy, and the SOC does not decrypt attendee traffic. But defenders still need ways to identify threats. Cisco Secure Firewall's Encrypted Visibility Engine helped the team find meaningful signals in encrypted sessions without decryption, including activity that supported a malware investigation and response. Fourth, AI became part of the security story in two ways. The SOC used Cisco AI Defense to gain visibility into generative AI application usage and to help protect on-premises AI models running in the SOC in a Box. At the same time, the team observed that AI demonstrations and agentic applications can introduce risk when they are built or operated without basic secure communication controls. Finally, the human mission of the SOC remained the same. The report includes examples of accidental data exposure, insecure email, unsecured web applications, misconfigured access paths, exposed storage, phishing infrastructure, scam domains, and malware investigations. In each case, the goal was not only to detect the issue, but to help RSAC and affected attendees understand and reduce the risk. That is why the full Findings Report matters. It is not just a list of alerts. It is a field report from a live, high-pressure SOC operating in a real conference environment, where technology, process, automation, AI, and human judgment all have to work together. Download the full RSAC 2026 SOC Findings Report to see the architecture, metrics, investigations, lessons learned, and recommendations from the 10th year of the SOC. The core advice remains simple: encrypt, encrypt, never trust, and always verify. Its thanks to the engineers, analysts and partners who made the SOC possible. Director, Security Operations.

INACTIVE