Full-Time

Information Security Operations Engineer

Vulnerability Management, Threat Hunting

Posted on 10/3/2025

Cisco

Cisco

10,001+ employees

Networking hardware, security software, collaboration services

No salary listed

Bengaluru, Karnataka, India

In Person

Category
IT & Security (1)
Required Skills
TCP/IP
PowerShell
Bash
Microsoft Azure
Python
Wireshark
AWS
JIRA
Splunk
Linux/Unix
Requirements
  • Bachelors or Master’s degree in information security or equivalent with minimum 10 years of Security Operations experience
  • Demonstrated ability administering and operating security tooling such as Nessus, OSQuery, Splunk, Burpsuite, Nmap, Wireshark, Falco, Tenable, Wiz.io, etc.
  • Thorough technical expertise in administrating/operating and supporting various public cloud technologies including AWS, Azure and GC
  • Ability to create custom correlation rules to detect known or suspected malware traffic patterns within security tools
  • Packet-level knowledge of TCP/IP protocols and network applications and an understanding of TCP/IP routing behaviors
  • Certifications such as CEH, Splunk, CISSP, Cloud Certs – AWS/GCP/Azure
  • Understanding of regular expression and expertise in various query languages including Splunk and Jira.
  • Demonstrated experience operating in regulated environments and ensuring incident response activities are aligned with compliance requirements.
  • Familiarity with and ability to support incident response practices aligned with SOC 2, IRAP, ISO/IEC 27001, NIST 800-53, HIPAA, and other relevant regulatory standards.
  • Experience analyzing events or incidents to triage the issue, find the root cause through log and forensic analysis, and determine security vulnerabilities, attacker exploit techniques and methods to construct the appropriate remediation.
  • Experience developing playbooks, run books, solve technical issues, and recognize and identifying patterns to reduce ticket volume
  • Ability to write scripts (e.g., Python, PowerShell, Bash) to automate tasks.
  • Strong knowledge of security standard methodologies, principles, and common security frameworks. Such as MITRE ATT&CK, NIST, ISO 27001, OWASP-Top 10, CIS benchmarks.
  • Knowledge of TCP/IP, AI tools, CVSS, Linux, Virtualization, Containers
  • Strong communication, organizational, and problem-solving skills in a dynamic environment
  • Effective documentation skills, to include technical diagrams and written descriptions
  • Ability to work independently and as part of a team with professional demeanor.
Responsibilities
  • Monitor SIEM for alerts and anomalies. Identify and triage potential security incidents (e.g., malware infections, phishing, data ex-filtration).
  • Lead investigations into confirmed incidents. Contain, eradicate, and recover from security events. Coordinate with internal stakeholders to implement remediation. Collect and preserve evidence for internal investigations or potential legal action. Contribute to incident response teams, maintaining relevant communication in emails, ticket summaries, analysis and reporting. Work with Incident handlers to provide recommendations for remediation of compromised systems and any relevant countermeasures.
  • Perform threat hunting to proactively identify risks. Analyze indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs).
  • Develop and enhance incident response playbooks. Identify opportunities for automation to streamline incident handling.
  • Lead post-incident reviews (PIRs), documenting lessons learned. Recommend and track corrective actions to prevent recurrence. Be able to translate incident response outcomes into documentation and reports to satisfy audit and compliance reviews.
  • Monitor various security blogs, alerts and notifications, RSS feeds and forums to keep abreast of the latest security news, attacks, threats, vulnerabilities and exploits.
  • Applying the output of threat hunts into new detections and gap assessment
  • Build automated log correlations in Splunk or a similar tool to identify anomalous and potentially malicious behavior.
  • Review, create or document standard operating procedures, recommendations, projects specific documents and resource guides as needed.
  • Supervise vulnerabilities and work with engineering teams to drive proper mitigations.
  • Supervise security operations queues to ensure timely triage of operations events and requests
  • Supervise global vulnerability feeds, assess impact to the business and respond promptly.
  • Participate in security incident investigations and retrospect on security events
  • Ensure all required logging is enabled and collected in SIEM tool
  • Participate in on-call rotations as needed to support continuous monitoring needs that may lay outside of business hours.

Cisco designs and sells networking hardware, software, and services that help organizations connect, protect, and manage data. Its products include networking gear, security solutions, cloud services, and collaboration tools like Webex to support hybrid work. Cisco differentiates itself with a broad, integrated stack—routing and switching, security, cloud, and collaboration—that works together at scale. Its goal is to help customers securely connect people, devices, and applications, enabling reliable communication and digital transformation across enterprises of all sizes.

Company Size

10,001+

Company Stage

IPO

Headquarters

San Jose, California

Founded

1984

Simplify Jobs

Simplify's Take

What believers are saying

  • Networking revenues surged 21% YoY to $8.29 billion in Q2 FY2026 from AI infrastructure demand.
  • Six consecutive quarters of 20%+ networking orders driven by Wi-Fi 7 and campus upgrades.
  • JPMorgan raised price target to $96 citing AI growth in servers, switches, and optics.

What critics are saying

  • Arista erodes Cisco's share in high-performance Ethernet switches for AI data centers within 12 months.
  • HPE's Juniper acquisition undercuts Cisco's SASE offerings, accelerating defections in 6 months.
  • BWG Global downgrade reveals weakening demand for Cisco's legacy campus gear in 3 months.

What makes Cisco unique

  • Cisco's $28 billion Splunk acquisition integrates data analytics with ThousandEyes for $31.4 billion ARR.
  • Cisco open-sourced AI-BOM tool tracking 150 models to combat shadow AI security risks.
  • Cisco's Universal Quantum Switch connects incompatible quantum systems at room temperature with <4% degradation.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Paid Vacation

Hybrid Work Options

Flexible Work Hours

Professional Development Budget

Company News

Dolphin Publications
Apr 10th, 2026
Cisco acquires Galileo to strengthen Splunk's AI observability capabilities

Cisco is acquiring Galileo, an AI observability specialist, to strengthen Splunk's position in the AI monitoring market. The deal is expected to close in July 2026. Galileo provides tools to evaluate AI output quality, detect errors before they reach users, and improve AI agent behaviour in production. The platform monitors hallucinations, bias, security risks and cost metrics across the entire agent development lifecycle, offering real-time observability for multi-agent systems. The acquisition will integrate Galileo into Splunk Observability Cloud, expanding existing AI agent monitoring capabilities. Galileo offers over 20 evaluation metrics including hallucination detection and supports major AI platforms like OpenAI, Anthropic, Azure OpenAI and AWS Bedrock. Cisco and Galileo previously collaborated on Cisco's AGNTCY initiative. Both companies will operate independently until the deal closes.

SiliconANGLE Media
Apr 10th, 2026
Cisco buys Galileo to strengthen Splunk’s agentic monitoring capabilities

Cisco buys Galileo to strengthen Splunk's agentic monitoring capabilities - SiliconANGLE

Yahoo Finance
Apr 10th, 2026
Cisco joins Project Glasswing with Anthropic and Amazon to detect software vulnerabilities using AI

Cisco Systems has joined Project Glasswing alongside Anthropic, Amazon and other tech companies to detect software vulnerabilities using advanced AI models. The collaboration includes early access to Anthropic's Claude Mythos Preview and has already identified security flaws missed by existing tools. The initiative aligns with Cisco's strategy of integrating AI-driven security capabilities into its networking and collaboration products. For investors, the partnership positions Cisco to address software risks for large enterprise and government customers as AI reshapes cybersecurity. Cisco shares currently trade at $83.17, approximately 7% below the analyst target of $89.04. The company has raised $295 million to date, with recent 30-day returns of roughly 7%. Success depends on real-world effectiveness and maintaining customer trust in AI-based defences.

Yahoo Finance
Apr 6th, 2026
Cisco appoints former Deloitte executive Pete Shimer to board of directors

Cisco has appointed Pete Shimer to its board of directors, effective immediately. Shimer will serve on the board's Audit Committee. Shimer brings 40 years of executive leadership experience from Deloitte, where he held C-suite positions including chief operating officer, chief financial officer and interim chief executive officer. His expertise spans enterprise transformation, strategic planning and digital innovation. He currently serves on the boards of Alaska Airlines, Korn Ferry and Synopsys, and is executive chair of the Cancer Artificial Intelligence Alliance. Shimer holds a Bachelor of Arts degree in Accounting from the University of Washington. Cisco chair and CEO Chuck Robbins said Shimer's experience leading global organisations and guiding digital transformation brings valuable insight as Cisco delivers infrastructure for AI innovation.

Yahoo Finance
Apr 6th, 2026
Cisco beats Q4 revenue estimates with $15.35B, stock falls 7.6% amid sector downturn

Applied Digital topped Q4 IT services and tech stocks, while the sector overall saw revenues beat analyst estimates by 5.3%. The 20 tracked companies reported strong results, though share prices averaged a 10.4% decline following earnings announcements. Cisco reported revenues of $15.35 billion, up 9.7% year on year, exceeding analyst expectations by 1.5%. The networking equipment maker delivered a strong quarter with revenue guidance surpassing forecasts. CEO Chuck Robbins highlighted the company's portfolio strength and its role in connecting and protecting customers. Despite positive results, Cisco's stock fell 7.6% post-earnings to $79.08. The IT services sector faces growth opportunities from cloud adoption and AI-driven automation, whilst navigating challenges including competition from cloud-native providers and supply chain constraints for networking hardware.

INACTIVE