Threat Hunting Detection Engineer
3 days ago
Meet the Team Cisco's Security Visibility and Incident Command (SVIC) forms part of the monitoring & response branch of Cisco's Security and Trust Organization (S&TO) and is Cisco's cyber investigations and forensics team. We provide Cisco with security threat detection, compliance monitoring, vulnerability discovery and response services to protect Cisco's digital landscape from attacks, abuse, reputational harm, and loss of its intellectual assets. The primary mission of SVIC is to help ensure system and data risk management by performing comprehensive investigations into cyber security incidents, and to assist in the prevention of such incidents by engaging in dedicated threat assessment, mitigation planning, incident trend analysis, and security architecture review. We are a highly-functioning, diverse, and globally distributed group of committed professionals from various technical backgrounds. We are Open-Source Software contributors, technical authors, tool builders, DFIR (Digital Forensics & Incident Response) community members, lock pickers, makers, and breakers Your Impact SVIC is looking for an experienced security professional to join our Cyber Detection Engineering Team. This is an opportunity to contribute to a highly visible security operations function with global impact upon Cisco, its diversified business, business units, service ventures, partners, and customers. We are seeking a motivated and analytical security specialist who thrives on understanding attacker methodologies to build robust and proactive detection capabilities. Our engineers excel at designing, developing, and deploying security detections that identify threats across complex systems. You have a strong interest in complex problem solving, with an ability to challenge assumptions and consider alternative perspectives while mastering the craft of security detection. You are forward-thinking and act as a key contributor in strengthening Cisco's defensive posture, operating exceedingly well in a strong, tight-knit, collaborative team environment. Responsibilities * Design, develop, and implement security detection rules, signatures, and use cases across various security platforms (SIEM, EDR, IDS/IPS, Cloud Native Security Tools). * Translate threat intelligence and adversary tools, tactics & procedures (TTPs) into actionable detection logic. * Perform continuous tuning and optimization of existing detection rules to reduce false positives and improve detection efficacy. * Collaborate with Threat Hunters and Incident Responders to understand emerging threats and incident patterns, incorporating lessons learned into new detection strategies. * Engage with data source & business SMEs (subject matter experts) in SVIC and InfoSec to build & improve methods for detecting security incidents in cloud (IaaS, SaaS, PaaS) environments. * Research and deploy modern technologies or enhancements to support business objectives related to security detection, threat hunting, forensics, and response. * Study how attackers operate and their methods, and use your IT and networking expertise to build & improve detection logic and investigative procedures. * Collaborate with your peers to evolve our operational processes & procedures towards improving efficiency & efficacy. * Cultivate expertise in the technical subjects you are passionate about, to guide SVIC towards better ways in achieving our mission. * Teach, mentor and support your peers in areas you have specialized knowledge or experience. * Represent SVIC in collaboration with industry peers and in trusted working groups. * Participate in a follow-the-sun on-call rotation. Minimum Qualifications * Minimum of 5-6 years of hands-on experience in security detection engineering, incident handling, or a closely related cyber security role. * Self-Starter, Go-Getter & Self-Learner. * Superb communication (verbal and written) skills. * Reasonable scripting/coding abilities (e.g., Python, PowerShell) and an eye for automation opportunities. * Networking Experience: A solid grasp of networking and core Internet protocols (e.g. TCP/IP, DNS, SMTP, HTTP, TLS and distributed networks). * Security Technology Experience: Extensive experience with security detection platforms such as SIEM (e.g., Splunk, Elastic, Sentinel), EDR (e.g., Cisco Secure Endpoint, CrowdStrike, SentinelOne), IDS/IPS, and Cloud Security Posture Management (CSPM) tools. * Cloud Experience: Experience or familiarity with the usage of cloud computing platforms & components, like - AWS, GCP, Azure, Docker, Kubernetes, etc., specifically in the context of cloud native detection. * Dev-Sec-Ops Experience: Experience or familiarity with integrating security into CI/CD pipelines and automating security controls. * IT Infrastructure Experience: Extensive knowledge of IT infrastructure services, Operating systems (Windows, Linux), and networking. * Identity Management Experience: Experience or familiarity with protocols & products used for authentication & authorization, like - Radius, Active Directory, LDAP, NTLM, Kerberos, SAML, OAuth, JWT, etc., and detecting abuse. * Experience in developing and deploying detection rules using formats like YARA, Sigma, or custom SIEM queries. * Experience in one or more data analytics platforms or languages like - Splunk, Elastic Stack, Kusto Query Language (KQL), Structured Query Language (SQL), etc., for log analysis and rule creation. Preferred Qualifications * Agility in managing multiple detection projects concurrently and a curiosity to learn about new threats and technologies. * Proven track record of designing and implementing effective security detections. * Flexibility - willingness to pitch in where needed across program and team, and outside typical business hours. * Ability to work shift hours as well as on-call out of hours. * Leadership, influence, and collaboration skills; sound problem resolution, judgment, negotiating and decision-making skills. At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Simply put - we power the future. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you.
Why Cisco?
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
-
Threat Detection Engineer
1 week ago
Bengaluru, Karnataka, India Millennium Full time ₹ 12,00,000 - ₹ 24,00,000 per yearThreat Detection EngineerThreat Detection EngineerDo you have a passion for hunting malicious activities in the background of business as usual and figuring out how to detect and respond to new threats?Millennium SOC is going through a transformation, we are looking for an experienced Threat Detection Engineer to drive our best-in-class posture. This is...
-
Threat Detection
6 days ago
Bengaluru, Karnataka, India Clarity Consulting Full time ₹ 40,00,000 - ₹ 1,20,00,000 per yearRoles and ResponsibilitiesDevelop expertise in Splunk Enterprise Security (SES) platform for threat detection.Collaborate with incident response team to respond to detected threats and minimize damage.Identify and investigate suspicious activity alerts from Splunk Enterprise Security (SES) platform.Conduct threat hunting activities using various techniques...
-
Bengaluru, Karnataka, India Triune Infomatics Inc Full time ₹ 20,00,000 - ₹ 25,00,000 per yearRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident ResponseWorking Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)Reporting To: Security Operations (SecOps) Leader – USAAbout the Role:We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven experience...
-
Security Engineer, Threat Detection
2 weeks ago
Bengaluru, Karnataka, India Workato Full time ₹ 15,00,000 - ₹ 25,00,000 per yearAbout WorkatoWorkato transforms technology complexity into business opportunity. As the leader in enterprise orchestration, Workato helps businesses globally streamline operations by connecting data, processes, applications, and experiences. Its AI-powered platform enables teams to navigate complex workflows in real-time, driving efficiency and...
-
Security Engineer, Threat Detection
2 weeks ago
Bengaluru, Karnataka, India Workato Full time ₹ 80,00,000 - ₹ 2,00,00,000 per yearAbout WorkatoWorkato transforms technology complexity into business opportunity. As the leader in enterprise orchestration, Workato helps businesses globally streamline operations by connecting data, processes, applications, and experiences. Its AI-powered platform enables teams to navigate complex workflows in real-time, driving efficiency and...
-
Thread Modelling/Hunting
2 weeks ago
Bengaluru, Karnataka, India Tata Consultancy Services (TCS) Full time ₹ 12,00,000 - ₹ 36,00,000 per yearKey ResponsibilitiesThreat Assessment & AnalysisReview and assess various cyber threat intelligence issues reported to the team.Analyze reported threats to determine authenticity and potential impact.For genuine threats, perform deep technical analysis to understand underlying technology aspects.Collaboration & ResolutionLiaise with relevant technology and...
-
Senior Detection Engineer
4 days ago
Bengaluru, Karnataka, India Vectra Full time ₹ 12,00,000 - ₹ 36,00,000 per yearVectra is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond...
-
Senior Detection Engineer
4 days ago
Bengaluru, Karnataka, India Vectra AI Full time ₹ 12,00,000 - ₹ 36,00,000 per yearVectra is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond...
-
Threat Hunting Investigator
2 days ago
Bengaluru, Karnataka, India Cisco Full time ₹ 12,00,000 - ₹ 24,00,000 per yearMeet the Team Cisco's Security Visibility and Incident Command (SVIC) forms part of the monitoring & response branch of Cisco's Security and Trust Organization (S&TO) and is Cisco's cyber investigations and forensics team. We provide Cisco with security threat detection, compliance monitoring, vulnerability discovery and response services to protect Cisco's...
-
Senior Threat Hunter
6 days ago
Bengaluru, Karnataka, India ColorTokens Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Title: Senior Threat HunterLocation: Bangalore (on site)Experience Level: 5 to 6 yearsAbout ColorTokensAt ColorTokens , we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform , companies can minimize the impact of breaches by...