Threat Hunting Investigator (TS/SCI)

Cisco
North Carolina

Application window is expected to close by 08/25/2025.

Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.

Existing or previous Government Security Clearance is required with ability to obtain TS/SCI.

Work must be completed onsite in a secure space at our RTP office. No Hybrid or Remote.

Meet the Team

Cisco's Security Visibility and Incident Command (SVIC) forms part of the investigative branch of Cisco's Security and Trust Organization (S&TO) and is Cisco's cyber investigations and forensics team. It provides Cisco with tailored security monitoring services in order to protect Cisco from cyber-attacks and the loss of its intellectual assets. The primary mission of SVIC is to help ensure company, system, and data preservation by performing comprehensive investigations into computer security incidents, and to give to the prevention of such incidents by engaging in dedicated threat assessment, mitigation planning, incident trend analysis, and security architecture review.

The SVIC is a highly-functioning, diverse, and globally distributed group of best-in-class professionals from various technical backgrounds. We're Open-Source Software contributors, technical authors, tool builders, DFIR community members, lock pickers, makers, and breakers.

Your Impact

SVIC is looking for an experienced security professional to join the Computer Security Incident Response Team. This is an opportunity to contribute to a highly transparent security operations function with global impact upon Cisco, its diversified business, business units, service ventures, partners, and customers. We are looking for a motivated individual with good team fit and the ability to focus on data security and incident analysis. You have a very strong interest in complex problem solving, ability to challenge assumptions, consider alternative perspectives, nimble thinking and perform in high-stress situations, while operating exceedingly well in a strong, tight-knit, collaborative team environment.

Responsibilities Include

  • Document cases, procedures, analysis, and investigations accurately and thoroughly (including best-practice documentation).
  • Assist with setup and tuning of multiple security monitoring products and data feeds
  • Collaborate with data source SMEs in SVIC and InfoSec to enhance, improve, or modify cloud (IaaS, SaaS, etc) based security detection and response.
  • Update, modify, and enhance existing programs used for security detection and response.
  • Develop documentation on all custom solutions.
  • Identify attackers and their methods but also use your IT and networking expertise to improve detection logic.
  • Occasional travel (<10%)

Attack Analysis

  • Attacker Tools, TTPs
  • Log Analysis (System, Firewall, Application

Cyber Threat Intelligence

  • Threat Hunting
  • Intelligence Analysis
  • Attacker Methodology
  • Industry Peer Collaboration & Information Sharing

Incident/Investigations Handling

  • CyberSecurity Impact Assessment
  • CyberSecurity Problem Management
  • Automation/SOAR
  • Root Cause ID / LTF

Minimum Qualifications

  • 4 + years of Cybersecurity or IT security related work experience.
  • Python scripting/coding experience
  • Experience with any three or more of the following tools: Splunk , CSE(AMP4E), Network AMP, WSA, Firepower IPS , NGFW, ESA, CTA, Threat-Grid , Secure Network Analytics (formerly Stealthwatch) , Umbrella, SecureX, OSQuery, Threat-Quotient, MISP, Recorded-Future, Volatility, Powershell, Wireshark, Encase, Tableau, TheHive
  • Must have Experience with Log Analysis (System, Firewall, Application)

Preferred Qualifications

  • Good technical skills in a variety of operating system, languages, and databases
  • Experience with - Go, Java, JavaScript, SQL, MySQL, STIX/TAXII AND/OR MITRE ATT&CK
  • Certifications GSEC, GCIA, GISF, GCED, GCFA, GCFE, GREM, GCTI, GASF, GCEH, CISSP, CCSP OR SSCP
  • Cloud experience with AWS or Azure.
  • Agility and willingness to deal with a high level of ambiguity and change
  • Flexibility – willingness to pitch in where needed across program and team

Why Cisco?

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Simply put – we power the future.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with

empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.

We are Cisco, and our power starts with you.

#STO25 STO25

Posted 2025-08-19

Recommended Jobs

Industrial Electrician

Kellanova
Cary, NC

Do you have a spark for tinkering with electrical and mechanical components? We have an opening in our state-of-the-art facility for an   Industrial Electrician   in Cary, NC. This is an overnight sh…

View Details
Posted 2025-08-19

RTP EM Tech

Medasource
Durham, NC

Summary: The QC Environmental Monitoring Technician will perform routine and investigational environmental monitoring of classified manufacturing, filling, and support areas. Support daily EM labor…

View Details
Posted 2025-08-07

Senior Food Supervisor

Sodexo
Greensboro, NC

Location Name: NORTH CAROLINA AGRICULTURAL AND TECHNICAL STATE UNIVERSITY - 94021007 Location ID: 94021007 Senior Food Supervisor Location: NORTH CAROLINA AGRICULTURAL AND TECHNICAL STATE…

View Details
Posted 2025-07-28

Rebar Fabricator

CMC
Charlotte, NC

it's what's inside that counts _______________________________ There’s more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it’s the people inside our re…

View Details
Posted 2025-08-19

Travel Physical Therapist (PT) Acute Care

Critical Connection, Inc.
Roxboro, NC

CCI needs a Physical Therapist (PT) Travel/Local needed for an Acute Care Hospital in Roxboro, NC. Great for a travel pair! 2 PT's Needed! ~$2000 - $2100 - net weekly take home. ~ Local Contrac…

View Details
Posted 2025-07-30

Cook

Selwyn Avenue Pub
Charlotte, NC

We have an extraordinary opportunity for an experienced Line Cook to join our talented team. We offer flexible hours and can accommodate people looking for full or part time employment. Payroll is pro…

View Details
Posted 2025-08-06

First grader babysitter in Chapel Hill required

Wyndy
Chapel Hill, NC

Pay: $18 - $26 per hour Start Date: Anytime Location: Chapel Hill, NC Job Description First grader babysitter needed for a warm and loving family. Must have a genuine passion for childc…

View Details
Posted 2025-08-19

Substance Abuse Nurse

Coastal Horizons Center
Wilmington, NC

Job Description Job Description At Coastal Horizons , our mission is to provide a continuum of professional services to promote healthier lives, stronger families, and safer communities. We a…

View Details
Posted 2025-07-25

Men's Team Lead

Louis Vuitton
Charlotte, NC

The Men's Team Lead at Louis Vuitton in Charlotte will act as a brand ambassador, supporting the Store Manager and/or Team Manager. This role involves coaching and developing the team, building client…

View Details
Posted 2025-07-29

Liaison Officer

MbSolutions Inc
Fort Bragg, NC

Job Description Job Description Individuals will serve as the senior Liaison Officer to the ASCC for Army Materiel Command (AMC), representing the command on all facets of the programs and polici…

View Details
Posted 2025-07-29