Start Your Search Here

push notification bell

Would you like to receive notifications about jobs in San Francisco?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

Cisco

San Francisco / Global

Staff Software Engineer - AI/Security Platform

Job Description

Cisco AI-Enhanced Security Operations EngineerWe are an agile team with a startup feel and a strong bias for action. We move fast, embrace failure as part of the process, and stay focused on solving real-world problems for defenders on the front lines. Our team blends deep expertise in AI, cybersecurity, platform and systems engineering. We are driven by a shared belief that the only way to outpace hackers is through AI advancements that free up humans to tackle real threats and more challenging problems.This is a place for builders who thrive in ambiguity, challenge the status quo, and care deeply about making a meaningful impact. If you're energized by tough problems, excited to shape the future of cyber defense, and eager to work alongside passionate experts, you'll feel right at home.Your ImpactDesign and build systems that combine security-relevant data, detection signals, context, and foundation models to spot and predict threats, those in action and those that are about to happen.Prototype and test new AI features - from decoding events and system environments to predicting anomalies and threats - working closely with security SMEs and security researchers to validate real-world utility.Develop an AI DevOps pipeline to enable rapid experimentation with data. Knowledge bases, models, and context memory, using clear, measurable success criteria to evaluate iterations.Architect and build the distributed platform that can correlate trillions of events & signals, and can synthesize them into explainable findings and alerts, consumed by our triage resolution agents – you will be building a key capability of the Agentic SOC.Collaborate with product and platform teams to co-design AI-enhanced threat detection and prediction workflows that are intuitive, scalable, and immediately useful to analysts.Contribute to the core architecture powering AI-native security operations, helping to shape how Splunk and Cisco scale trusted automation across the enterprise.Minimum QualificationsBachelor's Degree with 8+ years of related experience or Master's with 6+ years of related experience.Engineering Qualifications:Distributed Systems design and implementation - Experience with an emphasis on storage systems and storage access layersData Platform/Fabric - Experience implementing data platforms and/or data lakes and warehouses.Proficient Python Development - Experience building scalable backend services, APIs, and automation workflows in Python.DevOps/SecOps Practices - Experience, proficient with CI/CD pipelines, version control (GitHub/GitLab), Jira, and automated testing frameworks.Agentic development – Experience designing agent systems that will perform coding tasks for you.Cross-Functional Collaboration – Experience partnering with product managers, security SMEs, and engineers to iterate quickly and deliver impactful solutions.Security Qualifications:Security Telemetry Fluency – Experience working with common telemetry data sources such as endpoint logs, network traffic, authentication events, or cloud audit trails and understanding how they're used in detection and investigation workflows.Preferred QualificationsSecurity Data Engineering – Experience building and maintaining pipelines for ingesting, parsing, and normalizing large-scale security telemetry.Enterprise-grade Security Product Experience – Familiarity with TDIR/SIEM architectures, correlation searches, threat hunting support systems. Bonus if you've worked with Splunk's APIs, internals, or have experience developing on the Splunk platform.Security Operations Experience – Understanding of security operations concepts, including attack surface management, threat analytics, detection, triage, investigation, and response. Alternatively, former Tier 3 SOC analyst or equivalent, with experience automating SecOps workflows and building scalable, resilient detection infrastructure.Data Encoding & Embeddings – Exposure to event storage systems or generating custom embeddings for domain-specific tasks in cybersecurity.RAG and GraphRAG Search Implementation – Hands-on experience developing retrieval-augmented generation pipelines and working with databases (e.g., FAISS, Pinecone).Model Integration – Skilled in crafting, testing, and optimizing training workloads for large language or special-purpose models such as GNNs, GCNs, GATs. Ideally, you have contributed to or shipped an AI-powered feature or product and understand the nuances of integrating models into real-world workflows - including usability, performance, and trust considerations.AI Evaluation & Experimentation – Capable of designing experiments to evaluate model output for accuracy, usability, performance, and costUX and Human Factors for Analysts – Background or interest in designing intuitive, AI-assisted analyst workflows with a focus on usability, trust, and decision support.
Apply Now

Similar Opportunities

View all jobs

Get Job Alerts

Don't miss the perfect fit. Get Daily curated job alerts.

Job Title or Keyword(s)
Location