hero

The Storyboard

Welcome to the Storyboard, a place to explore career adventures at start-ups and companies founded by Claremont alumni and the Claremont community. Choose your next adventure at a company where you’ll have an edge from day one, and leverage our Claremont network to build your career.

Also, make sure to check out our newsletter, StoryHouse Review, to find out more about these companies in the Claremont ecosystem.

Threat Research Engineer - XDR

Cisco

Cisco

Austin, TX, USA
Posted on Jan 12, 2025

Application window is expected to close by 1/15/2025

The ideal candidate for this role will be located anywhere in the US

What You’ll Do

We are seeking a Threat Research Engineer to design and implement behavioral-based detections for implementation by customers in the XDR environment. The person will serve as a Threat Detection Engineer and primarily interface with Development with the objective of improving attack detection from disparate data across a wide data set.

Who You Are

This is a technical role for a subject matter expert (SME). The role involves projects or issues of high complexity that require in-depth knowledge across multiple technical operations areas and business segments. This is a unique position as it will report to Solution Engineering, but work cross-functionality; it's very important to be able to work across teams in a collaborative manner.

As a Threat Research Engineer you will be responsible for:

  • Capturing requirements and developing testing strategies to assess integrations and workflows in order to support Cisco XDR Customer needs.
  • Developing detections based on understandings of cross product alerts and telemetry events.
  • Articulate complex attack sequences, tools, tactics and procedures used by various threat actors into engineering and detection requirements.
  • Working with various product development team to build and maintain an end to end system to support current and future workflow needs.
  • Identify strategic integration opportunities with new and existing customers.
  • Stay current on security products and best practices, advise on products as needed.
  • Collaborate with teams from across the organization

Minimum Qualifications:

  • Expert level understanding of Attack Tactics, techniques and procedures.
  • Experience with SOC, NOC, TOC, Threat Intelligence and/or Managed Security Service (MSS) operations.
  • Experience implementing security orchestration, automation and response (SOAR) technologies.
  • Senior level understanding of data flow, data formatting/normalization, logging best practices and data parsing between security products.
  • Experience interfacing with, and capturing requirements from customers.
  • Experience with API integration across products, applications and network environments.
  • Technical writing & Documentation skills

Preferred Qualifications:

  • Understanding of design and user experience
  • Strong analytical and organizational skills.
  • Excellent verbal and written communication, problem-solving, and time-management skills.
  • Ability to work efficiently and productively with minimal guidance or direction.
  • Good understanding of query optimization against large data sources so as to not cause performance impacts to the system.

Why Cisco?

#WeAreCisco. We are all unique, but collectively we bring our talents to work as a team, to develop innovative technology and power a more inclusive, digital future for everyone. How do we do it? Well, for starters – with people like you!

Nearly every internet connection around the world touches Cisco. We’re the Internet’s optimists. Our technology makes sure the data traveling at light speed across connections does so securely, yet it’s not what we make but what we make happen which marks us out. We’re helping those who work in the health service to connect with patients and each other; schools, colleges, and universities to teach in even the most challenging of times. We’re helping businesses of all shapes and sizes to connect with their employees and customers in new ways, providing people with access to the digital skills they need and connecting the most remote parts of the world – whether through 5G, or otherwise.

We tackle whatever challenges come our way. We have each other’s backs, we recognize our accomplishments, and we grow together. We celebrate and support one another – from big and small things in life to big career moments. And giving back is in our DNA (we get 10 days off each year to do just that).

We know that powering an inclusive future starts with us. Because without diversity and a dedication to equality, there is no moving forward. Our 30 Inclusive Communities, that bring people together around commonalities or passions, are leading the way. Together we’re committed to learning, listening, caring for our communities, whilst supporting the most vulnerable with a collective effort to make this world a better place either with technology, or through our actions.

So, you have colorful hair? Don’t care. Tattoos? Show off your ink. Like polka dots? That’s cool. Pop culture geek? Many of us are. Passion for technology and world changing? Be you, with us! #WeAreCisco

Message to applicants applying to work in the U.S. and/or Canada:

When available, the salary range posted for this position reflects the projected hiring range for new hire, full-time salaries in U.S. and/or Canada locations, not including equity or benefits. For non-sales roles the hiring ranges reflect base salary only; employees are also eligible to receive annual bonuses. Hiring ranges for sales positions include base and incentive compensation target. Individual pay is determined by the candidate's hiring location and additional factors, including but not limited to skillset, experience, and relevant education, certifications, or training. Applicants may not be eligible for the full salary range based on their U.S. or Canada hiring location. The recruiter can share more details about compensation for the role in your location during the hiring process.

U.S. employees have access to quality medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, short and long-term disability coverage, basic life insurance and numerous wellbeing offerings.

Employees receive up to twelve paid holidays per calendar year, which includes one floating holiday (for non-exempt employees), plus a day off for their birthday. Non-Exempt new hires accrue up to 16 days of vacation time off each year, at a rate of 4.92 hours per pay period. Exempt new hires participate in Cisco’s flexible Vacation Time Off policy, which does not place a defined limit on how much vacation time eligible employees may use, but is subject to availability and some business limitations. All new hires are eligible for Sick Time Off subject to Cisco’s Sick Time Off Policy and will have eighty (80) hours of sick time off provided on their hire date and on January 1st of each year thereafter. Up to 80 hours of unused sick time will be carried forward from one calendar year to the next such that the maximum number of sick time hours an employee may have available is 160 hours. Employees in Illinois have a unique time off program designed specifically with local requirements in mind. All employees also have access to paid time away to deal with critical or emergency issues. We offer additional paid time to volunteer and give back to the community.

Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components. For quota-based incentive pay, Cisco typically pays as follows:

.75% of incentive target for each 1% of revenue attainment up to 50% of quota;

1.5% of incentive target for each 1% of attainment between 50% and 75%;

1% of incentive target for each 1% of attainment between 75% and 100%; and once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.

For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.