
Sr. Staff Software Engineer, Splunk Security Core AI, Agentic SOC (hybrid)
Cisco · 2 Locations
Job description
The application window is expected to close on: 11/30/2026This is a hybrid role, with an on-site requirement for San Jose or San Francisco offices. Build the next generation Agentic SOC for a world where threats are created, adapted, and launched at machine speed. As adversaries increasingly use AI to accelerate attacks, security teams need more than better tools. They need intelligent systems that can reason across complex security data, recognize known and emerging threats, investigate at scale, and work alongside humans to take decisive, governed action. Meet the Team As a Senior Staff Software Engineer on Cisco’s Security Core AI team, you will help turn that vision into reality. You will build the shared platforms, orchestration, and evaluation systems that enable trusted AI agents across Cisco and Splunk security products. Your work will define how agentic security operates across public cloud, on-premises, sovereign cloud, and air-gapped environments, where reliability, control, auditability, and customer trust are non-negotiable. This is an opportunity to help reinvent how security operations work, translating rapid advances in AI into durable capabilities that give defenders the speed and leverage to meet a new generation of threats. Your Impact • Shape technical direction and lead ambiguous, cross-team Agentic SOC capabilities from concept through measurable production improvement. • Design and build reusable capabilities spanning agent runtime, orchestration, governed tool use, context and memory, evaluation systems, trace analysis, and quality gates. • Translate SOC, SIEM, detection, incident, investigation, and response needs into shared mechanisms in partnership with security-domain experts. • Design agents and supporting systems for grounded reasoning, planning, delegation, human oversight, traceability, auditability, and safe failure handling. • Define measurable success criteria for AI capabilities, including task completion, groundedness, tool-use correctness, trajectory quality, human intervention, safety, latency, cost, and reliability. • Establish closed-loop, metrics-driven development using golden datasets, offline and online evaluations, production traces, SME and customer feedback, experiments, and regression gates. • Connect AI quality metrics to production behavior and customer outcomes, identifying signals that are incomplete, misleading, or vulnerable to optimization without meaningful improvement. • Architect for public cloud, on-premises, sovereign cloud, and air-gapped environments, addressing data residency, restricted connectivity, local model and tool availability, packaging, upgrades, and resource constraints. • Establish patterns for identity propagation, authorization, tenant isolation, policy enforcement, privacy, auditability, and permission-aware actions. • Evaluate, integrate, and drive adoption of technologies across Splunk and Cisco, contributing Security requirements and reusable improvements. • Leverage AI tools throughout requirements, design, coding, review, testing, documentation, debugging, release, and production improvement, with appropriate human validation and security, privacy, and intellectual-property controls. • Diagnose failures spanning models, prompts, tools, data, orchestration, services, infrastructure, and product integrations. • Remain hands-on in implementation and design reviews, raise engineering standards, and mentor and influence senior engineers across teams. Minimum Qualifications • 6+ years of experience developing, testing, and/or operating production software. • Experience building and/or operating large-scale distributed or AI-enabled production systems, with experience programming with Python or Go. • Bachelors + 10 years of related experience, or Masters + 6 years of related experience, or PhD + 3 years of related experience. Preferred Qualifications • Experience with LLM and agentic-system concepts including grounding, planning, tool use, memory, human oversight, evaluation, tracing, and regression analysis. • Demonstrated experience defining AI metrics, building evaluation and experimentation loops, and connecting offline results to production behavior and customer outcomes. • Experience delivering software across public cloud, on-premises, sovereign cloud, or air-gapped environments. • Familiarity with SOC, SIEM, detections, incidents, investigations, response, identity, policy, privacy, and auditability. • Demonstrated success leading cross-team technical initiatives, adopting shared technologies, mentoring senior engineers, and using AI responsibly throughout the software development lifecycle. Why Cisco? At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you. Message to applicants applying to work in the U.S. and/or Canada: The starting salary range posted for this position is $214,100.00 to $309,800.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process. U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time. U.S. employees are eligible for paid time away as described below, subject to Cisco’s policies: 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees Exempt employees participate in Cisco’s flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations) 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next Additional paid time away may be requested to deal with critical or emergency issues for family members Optional 10 paid days per full calendar year to volunteer For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco’s policies. Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subjec
Verified and listed by ActiveJobs. Applications are made directly on Cisco's own career page — we never sit in the middle.