Point your AI agent at freehire and let it find you a job.

Get the CLI →

Cisco

NewBe an early applicant

Customer Delivery Architect | 10+ years, SOC transformation

Discussion

Meet the Team

Cisco Customer Experience (CX) Security Services is a global team of elite security practitioners, architects, and trusted advisors who help our largest enterprise and service provider customers defend against sophisticated threats, achieve operational cyber resilience, and accelerate digital transformation. As part of our specialized Security Operations Center (SOC) Transformation & Advanced Analytics practice, you will work alongside top-tier consulting engineers, automation developers, and solution architects to design and deliver next-generation SOC architectures, SIEM modernization, behavioral analytics, and end-to-end security automation.

Your Impact

As a Security Consulting Architect for SOC Transformation & Splunk, you will be the chief technical authority and visionary guiding our enterprise customers through complex SOC modernization journeys. You will translate customer business outcomes, risk profiles, and operational strategies into scalable, high-fidelity security architectures powered by Splunk Cloud, Splunk Enterprise Security (ES), Splunk SOAR, User & Entity Behavior Analytics (UEBA), Cribl Stream, and modern object storage (MinIO).

This is a high-impact, hands-on leadership role. You will engage with customer CISOs, SOC Directors, and Enterprise Architects to define target operating models and modernization roadmaps, while also leading implementation pods, troubleshooting deep technical roadblocks, optimizing search pipelines, and setting the engineering standards for multi-terabyte security analytics.

  • Target SOC Architecture & Transformation Strategy: Lead the architectural design, Target Operating Model (TOM), and delivery strategy for multi-tier enterprise SOCs, SIEM modernizations, and security automation frameworks aligned with MITRE ATT&CK and Cisco Validated Designs.
  • Splunk Cloud & Enterprise Security (ES) Mastery: Architect enterprise-scale Splunk Cloud deployments; design Risk-Based Alerting (RBA) frameworks, Data Model Acceleration (DMA) strategies, optimized | tstats search pipelines, Asset & Identity (A&I) contextual enrichment, and ESCU detection updates to eliminate alert fatigue.
  • Modern Telemetry Ingestion & Storage Architecture: Architect high-throughput, resilient security data collection pipelines leveraging Cribl Stream for edge transformation, filtering, and routing, combined with MinIO / S3-compatible object storage for high-performance SmartStore tiering and compliance data archiving.
  • Security Automation & SOAR Engineering: Define incident triage and response workflows, designing modular, production-grade Python playbooks in Splunk SOAR for automated threat enrichment (Talos, VirusTotal), endpoint containment (EDR isolation), firewall mitigation, and bidirectional ITSM (ServiceNow) synchronization.
  • Technical Pod Leadership & Governance: Provide technical direction, architectural governance, and mentorship to specialized engineering execution pods (Data Ingestion/GDI, Detection Engineering, UEBA, SOAR); serve as the hands-on escalation authority for complex SPL optimization, CIM normalization, and API integrations.

Minimum Qualifications

  • 10+ years of technical cybersecurity engineering and architecture experience designing and deploying enterprise Security Operations Center (SOC) environments and SIEM/SOAR platforms.
  • 5+ years of dedicated, hands-on architecture and engineering experience with Splunk Enterprise, Splunk Cloud, and Splunk Enterprise Security (ES), including correlation search engineering, Data Model Acceleration, and Risk-Based Alerting (RBA).
  • 3+ years of hands-on experience in security telemetry pipeline engineering, including log routing and normalization with Cribl Stream, data parsing (props.conf / transforms.conf), and object storage/SmartStore tiering with MinIO or S3-compatible cloud storage.
  • 3+ years of security orchestration and automation experience designing and building automated response playbooks using Splunk SOAR (Phantom), REST APIs, and Python
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical industry engineering experience.

Preferred Qualifications

  • Splunk & Pipeline Certifications: Splunk Enterprise Certified Architect, Splunk Enterprise Security Certified Admin, Splunk SOAR Certified Automation Developer, or Cribl Certified Observability Engineer (CCOE).
  • Industry Security Credentials: CISSP, CCIE Security, CISM, or GIAC certifications (GCIH, GCIA, GDSA, GMON).
  • Advanced Behavioral Analytics & Threat Modeling: Practical experience deploying Splunk UEBA, implementing machine learning models for anomaly detection, and conducting atomic detection testing against the MITRE ATT&CK matrix.
  • Executive Advisory & Technical Consulting: Exceptional C-suite consulting, presentation, and technical leadership skills with a proven track record of advising CISOs, leading technical workshops, and driving organizational change.
  • Hybrid Cloud & Multi-Vendor Ecosystem Integration: Deep knowledge of multi-cloud security logging, Next-Gen Firewalls (Palo Alto, Cisco Secure Firewall), EDR platforms (CrowdStrike, Microsoft Defender), and Cisco Security Cloud integrations.

Why Cisco?

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.

We are Cisco, and our power starts with you.


Disclaimer

To ensure that we hire the best talent in the right way, we follow a strict hiring process and recently, Cisco has been made aware of fraudulent recruiters claiming to be from the company. Please be advised that any communication from Cisco about careers will:

  • be in direct response to an application you have submitted through the company career site
  • begin with screening or an interview
  • originate from a Cisco email address, and
  • be conducted across email, phone, or WebEx

Cisco will never make a job offer without conducting an interview process or ask you for money in any way. If you have been requested to apply for a role or have received an offer from a site other than or cisco.wd5.myworkday.com, do not provide any personal identifying information, including your Aadhaar or other personal identifying number, birth certificate, banking information, driver's license, or passport.


If you are the target of a recruiting scam, consider filing a report with your local law enforcement authorities. Cisco bears no responsibility, and cannot be held liable, for any claims, damages, expenses, or other inconvenience resulting from or in any way connected to recruiting scams.


See also

Architecture jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available