Level

Cisco

Sr. Staff Software Engineer, Splunk Security Core AI, Agentic SOC (hybrid)

AI in this role

Build shared platforms, orchestration, and evaluation systems for agentic security operations and AI agents.

ai-agentsagentic-socorchestrationevaluation-systemsmachine-learningsecurity-operations
The application window is expected to close on: 11/30/2026

This is a hybrid role, with an on-site requirement for San Jose or San Francisco offices.



Build the next generation Agentic SOC for a world where threats are created, adapted, and launched at machine speed.


As adversaries increasingly use AI to accelerate attacks, security teams need more than better tools. They need intelligent systems that can reason across complex security data, recognize known and emerging threats, investigate at scale, and work alongside humans to take decisive, governed action.


Meet the Team


As a Senior Staff Software Engineer on Cisco’s Security Core AI team, you will help turn that vision into reality. You will build the shared platforms, orchestration, and evaluation systems that enable trusted AI agents across Cisco and Splunk security products. Your work will define how agentic security operates across public cloud, on-premises, sovereign cloud, and air-gapped environments, where reliability, control, auditability, and customer trust are non-negotiable.


This is an opportunity to help reinvent how security operations work, translating rapid advances in AI into durable capabilities that give defenders the speed and leverage to meet a new generation of threats.


Your Impact


• Shape technical direction and lead ambiguous, cross-team Agentic SOC capabilities from concept through measurable production improvement.

• Design and build reusable capabilities spanning agent runtime, orchestration, governed tool use, context and memory, evaluation systems, trace analysis, and quality gates.

• Translate SOC, SIEM, detection, incident, investigation, and response needs into shared mechanisms in partnership with security-domain experts.

• Design agents and supporting systems for grounded reasoning, planning, delegation, human oversight, traceability, auditability, and safe failure handling.

• Define measurable success criteria for AI capabilities, including task completion, groundedness, tool-use correctness, trajectory quality, human intervention, safety, latency, cost, and reliability.

• Establish closed-loop, metrics-driven development using golden datasets, offline and online evaluations, production traces, SME and customer feedback, experiments, and regression gates.

• Connect AI quality metrics to production behavior and customer outcomes, identifying signals that are incomplete, misleading, or vulnerable to optimization without meaningful improvement.

• Architect for public cloud, on-premises, sovereign cloud, and air-gapped environments, addressing data residency, restricted connectivity, local model and tool availability, packaging, upgrades, and resource constraints.

• Establish patterns for identity propagation, authorization, tenant isolation, policy enforcement, privacy, auditability, and permission-aware actions.

• Evaluate, integrate, and drive adoption of technologies across Splunk and Cisco, contributing Security requirements and reusable improvements.

• Leverage AI tools throughout requirements, design, coding, review, testing, documentation, debugging, release, and production improvement, with appropriate human validation and security, privacy, and intellectual-property controls.

• Diagnose failures spanning models, prompts, tools, data, orchestration, services, infrastructure, and product integrations.

• Remain hands-on in implementation and design reviews, raise engineering standards, and mentor and influence senior engineers across teams.


Minimum Qualifications


• 6+ years of experience developing, testing, and/or operating production software.

• Experience building and/or operating large-scale distributed or AI-enabled production systems, with experience programming with Python or Go.

• Bachelors + 10 years of related experience, or Masters + 6 years of related experience, or PhD + 3 years of related experience.


Preferred Qualifications


• Experience with LLM and agentic-system concepts including grounding, planning, tool use, memory, human oversight, evaluation, tracing, and regression analysis.

• Demonstrated experience defining AI metrics, building evaluation and experimentation loops, and connecting offline results to production behavior and customer outcomes.

• Experience delivering software across public cloud, on-premises, sovereign cloud, or air-gapped environments.

• Familiarity with SOC, SIEM, detections, incidents, investigations, response, identity, policy, privacy, and auditability.

• Demonstrated success leading cross-team technical initiatives, adopting shared technologies, mentoring senior engineers, and using AI responsibly throughout the software development lifecycle.


Why Cisco? 

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. 

We are Cisco, and our power starts with you. 

Message to applicants applying to work in the U.S. and/or Canada:

The starting salary range posted for this position is $214,100.00 to $309,800.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.

Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.

U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks.  Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.

U.S. employees are eligible for paid time away as described below, subject to Cisco’s policies:

  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees

  • 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco

  • Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees

  • Exempt employees participate in Cisco’s flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)

  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next

  • Additional paid time away may be requested to deal with critical or emergency issues for family members

  • Optional 10 paid days per full calendar year to volunteer

For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco’s policies.

Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:

  • .75% of incentive target for each 1% of revenue attainment up to 50% of quota;

  • 1.5% of incentive target for each 1% of attainment between 50% and 75%;

  • 1% of incentive target for each 1% of attainment between 75% and 100%; and

  • Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.

For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.

The applicable full salary ranges for this position, by specific state, are listed below:

New York City Metro Area:

$214,100.00 - $356,300.00

Non-Metro New York state & Washington state:

$192,400.00 - $317,200.00

* For quota-based sales roles on Cisco’s sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.

** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.

How we rate this

Sr. Staff Software Engineer, Splunk Security Core AI, Agentic SOC (hybrid) at Cisco rates 90 out of 100 for how much of the daily work is AI. That makes it Builds AI (AI Level 4 of 4). The level is about AI in the job, not seniority.

Classification

Builds AI. The job is building AI systems.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

AI AgentsAgentic SocOrchestrationEvaluation SystemsMachine LearningSecurity Operations

Questions you could be asked

  1. How do you decide when an AI agent can act on its own versus asking for approval first?
  2. Tell me about a project where agentic soc was part of your work. What did you do?
  3. Tell me about a project where orchestration was part of your work. What did you do?
  4. Tell me about a project where evaluation systems was part of your work. What did you do?
  5. Tell me about a project where machine learning was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: AI Agents, Agentic Soc, Orchestration, Evaluation Systems, and Machine Learning. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
  • Lead with what you built, trained or shipped — this role is judged on the AI system itself, not the tools around it.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new remote software engineer jobs (Builds AI ●●●●) by email

One email a week with the new remote software engineer jobs (Builds AI ●●●●), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Software Engineering roles that build AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Cisco

More software engineer jobs

Related searches

Same AI level