1

Splunk Siem Engineer Jobs in San Ramon, CA (NOW HIRING)

Security Operations Lead

Foster City, CA · On-site

$295K - $385K/yr

This role leads the global SOC function-monitoring, SIEM ownership, detection engineering, alert ... Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.). * Deep ...

Build capabilities for triage resolution agents in Cisco/Splunk's Agentic SOC * Collaborate with ... Preferred: familiarity with TDIR/SIEM architectures, correlation searches, and threat hunting ...

Senior Security Engineer

San Jose, CA · On-site

$184K - $208K/yr

Experience with SIEM platforms (Splunk, Sentinel, Elastic, or similar) for log analysis and detection engineering * Solid networking knowledge - firewalls, proxies, DNS security, network segmentation ...

Senior Security Engineer

San Jose, CA · On-site

$184K - $208K/yr

Experience with SIEM platforms (Splunk, Sentinel, Elastic, or similar) for log analysis and detection engineering * Solid networking knowledge - firewalls, proxies, DNS security, network segmentation ...

Meet the Team The Splunk Enterprise Security team develops a data-driven SIEM designed to ... Engineers partner closely with Product Management, Architects, UX, multi-functional teams, and ...

Showing results 21-40

Splunk Siem Engineer information

What does a Splunk SIEM Engineer do?

A Splunk SIEM Engineer is responsible for designing, implementing, and managing Splunk Security Information and Event Management (SIEM) solutions within an organization. They monitor security events, create dashboards, and develop alerts to detect and respond to potential threats. Their work involves integrating various data sources into Splunk, maintaining system performance, and ensuring compliance with security policies. Splunk SIEM Engineers also play a key role in incident response and help organizations improve their overall security posture.

What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer?

To thrive as a Splunk SIEM Engineer, you need strong expertise in security information and event management (SIEM), log analysis, scripting, and a background in cybersecurity, often supported by a computer science degree or related certifications. Familiarity with Splunk Enterprise Security, Splunk Query Language (SPL), and certifications like Splunk Certified Power User or Splunk Certified Admin are commonly required. Analytical thinking, problem-solving skills, and effective communication help engineers interpret security data and collaborate with IT teams. These skills are crucial for proactively detecting threats, optimizing security operations, and ensuring the resilience of organizational IT environments.

What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?

Splunk SIEM Engineers often encounter challenges such as inconsistent log formats, lack of documentation from data source owners, and ensuring data normalization for effective correlation and analysis. Additionally, dealing with high data volume while maintaining system performance and security compliance can be demanding. Close collaboration with IT, security teams, and application owners is critical to troubleshoot issues and fine-tune data onboarding processes.

What is the difference between Splunk Siem Engineer vs Security Analyst?

AspectSplunk Siem EngineerSecurity Analyst
CertificationsSplunk Certified Power User, Splunk Certified AdminCompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on configuring, maintaining, and optimizing Splunk SIEM toolsMonitor security alerts, investigate incidents, and implement security measures
Industry UsagePrimarily in cybersecurity, IT operations, and complianceAcross cybersecurity teams, incident response, and risk management

The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.

What job categories do people searching Splunk Siem Engineer jobs in San Ramon, CA look for?

The top searched job categories for Splunk Siem Engineer jobs in San Ramon, CA are:

What cities near San Ramon, CA are hiring for Splunk Siem Engineer jobs?

Cities near San Ramon, CA with the most Splunk Siem Engineer job openings:

Infographic showing various Splunk Siem Engineer job openings in San Ramon, CA as of June 2026, with employment types broken down into 1% As Needed, 53% Full Time, 39% Part Time, 2% Contract, and 5% Nights. Highlights an 78% Physical, 9% Hybrid, and 13% Remote job distribution.

Staff Software Engineer - AI/Security Platform

Cisco

San Francisco, CA • Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Cisco Systems rating

8.2

Company rating: 8.2 out of 10

Based on 43 frontline employees who took The Breakroom Quiz

46th of 161 rated electronics manufacturers


Job description

The application window is expected to close on: 09/26/2026

Meet the Team

We are an agile team with a startup feel and a strong bias for action. We move fast, embrace failure as part of the process, and stay focused on solving real-world problems for defenders on the front lines. Our team blends deep expertise in AI, cybersecurity, platform and systems engineering. We are driven by a shared belief that the only way to outpace hackers is through AI advancements that free up humans to tackle real threats and more challenging problems.

This is a place for builders who thrive in ambiguity, challenge the status quo, and care deeply about making a meaningful impact. If you're energized by tough problems, excited to shape the future of cyber defense, and eager to work alongside passionate experts, you'll feel right at home.

Your Impact

  • Design and build systems that combine security-relevant data, detection signals, context, and foundation models to spot and predict threats, those in action and those that are about to happen.

  • Prototype and test new AI features - from decoding events and system environments to predicting anomalies and threats - working closely with security SMEs and security researchers to validate real-world utility.

  • Develop an AI DevOps pipeline to enable rapid experimentation with data. Knowledge bases, models, and context memory, using clear, measurable success criteria to evaluate iterations.

  • Architect and build the distributed platform that can correlate trillions of events & signals, and can synthesize them into explainable findings and alerts, consumed by our triage resolution agents - you will be building a key capability of the Agentic SOC.

  • Collaborate with product and platform teams to co-design AI-enhanced threat detection and prediction workflows that are intuitive, scalable, and immediately useful to analysts.

  • Contribute to the core architecture powering AI-native security operations, helping to shape how Splunk and Cisco scale trusted automation across the enterprise.

Minimum Qualifications

  • Bachelor's Degree with 8+ years of related experience or Master's with 6+ years of related experience.

Engineering Qualifications:

  • Distributed Systems design and implementation - Experience with an emphasis on storage systems and storage access layers

  • Data Platform/Fabric - Experience implementing data platforms and/or data lakes and warehouses.

  • Proficient Python Development - Experience building scalable backend services, APIs, and automation workflows in Python.

  • DevOps/SecOps Practices - Experience, proficient with CI/CD pipelines, version control (GitHub/GitLab), Jira, and automated testing frameworks.

  • Agentic development - Experience designing agent systems that will perform coding tasks for you.

  • Cross-Functional Collaboration - Experience partnering with product managers, security SMEs, and engineers to iterate quickly and deliver impactful solutions.

Security Qualifications:

  • Security Telemetry Fluency - Experience working with common telemetry data sources such as endpoint logs, network traffic, authentication events, or cloud audit trails and understanding how they're used in detection and investigation workflows.

Preferred Qualifications

  • Security Data Engineering - Experience building and maintaining pipelines for ingesting, parsing, and normalizing large-scale security telemetry.

  • Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures, correlation searches, threat hunting support systems. Bonus if you've worked with Splunk's APIs, internals, or have experience developing on the Splunk platform.

  • Security Operations Experience - Understanding of security operations concepts, including attack surface management, threat analytics, detection, triage, investigation, and response. Alternatively, former Tier 3 SOC analyst or equivalent, with experience automating SecOps workflows and building scalable, resilient detection infrastructure.

  • Data Encoding & Embeddings - Exposure to event storage systems or generating custom embeddings for domain-specific tasks in cybersecurity.

  • RAG and GraphRAG Search Implementation - Hands-on experience developing retrieval-augmented generation pipelines and working with databases (e.g., FAISS, Pinecone).

  • Model Integration - Skilled in crafting, testing, and optimizing training workloads for large language or special-purpose models such as GNNs, GCNs, GATs. Ideally, you have contributed to or shipped an AI-powered feature or product and understand the nuances of integrating models into real-world workflows - including usability, performance, and trust considerations.

  • AI Evaluation & Experimentation - Capable of designing experiments to evaluate model output for accuracy, usability, performance, and cost

  • UX and Human Factors for Analysts - Background or interest in designing intuitive, AI-assisted analyst workflows with a focus on usability, trust, and decision support.

Why Cisco?

At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.

We are Cisco, and our power starts with you.

Message to applicants applying to work in the U.S. and/or Canada:The starting salary range posted for this position is $186,900.00 to $267,700.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.

Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.

U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.

U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:

  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees

  • 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco

  • Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees

  • Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)

  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours ofunused sick timecarried forwardfrom one calendar yearto the next

  • Additional paid time away may be requested to deal with critical or emergency issues for family members

  • Optional 10 paid days per full calendar year to volunteer

For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies.

Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:

  • .75% of incentive target for each 1% of revenue attainment up to 50% of quota;

  • 1.5% of incentive target for each 1% of attainment between 50% and 75%;

  • 1% of incentive target for each 1% of attainment between 75% and 100%; and

  • Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.

For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.

The applicable full salary ranges for this position, by specific state, are listed below:

New York City Metro Area:

$186,900.00 - $307,800.00

Non-Metro New York state & Washington state:

$166,300.00 - $274,100.00

* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.

** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.


What Cisco Systems employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Cisco Systems logo

About Cisco Systems

Sourced by ZipRecruiter

Cisco Systems, a global tech titan based in San Jose, CA, US, operates in the information technology and services industry. Founded in 1984, the company was derived from a project between two computer scientists from Stanford University. They aimed to connect different networks of computer systems at the university, resulting in the first multi-protocol router, and subsequently, the birth of Cisco. As an industry-leading manufacturer of networking hardware and telecommunications equipment, Cisco's product and services range includes routers, switches, firewall devices, and telecommunication technology. The company's mission, "to shape the future of the Internet by creating unprecedented value and opportunity for our customers, employees, investors, and ecosystem partners," is a testament to its pursuit of technology-forward innovation and customer satisfaction.

Industry

Computer and computer peripheral equipment and software wholesalers

Company size

10,000+ Employees

Headquarters location

San Jose, CA, US

Year founded

1984

Social media