false
Engineering

Leader, Software Engineering

Splunk, a Cisco company, is building a safer and more resilient digital world with an end-to-end full stack platform made for a hybrid, multi-cloud world. Leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable. Our customers love our technology, but it's our caring employees that make Splunk stand out as an amazing career destination. No matter where in the world or what level of the organization, we approach our work with kindness. So bring your work experience, problem-solving skills and talent, of course, but also bring your joy, your passion and all the things that make you, you. Come help organizations be their best, while you reach new heights with a team that has your back.

Role Summary

As Manager of the Attack Analyzer team, you'll lead the development of innovative threat detection capabilities that protect millions of users from sophisticated phishing and malware attacks. Your team's work directly enables organizations to achieve 90% faster resolution of phishing alerts and automate 61% of threat analysis workflows without human intervention.
You'll have the opportunity to shape the future of automated threat analysis while building an elite team of security researchers and engineers. This role combines the technical depth of threat research with the strategic impact of product leadership, offering a unique opportunity to influence both technology and team development in the constantly evolving cybersecurity landscape.
If you're passionate about building exceptional teams, driving technical innovation, and making a measurable impact on global cybersecurity, we want to hear from you. Join us in revolutionizing how organizations detect and respond to email-based threats.

Meet the Team

Do you have a passion for building premier threat detection capabilities while leading a team of exceptional threat researchers? Are you excited about revolutionizing how organizations defend against phishing and malware threats through intelligent automation? If you flourish with combining technical excellence with people leadership, we want to meet you.
The Splunk Security organization is seeking an exceptional engineering manager to lead our Attack Analyzer threat research team. This team is responsible for developing and improving detection content that powers Splunk Attack Analyzer, a platform that automates malware and phishing investigations and provides organizations with the forensic insights necessary for accurate and timely threat detection.
As a technical leader who understands both the intricacies of threat analysis and the art of building high-performing teams, you'll drive the strategic direction of a product that processes millions of threats annually and directly impacts the security posture of organizations worldwide.

What you'll get to do

Team Leadership & Development
  • Lead, mentor, and grow a team of senior threat researchers and detection engineers focused on phishing and malware analysis
  • Foster a culture of innovation, technical excellence, and continuous learning within the team
  • Recruit premier talent and build the team's capabilities in emerging threat landscapes
  • Conduct performance evaluations, career development planning, and technical mentoring
  • Collaborate with multi-functional teams including Product Management, Engineering, and Customer Success

Product Strategy & Technical Direction

  • Define and complete the technical roadmap for Splunk Attack Analyzer's detection capabilities
  • Drive innovation in automated threat analysis, with particular focus on credential phishing and advanced malware detection
  • Partner with product teams to enhance threat detection capabilities across the broader Splunk security portfolio
  • Establish detection quality standards and metrics to measure the effectiveness of threat analysis automation

Technical Excellence & Research Leadership

  • Guide the development of next-generation detection logic and analysis techniques for email-based threats
  • Be responsible for the creation of high-quality detection content and automation tools that scale across customer environments
  • Ensure the team stays ahead of evolving phishing tactics, techniques, and procedures (TTPs)
  • Drive integration initiatives with Splunk SOAR and other security platforms for end-to-end threat response workflows

Collaborator Management & Communication

  • Present technical strategy and team progress to senior leadership and key collaborators
  • Collaborate with customer-facing teams to understand market needs and translate them into product requirements
  • Represent Splunk's threat detection capabilities at industry conferences and customer engagements
  • Establish relationships with threat intelligence partners and the broader security research community

Must-have Qualifications

Leadership & Management Experience

  • validated experience running technical teams in cybersecurity, with at least 2 years in a senior management role
  • Consistent track record of building and scaling high-performing engineering teams
  • Experience running complex technical projects with multiple collaborators and contending priorities
  • Strong ability to translate business requirements into technical solutions and team objectives

Technical Expertise

  • 8+ years of hands-on experience in threat research, malware analysis, or security product development
  • Deep understanding of email security, phishing techniques, and sandbox analysis technologies
  • Expert knowledge of threat detection methodologies, particularly for credential phishing and malware
  • Strong background in detection engineering, with experience in platforms like Sigma, YARA, or similar
  • (Nice to Have) Proficiency in Python and familiarity with detection content development workflows

Domain Knowledge

  • Comprehensive understanding of adversary tactics, techniques, and procedures (TTPs), focused email-based attacks
  • Experience with threat intelligence platforms and frameworks like MITRE ATT&CK
  • (Nice to Have) Familiarity with:
  • API development, automation technologies, and security orchestration platforms
  • Cloud security architectures and containerization technologies (e.g., Docker, Kubernetes)

Communication & Strategy

  • Exceptional communication skills with ability to present sophisticated technical concepts to diverse audiences
  • Experience working with product management teams to define and prioritize feature development
  • Data-driven attitude with strong analytical and problem-solving skills.

Nice-to-have Qualifications

  • Previous experience with email security products, sandbox technologies, or automated threat analysis platforms
  • Contributions to open-source security projects or published research in threat detection
  • Speaking experience at major security conferences (RSA, Black Hat, DEF CON, BSides)
  • Experience with Splunk platform development or security analytics
  • Background in machine learning applications for threat detection
  • Bachelor’s or advanced degree in Computer Science or a related technical field.
 
Cisco is an Equal Opportunity Employer 
 
At Cisco, we believe creating a culture of belonging isn’t just the right thing to do; it’s also the smart thing. We prioritize diversity, equity, inclusion, and belonging to ensure our employees are supported to bring their best, most authentic selves to work where they can thrive. Qualified applicants receive consideration for employment without regard to race, religion, color, national origin, ancestry, sex, gender, gender identity, gender expression, sexual orientation, marital status, age, physical or mental disability or medical condition, genetic information, veteran status, or any other consideration made unlawful by federal, state, or local laws. We consider qualified applicants with criminal histories, consistent with legal requirements.
 
Note:
 
Base Pay Range 
 
Base Pay Range: $175,000 - 213,000 per year
 
When available, the salary range posted for this position reflects the projected hiring range for new hire, full-time salaries in U.S. and/or Canada locations, not including equity or benefits. For non-sales roles the hiring ranges reflect base salary only; employees are also eligible to receive annual bonuses. Hiring ranges for sales positions include base and incentive compensation target. Individual pay is determined by the candidate's hiring location and additional factors, including but not limited to skillset, experience, and relevant education, certifications, or training. Applicants may not be eligible for the full salary range based on their U.S. or Canada hiring location. The recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees have access to quality medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, short and long-term disability coverage, basic life insurance and numerous wellbeing offerings.
 
Employees receive up to twelve paid holidays per calendar year, which includes one floating holiday (for non-exempt employees), plus a day off for their birthday. Non-Exempt new hires accrue up to 16 days of vacation time off each year, at a rate of 4.92 hours per pay period. Exempt new hires participate in Cisco’s flexible Vacation Time Off policy, which does not place a defined limit on how much vacation time eligible employees may use but is subject to availability and some business limitations. All new hires are eligible for Sick Time Off subject to Cisco’s Sick Time Off Policy and will have eighty (80) hours of sick time off provided on their hire date and on January 1st of each year thereafter.  Up to 80 hours of unused sick time will be carried forward from one calendar year to the next such that the maximum number of sick time hours an employee may have available is 160 hours. Employees in Illinois have a unique time off program designed specifically with local requirements in mind. All employees also have access to paid time away to deal with critical or emergency issues. We offer additional paid time to volunteer and give back to the community.
 
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components. For quota-based incentive pay, Cisco typically pays as follows:
.75% of incentive target for each 1% of revenue attainment up to 50% of quota;
1.5% of incentive target for each 1% of attainment between 50% and 75%;
1% of incentive target for each 1% of attainment between 75% and 100%; and once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.

Splunk's Hiring Practices

Splunk turns machine data into answers. Organizations use market-leading Splunk solutions with machine learning to solve their toughest IT, Internet of Things and security challenges.
 
Splunk, a Cisco company, is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis. We consider qualified applicants with criminal histories, consistent with legal requirements. Click here to review the US Department of Labor’s EEO is The Law notice. If you need assistance or an accommodation to apply or during the hiring process, please let us know by completing our Accommodation Request form.
 
Splunk also has policies in place to protect the personal information candidates disclose to us as part of the application process. Please click here to review Splunk’s Career Site Privacy Policy.

Splunk does not discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Please click here to review Splunk’s Pay Transparency Nondiscrimination Provision.

Splunk is committed to the health and safety of our employees and customers. Splunk is impacted by the mandates outlined for U.S. Government contractors in President Biden’s Path out of the Pandemic: COVID-19 Action Plan. As a result, Splunk requires U.S. employees, whether assigned to an office or 100% remote, to provide proof of full vaccination, as defined by the CDC. Splunk provides reasonable accommodations for employees who have qualifying medical or religious reasons.

Splunk is also committed to providing access to all individuals who are seeking information from our website. Any individual using assistive technology (such as a screen reader, Braille reader, etc.) who experiences difficulty accessing information on any part of Splunk’s website should send comments to accessiblecareers@splunk.com. Please include the nature of the accessibility problem and your e-mail or contact address. If the accessibility problem involves a particular page, the message should include the URL of that page.

Splunk doesn't accept unsolicited agency resumes and won't pay fees to any third-party agency or firm that doesn't have a signed agreement with Splunk.

To check on your application click here.

DIVE DEEPER

Find out what makes Splunk such a great place to work

box1 box1
Our Values

Splunkers are encouraged and empowered to be Innovative, passionate, disruptive, open and fun.

Learn More
box2 box2
Benefits and Wellbeing

Our benefits are designed to support your physical, financial, emotional and mental wellbeing.

Explore Splunk Benefits
box3 box3
Early Talent Program

Intern with people you want to hang out with, even outside the office.

Learn More
box3 box3

Our Blog

Hear from Splunkers on the latest.

Read the Blog
box2 box2
Diversity, Equity, Inclusion & Belonging

Learn about Splunk’s commitment to creating a culture of belonging.

See Our Approach
box1 box1
LinkedIn

Follow Splunk on LinkedIn for job announcements, company news and more.

Follow Us