Customer Delivery Architect | 10+ years, SOC transformation
Cisco
- Location
- Pune India
- Work model
- On-Site
- Level
- Mid
- Posted
- Sep 3, 2026
Skills
About this role
Meet the Team Cisco Customer Experience (CX) Security Services is a global team of elite security practitioners, architects, and trusted advisors who help our largest enterprise and service provider customers defend against sophisticated threats, achieve operational cyber resilience, and accelerate digital transformation. As part of our specialized Security Operations Center (SOC) Transformation & Advanced Analytics practice, you will work alongside top-tier consulting engineers, automation developers, and solution architects to design and deliver next-generation SOC architectures, SIEM modernization, behavioral analytics, and end-to-end security automation.
Your Impact
As a Security Consulting Architect for SOC Transformation & Splunk, you will be the chief technical authority and visionary guiding our enterprise customers through complex SOC modernization journeys. You will translate customer business outcomes, risk profiles, and operational strategies into scalable, high-fidelity security architectures powered by Splunk Cloud, Splunk Enterprise Security (ES), Splunk SOAR, User & Entity Behavior Analytics (UEBA), Cribl Stream, and modern object storage (MinIO). This is a high-impact, hands-on leadership role. You will engage with customer CISOs, SOC Directors, and Enterprise Architects to define target operating models and modernization roadmaps, while also leading implementation pods, troubleshooting deep technical roadblocks, optimizing search pipelines, and setting the engineering standards for multi-terabyte security analytics. Target SOC Architecture & Transformation Strategy: Lead the architectural design, Target Operating Model (TOM), and delivery strategy for multi-tier enterprise SOCs, SIEM modernizations, and security automation frameworks aligned with MITRE ATT&CK and Cisco Validated Designs. Splunk Cloud & Enterprise Security (ES) Mastery: Architect enterprise-scale Splunk Cloud deployments; design Risk-Based Alerting (RBA) frameworks, Data Model Acceleration (DMA) strategies, optimized | tstats search pipelines, Asset & Identity (A&I) contextual enrichment, and ESCU detection updates to eliminate alert fatigue. Modern Telemetry Ingestion & Storage Architecture: Architect high-throughput, resilient security data collection pipelines leveraging Cribl Stream for edge transformation, filtering, and routing, combined with MinIO / S3-compatible object storage for high-performance SmartStore tiering and compliance data archiving. Security Automation & SOAR Engineering: Define incident triage and response workflows, designing modular, production-grade Python playbooks in Splunk SOAR for automated threat enrichment (Talos, VirusTotal), endpoint containment (EDR isolation), firewall mitigation, and bidirectional ITSM (ServiceNow) synchronization. Technical Pod Leadership & Governance: Provide technical direction, architectural governance, and mentorship to specialized engineering execution pods (Data Ingestion/GDI, Detection Engineering, UEBA, SOAR); serve as the hands-on escalation authority for complex SPL optimization, CIM normalization, and API integrations.
Minimum Qualifications
10+ years of technical cybersecurity engineering and architecture experience designing and deploying enterprise Security Operations Center (SOC) environments and SIEM/SOAR platforms. 5+ years of dedicated, hands-on architecture and engineering experience with Splunk Enterprise, Splunk Cloud, and Splunk Enterprise Security (ES), including correlation search engineering, Data Model Acceleration, and Risk-Based Alerting (RBA). 3+ years of hands-on experience in security telemetry pipeline engineering, including log routing and normalization with Cribl Stream, data parsing (props.conf / transforms.conf), and object storage/SmartStore tiering with MinIO or S3-compatible cloud storage. 3+ years of security orchestration and automation experience designing and building automated response playbooks using Splunk SOAR (Phantom), REST