Cisco's 4,000-Person AI Pivot: The Real Talos + Splunk Pool Is 84
Cisco's 2026 cuts hit Talos and Splunk. The self-identified pool is 84 people, mostly invisible to LinkedIn. Here is how to source them.
Cisco is cutting nearly 4,000 people in 2026 to reallocate payroll into AI networking and silicon, and notifications started May 14. If you run security hiring, the interesting sliver is not the 4,000. It is the Talos threat researchers and Splunk SIEM engineers who just got shaken out of a profitable unit and are actively being pushed toward AI security roles by their own severance package.
What Cisco actually cut, and why the "Talos layoff" story is misleading
Cisco announced roughly 4,000 layoffs in 2026, about 5% of global headcount, in the same quarter it reported a record $15.8 billion in Q3 revenue, up 12% year over year. This is a reallocation, not a distress cut, and Talos plus Splunk are the security-relevant slices.
The California WARN filings give you the shape:
- 471 total workers across 3 filings, covering Santa Clara and San Francisco.
- Software engineering is the largest identified role category in those filings.
- Overlapping post-Splunk functions - sales ops, support, and engineering roles duplicated by the 2024 Splunk acquisition - are the consolidation target.
- Talos, Cisco's threat intelligence arm, is confirmed by TechCrunch as hit for the second consecutive cycle after the 2024 round.
- Severance reportedly includes free AI training courses, which is itself a hiring signal about where these people are being steered.
The press keeps writing "Cisco laid off Talos" as if a big, sourceable pool just spilled onto the street. It did not. Talos is 350+ people globally across research, analysis, and engineering. A single-digit percentage got cut. The org that processes 1.5 million malware samples a day and analyzes 13 billion web requests is still mostly intact, and the people who left are camouflaged.
The self-identified Talos + Splunk pool is 84 people, not thousands
In Refolk's index of professional profiles, the security-relevant, self-identified displaced pool from this cycle is roughly 84 people, not the 471 in the WARN filing and not the 4,000 in the press. Everything else is switching, routing, collaboration, and back office.
Here is the actual dataset:
| Segment | Count | Source |
|---|---|---|
| Talos-tagged threat/security researchers worldwide | 6 | Refolk's index |
| US threat researcher / analyst / intelligence universe | ~900 | Refolk's index |
| US security/detection/SIEM engineers with "Splunk" in headline | 70 | Refolk's index |
| Talos + Splunk self-identified pool (derived) | ~76 to 84 | Refolk's index |
| California WARN 2026 Cisco layoffs (all roles) | 471 | CaliforniaWarn.com |
| Talos org size (global, all functions) | 350+ | Cisco Talos overview |
The gap between "350+ Talos employees globally" and "6 Talos-tagged profiles worldwide" is the entire story. Talos researchers deliberately do not put "Talos" in their LinkedIn headline. They list "Cisco" as employer, sometimes "Cisco Systems," and often nothing more specific than "Security Researcher." Operational security is part of the job. Boolean searches on Talos miss them.
Why LinkedIn Recruiter cannot find these people
LinkedIn Recruiter cannot find displaced Talos researchers because they do not use the word "Talos" in their profiles, and the ex-Splunk cohort is concentrated at a handful of employers recruiters already saturate. Cold Boolean is the wrong tool for both.
Three mechanisms drive the invisibility:
- Opsec norms at Talos. Public-facing Talos work is bylined by a small group - Nick Biasini, head of outreach, is the most quoted. Everyone else publishes under "Cisco Talos" collective attribution or CVE credit. The individual's LinkedIn says "Security Researcher at Cisco" and nothing else.
- CVE and open-source attribution beats headline search. The signal that a candidate did real Talos work lives in CVE credits, Snort rule commits, ClamAV signatures, and conference talks, not on LinkedIn. If your sourcing stack cannot reach into GitHub and the open web, you are searching the wrong index.
- The Splunk pool is bunched. Refolk's index shows the top current employers for US Splunk-headline security engineers are Cisco Systems, Snowflake, and Herjavec Group. Three companies. Everyone already messages them. The displaced ex-Cisco/Splunk cohort inside that 70 is the interesting cut, and it needs Cisco-Splunk internal transfer history to identify.
This is the exact gap Refolk closes. You describe the person in plain English ("ex-Cisco Talos researcher with CVE credits, currently unemployed or listed as Cisco through Q4 2026") and get a ranked shortlist that pulls from GitHub, LinkedIn, and open-web signals at the same time. The Boolean gymnastics stop being your job.
The two-cycle purge changes what "ex-Talos" is worth
Ex-Talos in 2026 is a higher-signal hire than ex-Talos in 2024, because Cisco already cut Talos in the 2024 round of 6,000 layoffs and the researchers who survived that first purge were explicitly retained. The 2026 cuts include people Cisco actively chose to keep 18 months ago.
The loyalty tax is over. The people leaving now:
- Cleared an internal performance filter Cisco ran in early 2024.
- Watched their unit post record revenue while HR emailed them a WARN notice.
- Received severance that includes free AI training, which is the company literally telling them to go work on AI security.
- Have a fast-closing severance and non-solicit window running through Cisco's fiscal fourth quarter.
The researchers Cisco kept in 2024 and cut in 2026 are the highest-signal security hires of the year.
Expect comp expectations to be elevated. These are not distressed sellers. They know their unit was profitable. "We're pre-revenue and mission-driven" lands badly. "We pay Anthropic-adjacent comp and you own detection strategy" lands.
Where the 84 actually land, and how to intercept them
Ex-Talos researchers historically land at Microsoft, Mandiant/Google Red Team, Sophos, Zscaler, and Bishop Fox, per Refolk's index of the broader 900-person US threat researcher universe. Intel also shows up as a top current employer in that pool. Intercepting them means getting to the candidate before those brands do.
Intercept tactics, in order of yield:
- CVE attribution search. Pull CVE credits that cite Cisco Talos, then reverse them to individual researchers via GitHub and personal blogs. This is the only reliable way to find the 344 Talos people who are not in the visible 6.
- Snort and ClamAV commit history. Both are Cisco-owned open source. Commit authors with @cisco.com emails who stopped committing after May 14, 2026 are your list.
- Splunk internal transfer cohort. The 70 US Splunk-headline security engineers include a slice who came into Cisco via the 2024 Splunk acquisition. They are the SIEM and detection engineers most likely to be in the WARN 471. Filter for tenure that starts around the acquisition close date.
- Herjavec Group poach-back. Herjavec is a top current employer of Splunk-flavored security engineers per Refolk's index. Some of the ex-Cisco/Splunk cohort will land there first as a soft parachute. Six-month follow-ups convert.
- Conference talk history. BlackHat and DEF CON co-presenters with Talos staff overlap heavily with the invisible pool.
What to say in the first message
The first message to a displaced Talos or Splunk engineer should reference a specific piece of their public work - a CVE, a Snort rule, a Splunk detection - and skip the "saw you're open to opportunities" framing entirely. They are not open. They are exiting a profitable unit under protest.
Three concrete moves:
- Lead with the artifact. "Your write-up on that CVE and the Snort coverage that shipped with it is exactly the detection-engineering muscle we need for our EDR pipeline." Specific beats flattering.
- Name the AI security angle directly. Cisco's severance package is nudging them toward AI. If your role is AI security, say so in the first sentence. If it is not, say why traditional detection still matters and what your budget looks like.
- Acknowledge the comp reality. These candidates were at a company printing $15.8B a quarter. Post the band. If you cannot compete with Anthropic or Microsoft AI security comp, target the ex-Splunk SIEM cohort instead, where the pool is roughly 10x bigger and expectations sit closer to enterprise security-engineering norms.
Recruiters who try to run this play with a LinkedIn Recruiter seat and a Boolean string will get six results and a bad quarter. Recruiters who use Refolk to pull the CVE-plus-GitHub-plus-headline reconciliation get the actual 84 in an afternoon.
What to watch through the rest of fiscal 2026
Cisco has run this exact play before: about 4,200 cut in February 2024, then roughly 6,000 more later that year including Talos. Cisco has filed 36 WARN notices totaling 7,906 workers since October 2008 across California, Georgia, and Texas. The pattern is multiple waves per fiscal year, not one, and the sourcing window extends as long as the filings keep coming.
What to monitor:
- WARN Tracker. The next California filing will confirm whether a second 2026 wave is real.
- Snort and ClamAV commit velocity. A sharp drop in unique @cisco.com committers is a leading indicator of the invisible pool expanding.
- Herjavec Group and Bishop Fox job posts. Sudden posting spikes for senior detection engineers with Splunk experience signal the parachute companies preparing to catch the displaced cohort.
- KORE1 and similar staffing shops. KORE1's IT practice publicly claims to have moved roughly a dozen ex-Cisco engineers into new seats since late 2024. Their posting activity is a proxy for how fast the cohort is being absorbed.
The 84 number is a floor, not a ceiling. If Talos gets touched a third time, the self-identified pool could double, and the CVE-attribution sourcing method scales with it. The teams that will win these hires are the ones with sourcing infrastructure that reads GitHub, LinkedIn, and the open web as one graph.
FAQ
How is 84 the "real" pool when Cisco cut 4,000 people?
Because 4,000 is the global headcount reduction across every function, and the California WARN filings show only 471 roles in the security-relevant geography. Of those 471, most are switching, routing, collaboration, sales ops, and post-Splunk duplicates. Refolk's index shows only 6 people worldwide self-identify with a Talos-tagged threat researcher title, and 70 US security engineers list Splunk in their headline. Add them, subtract minimal overlap, and you get roughly 84 self-identified, security-relevant, currently sourceable profiles. The rest either do not exist as self-identified security specialists or are invisible under generic "Cisco" employer strings.
Why do Talos researchers hide their affiliation on LinkedIn?
Operational security. The team norm is to publish under "Cisco Talos" collective attribution, put "Cisco" or "Security Researcher" on LinkedIn, and let CVE credits and conference talks do the specificity. This is why Boolean search on "Talos" returns 6 profiles for a 350-person org, and why CVE and GitHub attribution beats headline search for this specific cohort.
What is the fastest way to identify the ex-Splunk cohort inside Cisco?
Filter for security, detection, or SIEM engineers whose Cisco tenure starts within a 90-day window around the 2024 Splunk acquisition close. Refolk's index shows 70 US profiles with Splunk in the headline, and the internal-transfer slice inside that group is the one most exposed to the 2026 WARN filings. Cross-reference with Splunk .conf speaker history and Splunkbase app authorship for signal on who actually built things versus who administered dashboards.
How long is the intercept window?
Notifications began May 14, 2026 and the reduction executes during Cisco's fiscal fourth quarter, so severance timing plus non-solicit clauses plus the AI training incentive in the package all compress candidates toward signed offers over the summer. Microsoft, Mandiant/Google, Sophos, and Zscaler will move first on the visible 6. The invisible 78 are the ones you can still win later if your sourcing stack can find them.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.