A Cisco product quality engineer shares their first-hand experience working in the Cisco Live AMER 2026 Security Operations Center. The post covers the full week: building the 'SOC in a Box' hardware stack (firewall, EndaceProbe, UCS compute, SPAN feeds), standing up the software portfolio (Cisco XDR, Splunk Enterprise Security, Secure Network Analytics, Foundation AI), and handling real incidents ranging from malicious website access to complex multi-stage attacks. A highlight was building 'AIM', a custom AI Tier-2 SOC analyst using Claude Opus, MCP servers for Endace and Splunk, and the XDR Conure API. The team also got hands-on with agentic SOC tools including the XDR Agentic Incident Attack Storyboard and Splunk Triage Agent, effectively being promoted to Tier 2 analysts on day one.