Software Security Lead
Posted 12hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Cisco software security lead securing AI-enabled enterprise platforms and applications. Leading threat modeling, architecture reviews, risk remediation, and portfolio security metrics.
Responsibilities:
- Serve as the security authority for Cisco’s IT and Enterprise Operations portfolio
- Maintain a current, data-backed view of portfolio security posture
- Translate threat trends, architectural shifts, and security debt into actionable priorities
- Advise and influence Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners
- Review and approve secure designs across the portfolio
- Apply security-by-design and security-by-default principles and make architecture trade-off decisions
- Lead portfolio-wide threat modeling and connect models to design decisions
- Integrate AI securely into in-scope platforms and apply Software Security AI frameworks
- Advocate for AI capabilities that strengthen security outcomes
- Coordinate security SMEs in areas such as cryptography and identity
- Present prioritized unmitigated security risks and residual posture at release or delivery
- Define and lead security engineering metrics, including risk reduction, mean time to remediate, security debt, and developer adoption
Requirements:
- Bachelor’s degree in computer science, Engineering, or a related field (or equivalent practical experience)
- 11+ years of experience in software/application security, secure software development, or security engineering, including a senior or lead role
- Proven experience leading threat modeling and secure design/architecture reviews for complex software systems, including AI- and LLM-enabled features
- Experience interpreting SAST, DAST, and SCA results and translating findings into risk-based, evidence-backed remediation guidance
- Experience with cloud-native applications and modern CI/CD pipelines, including containers and Kubernetes
- Ability to influence engineering and product leadership and drive security outcomes across teams without direct authority
- Preferred: expertise in identity and access management, cryptography, data security, enterprise application security, or software supply chain security
- Preferred: experience with SBOM generation, artifact signing, and SLSA-aligned practices
- Preferred: experience partnering with internal IT, operations, or platform engineering teams
- Preferred: experience defining and using security metrics
- Preferred certifications: CISSP, CSSLP, CCSP, or GIAC
Benefits:
- Medical, dental and vision insurance
- 401(k) plan with a Cisco matching contribution
- Paid parental leave
- Short- and long-term disability coverage
- Basic life insurance
- Cisco restricted stock unit grants may be available
- 10 paid holidays per full calendar year
- 1 floating holiday for non-exempt employees
- 1 paid day off for employee’s birthday
- Paid year-end holiday shutdown
- 4 paid days off for personal wellness
- 16 days of paid vacation per full calendar year for non-exempt employees
- Flexible vacation time off program for eligible exempt employees
- 80 hours of sick time off provided on hire date and each January 1st thereafter
- Up to 80 hours of unused sick time carried forward
- Additional paid time away for critical or emergency family issues
- Optional 10 paid volunteer days per full calendar year
- Annual bonuses for non-sales roles
- Incentive compensation for sales-plan employees



















