Software Security Lead

Posted 10hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Software Security Lead securing Cisco’s enterprise IT and Operations platforms across applications, cloud, identity, data, and AI. Leading threat modeling, architecture reviews, risk remediation, and security metrics.

Responsibilities:

  • Serve as the security authority for Cisco’s IT and Enterprise Operations portfolio
  • Maintain a current, data-backed view of portfolio security posture
  • Translate threat trends, architectural shifts, and security debt into actionable priorities
  • Advise and influence Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners
  • Review and approve secure designs across the portfolio
  • Apply security-by-design and security-by-default principles
  • Lead portfolio-wide threat modeling and connect models to design decisions
  • Integrate AI securely into in-scope platforms and apply Software Security AI frameworks
  • Advocate for AI capabilities that strengthen security outcomes
  • Coordinate security subject-matter experts in areas such as cryptography and identity
  • Present prioritized unmitigated security risks and residual posture at release or delivery
  • Define and lead security engineering metrics, including risk reduction, mean time to remediate, security debt, and developer adoption

Requirements:

  • Bachelor’s degree in computer science, Engineering, or a related field, or equivalent practical experience
  • 7+ years of experience in software/application security, secure software development, or security engineering, including a senior or lead role
  • Proven experience leading threat modeling and secure design/architecture reviews for complex software systems, including AI- and LLM-enabled features
  • Experience interpreting SAST, DAST, and SCA results
  • Experience translating findings into risk-based, evidence-backed remediation guidance
  • Experience with cloud-native applications and modern CI/CD pipelines, including containers and Kubernetes
  • Ability to influence engineering and product leadership and drive security outcomes across teams without direct authority
  • Preferred specialization in identity and access management, cryptography, data security, enterprise application security, or software supply chain security
  • Preferred experience with SBOM generation, artifact signing, and SLSA-aligned practices
  • Preferred experience partnering with internal IT, operations, or platform engineering teams
  • Preferred experience defining and using security metrics
  • Certifications such as CISSP, CSSLP, CCSP, or GIAC are preferred

Benefits:

  • Medical, dental and vision insurance
  • 401(k) plan with a Cisco matching contribution
  • Paid parental leave
  • Short- and long-term disability coverage
  • Basic life insurance
  • Cisco restricted stock unit grants may be available
  • 10 paid holidays per full calendar year
  • 1 floating holiday for non-exempt employees
  • Paid birthday day off
  • Paid year-end holiday shutdown
  • 4 paid personal wellness days
  • 16 days of paid vacation per full calendar year for non-exempt employees
  • Flexible vacation time off program with no defined limit for eligible exempt employees
  • 80 hours of sick time off provided on hire and each January 1st
  • Up to 80 hours of unused sick time carried forward annually
  • Additional paid time away for critical or emergency family issues
  • Optional 10 paid volunteer days per year
  • Annual bonuses for non-sales roles
  • Cisco careers site offers additional benefits and perks