
Software Security Lead
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Alabama, +42 more states.
• Act as the security expert for Cisco’s IT and Enterprise Operations portfolio.
• Maintain an up-to-date, data-informed perspective on the security posture of the portfolio.
• Convert threat trends, architectural changes, and security liabilities into actionable priorities.
• Provide guidance and influence to Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners.
• Evaluate and authorize secure designs throughout the portfolio.
• Implement principles of security-by-design and security-by-default, making architectural trade-off decisions.
• Lead organization-wide threat modeling initiatives, ensuring models are evidence-based and linked to design choices.
• Securely integrate AI into relevant platforms and utilize Software Security AI frameworks.
• Promote AI capabilities that enhance security outcomes.
• Coordinate with security subject-matter experts in fields such as cryptography and identity.
• Communicate prioritized unmitigated security risks and the residual security posture at release or delivery stages.
• Establish and oversee security engineering metrics that encompass risk reduction, mean time to remediate, security debt, and developer adoption.
• Bachelor’s degree in computer science, engineering, or a related discipline, or equivalent practical experience.
• Over 11 years of experience in software/application security, secure software development, or security engineering, including a senior or lead role.
• Demonstrated experience in leading threat modeling and secure design/architecture reviews for intricate software systems, including AI- and LLM-enabled features.
• Familiarity with interpreting SAST, DAST, and SCA results.
• Experience in translating security findings into risk-based, evidence-supported remediation recommendations.
• Knowledge of cloud-native applications and contemporary CI/CD pipelines, including containers and Kubernetes.
• Capacity to influence engineering and product leadership to drive security results across teams without direct authority.
• Preferred expertise in identity and access management, cryptography, data security, enterprise application security, or software supply chain security.
• Preferred experience with SBOM generation, artifact signing, and SLSA-aligned practices.
• Preferred background in collaborating with IT, operations, or platform engineering teams on enterprise applications and workflow/automation platforms.
• Preferred experience in defining and utilizing security metrics.
• Relevant certifications such as CISSP, CSSLP, CCSP, or GIAC are preferred.
• Medical, dental, and vision insurance.
• 401(k) plan with Cisco matching contributions.
• Paid parental leave.
• Short- and long-term disability coverage.
• Basic life insurance.
• Cisco restricted stock unit grants may be available.
• 10 paid holidays per full calendar year.
• 1 floating holiday for non-exempt employees.
• Paid day off for birthdays.
• Paid shutdown during year-end holidays.
• 4 paid personal wellness days.
• 16 paid vacation days per full calendar year for non-exempt employees.
• Flexible vacation time off program for exempt employees.
• 80 hours of sick time off provided on hire date and each January 1st.
• Up to 80 hours of unused sick time carried forward annually.
• Additional paid time off for critical or emergency family issues.
• Optional 10 paid volunteer days per full calendar year.
• Annual bonuses for non-sales roles, subject to Cisco policies.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.