
Software Security Lead
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Alabama, +43 more states.
• Act as the security expert for Cisco’s IT and Enterprise Operations portfolio.
• Maintain an updated, data-driven perspective on the security posture of the portfolio.
• Convert threat trends, architectural changes, and security liabilities into actionable priorities.
• Provide guidance and influence Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer stakeholders.
• Evaluate and authorize secure designs throughout the portfolio.
• Tailor security-by-design and security-by-default principles to fit various contexts.
• Oversee portfolio-wide threat modeling and link models to defensible, evidence-based design choices.
• Securely integrate AI into applicable platforms and implement Software Security AI frameworks.
• Promote AI capabilities that enhance security outcomes.
• Organize security subject-matter experts in areas like cryptography and identity management.
• Present prioritized unaddressed security risks during release or delivery stages.
• Establish and manage security engineering metrics, including risk reduction, mean time to remediate, security liabilities, and developer engagement.
• Bachelor’s degree in computer science, Engineering, or a related discipline (or equivalent hands-on experience).
• Over 7 years of experience in software/application security, secure software development, or security engineering, including a senior or leadership role.
• Demonstrated experience in leading threat modeling and secure design/architecture evaluations for complex software systems, including AI- and LLM-enabled functionalities.
• Proficient in interpreting SAST, DAST, and SCA results.
• Skilled at translating findings into risk-based, evidence-supported remediation recommendations.
• Familiarity with cloud-native applications and contemporary CI/CD pipelines, including containers and Kubernetes.
• Capability to influence engineering and product leadership, driving security results across teams without direct authority.
• Specialized knowledge in one or more areas such as identity and access management, cryptography, data security, enterprise application security, or software supply chain security.
• Experience with SBOM generation, artifact signing, and practices aligned with SLSA.
• Background in collaborating with internal IT, operations, or platform engineering teams.
• Experience in defining and utilizing security metrics.
• Relevant certifications such as CISSP, CSSLP, CCSP, or GIAC are desirable.
• Medical, dental, and vision insurance.
• 401(k) plan with a Cisco matching contribution.
• Paid parental leave.
• Coverage for short- and long-term disability.
• Basic life insurance.
• Cisco restricted stock unit grants may be available.
• 10 paid holidays for each full calendar year.
• 1 floating holiday for non-exempt employees.
• Paid day off for birthdays.
• Paid shutdown during year-end holidays.
• 4 paid personal wellness days.
• 16 paid vacation days for each full calendar year for non-exempt employees.
• Flexible vacation time off program without a defined limit for eligible exempt employees.
• 80 hours of sick leave provided at the time of hire and every January 1st.
• Up to 80 hours of unused sick leave can be carried over.
• Additional paid time off for urgent family matters.
• Option for 10 paid volunteer days each calendar year.
• Annual bonuses for non-sales positions, subject to Cisco policies.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.