
Software Security Lead
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in North Carolina.
• Act as the security expert for Cisco’s IT and Enterprise Operations portfolio.
• Keep an updated, data-driven perspective on the security posture of the portfolio.
• Convert threat patterns, architectural changes, and security vulnerabilities into actionable tasks.
• Provide guidance and influence to Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners.
• Evaluate and endorse secure designs across the portfolio.
• Implement security-by-design and security-by-default principles while making architectural trade-offs.
• Lead comprehensive threat modeling across the portfolio and connect these models to design choices.
• Safely integrate AI into relevant platforms and apply Software Security AI frameworks.
• Promote AI functionalities that enhance security results.
• Coordinate with security subject matter experts in areas such as cryptography and identity.
• Present prioritized unmanaged security risks and residual security posture during release or delivery phases.
• Define and oversee security engineering metrics, including risk reduction, mean time to remediate, security debt, and developer engagement.
• Bachelor’s degree in computer science, Engineering, or a related field (or equivalent practical experience).
• Over 11 years of experience in software/application security, secure software development, or security engineering, including a senior or lead position.
• Demonstrated experience in leading threat modeling and secure design/architecture reviews for intricate software systems, including AI- and LLM-enabled features.
• Proficient in interpreting SAST, DAST, and SCA results and converting findings into risk-based, evidence-supported remediation strategies.
• Familiarity with cloud-native applications and contemporary CI/CD pipelines, including containers and Kubernetes.
• Capability to influence engineering and product leadership and drive security outcomes across teams without direct authority.
• Preferred: expertise in identity and access management, cryptography, data security, enterprise application security, or software supply chain security.
• Preferred: experience with SBOM generation, artifact signing, and SLSA-aligned practices.
• Preferred: experience collaborating with internal IT, operations, or platform engineering teams.
• Preferred: experience defining and utilizing security metrics.
• Preferred certifications: CISSP, CSSLP, CCSP, or GIAC.
• Medical, dental and vision insurance.
• 401(k) plan with a Cisco matching contribution.
• Paid parental leave.
• Short- and long-term disability coverage.
• Basic life insurance.
• Cisco restricted stock unit grants may be available.
• 10 paid holidays per full calendar year.
• 1 floating holiday for non-exempt employees.
• 1 paid day off for the employee’s birthday.
• Paid year-end holiday shutdown.
• 4 paid days off for personal wellness.
• 16 days of paid vacation per full calendar year for non-exempt employees.
• Flexible vacation time off program for eligible exempt employees.
• 80 hours of sick time off provided at hire and each January 1st thereafter.
• Up to 80 hours of unused sick time carried forward.
• Additional paid time away for critical or emergency family matters.
• Optional 10 paid volunteer days per full calendar year.
• Annual bonuses for non-sales roles.
• Incentive compensation for sales-plan employees.
GitLab
GitLab
Lovesac
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.