
Software Security Lead
Posted 8 hours ago

Posted 8 hours ago
This is a fully remote position, open to applicants in North Carolina.
• Act as the security authority for Cisco’s IT and Enterprise Operations portfolio.
• Keep an updated, data-informed perspective on the security posture of the portfolio.
• Convert threat trends, architectural changes, and security liabilities into actionable priorities.
• Counsel and influence stakeholders in Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer teams.
• Evaluate and authorize secure designs across the entire portfolio.
• Implement security-by-design and security-by-default principles.
• Lead comprehensive threat modeling initiatives and link models to design choices.
• Safely incorporate AI into relevant platforms and utilize Software Security AI frameworks.
• Promote AI capabilities that enhance security outcomes.
• Coordinate with security subject-matter experts in fields such as cryptography and identity.
• Present prioritized unaddressed security risks and residual posture during release or delivery phases.
• Establish and oversee security engineering metrics, including risk reduction, mean time to remediate, security debt, and developer engagement.
• Bachelor’s degree in computer science, Engineering, or a related field, or equivalent hands-on experience.
• Over 7 years of experience in software/application security, secure software development, or security engineering, including in a senior or leadership role.
• Demonstrated experience in leading threat modeling and secure design/architecture evaluations for complex software systems, including AI- and LLM-enabled features.
• Proficiency in interpreting SAST, DAST, and SCA results.
• Experience in translating findings into risk-based, evidence-supported remediation recommendations.
• Familiarity with cloud-native applications and modern CI/CD pipelines, including containers and Kubernetes.
• Ability to influence engineering and product leadership and propel security outcomes across teams without direct authority.
• Preferred expertise in identity and access management, cryptography, data security, enterprise application security, or software supply chain security.
• Preferred experience with SBOM generation, artifact signing, and practices aligned with SLSA.
• Preferred collaboration experience with internal IT, operations, or platform engineering teams.
• Preferred experience in defining and utilizing security metrics.
• Relevant certifications such as CISSP, CSSLP, CCSP, or GIAC are preferred.
• Medical, dental, and vision insurance.
• 401(k) plan with a Cisco matching contribution.
• Paid parental leave.
• Short- and long-term disability coverage.
• Basic life insurance.
• Cisco restricted stock unit grants may be available.
• 10 paid holidays per full calendar year.
• 1 floating holiday for non-exempt employees.
• Paid birthday day off.
• Paid year-end holiday shutdown.
• 4 paid personal wellness days.
• 16 days of paid vacation per full calendar year for non-exempt employees.
• Flexible vacation time off program with no defined limit for eligible exempt employees.
• 80 hours of sick time off provided upon hire and each January 1st.
• Up to 80 hours of unused sick time carried forward annually.
• Additional paid time off for critical or emergency family matters.
• Optional 10 paid volunteer days per year.
• Annual bonuses for non-sales positions.
• Cisco careers site offers additional benefits and perks.
Arctiq
Cotiviti
Twilio
SimSpace
Get handpicked remote jobs straight to your inbox weekly.