6 days ago
Base Salary
$214k - $310k/yr
Responsibilities
- Design and build secure, scalable infrastructure and developer platforms with security controls embedded by default.
- Harden Kubernetes control planes, GitOps systems, CI/CD pipelines, and observability stacks.
- Drive Zero Trust through workload identity, continuous verification, and micro-segmentation.
- Own the security and reliability posture of secrets management, PKI, IAM governance, and other critical services.
- Lead cross-team incident response and blameless post-mortems that result in permanent engineering fixes.
- Automate security and compliance through policy-as-code and automated evidence collection.
- Set technical direction and advise engineering leadership on security, velocity, and reliability trade-offs.
Requirements
- Bachelor's degree plus 12 years of related experience, master's degree plus 8 years, or PhD plus 5 years.
- At least 5 years of hands-on production experience operating and scaling AWS, Azure, or GCP, including cloud security posture ownership, IAM, KMS or secrets management, network controls, and CSPM or equivalent tooling.
- At least 3 years building production security automation and tooling in Python and/or Go.
- At least 5 years applying SRE practices, including SLIs, SLOs, error budgets, incident command, and post-mortems.
- At least 5 years applying production security fundamentals including threat modeling, secure-by-default architecture, least privilege, workload identity, secrets and certificate lifecycle management, and vulnerability management at scale.
- Preferred experience includes Kubernetes security, RBAC, Network Policies, Pod Security Standards, admission controllers, image signing, control-plane hardening, service mesh mTLS, Terraform, OPA, Kyverno, Checkov, tfsec, ArgoCD, Flux, SAST, SCA, security scanning, SBOM generation, and artifact signing.
- Preferred experience includes Falco, eBPF-based detection, SIEM, CSPM or CNAPP platforms, Prometheus, Grafana, OpenTelemetry, AI/ML workload and MLOps security, and security automation using AI/LLM capabilities.
- Security certifications such as CISSP, CCSP, or AWS Certified Security – Specialty are preferred.
Benefits
- Hybrid role requiring candidates local to San Jose.
- Base salary range is $214,100 to $309,800, excluding incentive compensation, equity, and benefits.
- Medical, dental, and vision insurance, a 401(k) with Cisco matching contribution, paid parental leave, disability coverage, and basic life insurance are offered subject to eligibility.
- Eligible employees may receive Cisco restricted stock unit grants and annual bonuses subject to company policies.
- Paid holidays, a birthday day off, year-end shutdown, personal wellness days, vacation or flexible vacation, sick time, family emergency leave, and optional paid volunteer days are provided subject to applicable policies.
Tech Stack
Categories
About Cisco
Cisco is the worldwide technology leader that is revolutionizing the way organizations connect and protect in the AI era. For more than 40 years, Cisco has securely connected the world. With its industry leading AI-powered solutions and services, Cisco enables its customers, partners and communities to unlock innovation, enhance productivity and strengthen digital resilience. With purpose at its core, Cisco remains committed to creating a more connected and inclusive future for all.