Cisco

Principal Software Engineer – Application Security & AI Trust Architecture

Cisco
Apply
1 day ago
San Jose, CA, USAStaff+
H1B sponsor

Base Salary

$234k - $330k/yr

Responsibilities

  • Define and drive application security architecture across software platforms and services.
  • Design trust boundaries, sandboxing models, execution guardrails, and least-privilege controls for autonomous agents and LLM tool-calling workflows.
  • Architect authentication, authorization, and security controls for MCP servers, tool registries, APIs, and external integrations.
  • Establish security standards for OpenAPI, TypeSpec, and gRPC/Protobuf contracts, including automated contract testing and schema validation.
  • Lead architectural threat modeling and create reusable secure software patterns, cryptographic utilities, and session management frameworks.
  • Architect CI/CD security gates covering SAST, DAST, IAST, software composition analysis, container signing, and SBOM tracking.
  • Define policy-as-code security baselines using frameworks such as OPA/Rego and Cedar.
  • Act as the principal escalation point for application security architecture reviews and critical vulnerability disclosures.
  • Mentor senior software engineers on defensive coding, API security, and zero-trust application design.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture, including distributed application design, security, and operations.
  • Experience with OWASP Top 10, OWASP API Top 10, CWE/SANS 25, or zero-trust application patterns.
  • Experience with identity and access governance technologies or models including OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, RBAC, ABAC, or ReBAC.
  • Experience with at least one backend language: Python, Go, TypeScript/Node.js, Rust, or Java.
  • Experience integrating security controls into cloud-native architectures involving Kubernetes, AWS, GCP, Azure, API gateways, or service meshes.
  • Preferred experience with MCP or similar AI tool-invocation interfaces.
  • Preferred experience writing policy-as-code engines or custom linter/SAST rules using tools such as Open Policy Agent, AWS Cedar, Oso/Polar, Semgrep, or CodeQL.
  • Preferred application security research, CVE publication, open-source security tooling, or industry working-group experience.
  • Preferred experience evaluating and securing LLM-powered applications, tool-use execution loops, and RAG architectures.
  • Relevant security certifications such as CISSP, CSSLP, CCSP, or AWS Certified Security are preferred.

Benefits

  • Starting base salary range is $233,900.00 to $330,400.00, excluding incentive compensation, equity, and benefits.
  • Benefits may include medical, dental and vision insurance, a 401(k) plan with Cisco matching, paid parental leave, disability coverage, and basic life insurance.
  • Eligible employees may receive Cisco restricted stock unit grants.
  • Paid time off includes holidays, personal wellness days, sick time, vacation or flexible vacation, and additional family emergency leave subject to policy.
  • Optional paid volunteer time and annual bonuses may be available for non-sales roles.
Cisco

About Cisco

10,000+ employees

Cisco designs and sells networking, security, and collaboration platforms for enterprises, service providers, and governments, spanning routers and switches, Wi‑Fi, firewalls, zero‑trust, observability, and cloud-managed IT (Meraki) plus Webex. Its business model mixes hardware, software subscriptions, and support/consulting services. Founded in 1984 and headquartered in San Jose, California, Cisco is a public company traded on Nasdaq and serves customers across data centers, campuses, and service provider networks.

Contact me