1 day ago
Base Salary
$234k - $330k/yr
Responsibilities
- Define and drive application security architecture across software platforms and services.
- Design trust boundaries, sandboxing models, execution guardrails, and least-privilege controls for autonomous agents and LLM tool-calling workflows.
- Architect authentication, authorization, and security controls for MCP servers, tool registries, APIs, and external integrations.
- Establish security standards for OpenAPI, TypeSpec, and gRPC/Protobuf contracts, including automated contract testing and schema validation.
- Lead architectural threat modeling and create reusable secure software patterns, cryptographic utilities, and session management frameworks.
- Architect CI/CD security gates covering SAST, DAST, IAST, software composition analysis, container signing, and SBOM tracking.
- Define policy-as-code security baselines using frameworks such as OPA/Rego and Cedar.
- Act as the principal escalation point for application security architecture reviews and critical vulnerability disclosures.
- Mentor senior software engineers on defensive coding, API security, and zero-trust application design.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or a related technical field.
- 15+ years of experience in software engineering and application security architecture, including distributed application design, security, and operations.
- Experience with OWASP Top 10, OWASP API Top 10, CWE/SANS 25, or zero-trust application patterns.
- Experience with identity and access governance technologies or models including OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, RBAC, ABAC, or ReBAC.
- Experience with at least one backend language: Python, Go, TypeScript/Node.js, Rust, or Java.
- Experience integrating security controls into cloud-native architectures involving Kubernetes, AWS, GCP, Azure, API gateways, or service meshes.
- Preferred experience with MCP or similar AI tool-invocation interfaces.
- Preferred experience writing policy-as-code engines or custom linter/SAST rules using tools such as Open Policy Agent, AWS Cedar, Oso/Polar, Semgrep, or CodeQL.
- Preferred application security research, CVE publication, open-source security tooling, or industry working-group experience.
- Preferred experience evaluating and securing LLM-powered applications, tool-use execution loops, and RAG architectures.
- Relevant security certifications such as CISSP, CSSLP, CCSP, or AWS Certified Security are preferred.
Benefits
- Starting base salary range is $233,900.00 to $330,400.00, excluding incentive compensation, equity, and benefits.
- Benefits may include medical, dental and vision insurance, a 401(k) plan with Cisco matching, paid parental leave, disability coverage, and basic life insurance.
- Eligible employees may receive Cisco restricted stock unit grants.
- Paid time off includes holidays, personal wellness days, sick time, vacation or flexible vacation, and additional family emergency leave subject to policy.
- Optional paid volunteer time and annual bonuses may be available for non-sales roles.
Categories
About Cisco
Cisco designs and sells networking, security, and collaboration platforms for enterprises, service providers, and governments, spanning routers and switches, Wi‑Fi, firewalls, zero‑trust, observability, and cloud-managed IT (Meraki) plus Webex. Its business model mixes hardware, software subscriptions, and support/consulting services. Founded in 1984 and headquartered in San Jose, California, Cisco is a public company traded on Nasdaq and serves customers across data centers, campuses, and service provider networks.
