About The Position

At Cisco, we are redefining how our customers experience technology through the power of Cisco IQ Services and Applications. Our mission is to transform CX delivery by building intelligent, scalable platforms that anticipate needs rather than just reacting to them. As a member of our global, diverse, and AI-spec driven team, you will operate at the absolute frontier of innovation. We are deeply committed to leveraging the latest advancements in AI to build robust solutions that solve complex technical challenges for our enterprise customers, fostering a culture of curiosity, collaboration, and rapid iteration.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications.
  • Experience in application security frameworks such as OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OR zero-trust application patterns.
  • Experience in identity and access governance including one or more of OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, or fine-grained authorization models (RBAC, ABAC, ReBAC).
  • Experience in at least one backend language (Python, Go, TypeScript/Node.js, Rust, or Java).
  • Experience integrating security controls into cloud-native architectures such as Kubernetes, AWS/GCP/Azure, API gateways, or service meshes.

Nice To Haves

  • Experience with security implications of the Model Context Protocol (MCP) or similar AI tool-invocation interfaces.
  • Experience writing policy-as-code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL).
  • Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS).
  • Relevant security certifications (e.g., CISSP, CSSLP, CCSP, or AWS Certified Security).
  • Experience evaluating and securing LLM-powered applications, tool-use execution loops, and RAG architectures.

Responsibilities

  • Serve as a primary technical authority responsible for defining and driving the security architecture across software platforms and services.
  • Bridge the gap between high-level security strategy and hands-on engineering execution, ensuring products are secure from the cloud to the box.
  • Lead cross-functional initiatives, mentor engineering team members, engage with customers, and leverage AI to revolutionize the development lifecycle and threat prevention capabilities.
  • Design trust boundaries, sandboxing models, and execution guardrails for autonomous application agents and LLM tool-calling workflows.
  • Architect granular authentication, authorization, and least-privilege scoping for Model Context Protocol (MCP) servers, tool registries, and external integrations.
  • Mitigate emerging AI threat vectors (e.g., OWASP Top 10 for LLMs, indirect prompt injection, tool hijacking, credential harvesting, and context leakage).
  • Establish spec-driven security standards across application contracts (OpenAPI, TypeSpec, gRPC/Protobuf), embedding authentication schemes, data sanitization, and authorization scopes directly into machine-readable specs.
  • Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA), and injection vulnerabilities prior to deployment.
  • Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi-tenant data boundaries.
  • Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams.
  • Architect and scale automated security gates in CI/CD pipelines (SAST, DAST, IAST, software composition analysis, container image signing, and SBOM tracking).
  • Define policy-as-code (e.g., OPA/Rego, Cedar) frameworks to enforce deterministic security baselines across service deployments.
  • Serve as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures.
  • Mentor senior software engineers on defensive coding practices, modern API security standards, and zero-trust application design.

Benefits

  • medical, dental and vision insurance
  • a 401(k) plan with a Cisco matching contribution
  • paid parental leave
  • short and long-term disability coverage
  • basic life insurance
  • grants of Cisco restricted stock units
  • 10 paid holidays per full calendar year
  • 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • paid year-end holiday shutdown
  • 4 paid days off for personal wellness
  • 16 days of paid vacation time per full calendar year (non-exempt employees)
  • flexible vacation time off program (exempt employees)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter
  • up to 80 hours of unused sick time carried forward
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • annual bonuses (for non-sales roles)
  • performance-based incentive pay (for sales roles)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service