Software Security Lead (Remote)

CiscoResearch Triangle Park, NC
$139,300 - $203,600Remote

About The Position

We're the team behind the security of Cisco's IT and Enterprise Operations platforms, tools, and applications. Our portfolio spans enterprise applications, workflow and automation platforms, and the developer and operations tooling that keeps Cisco running. We're AI-forward. We're building a framework that puts AI to work at every step, a framework that drives a risk-based Security Development Lifecycle and clears away the manual bottlenecks that slow security down, so security scales right alongside the business. We own software security across the full range of enterprise technology in scope, spanning application, cloud, identity, data, and supply chain. We act as a strategic partner to Product Management, Engineering, and IT and Enterprise Operations leadership. Together, we keep software security risk understood, managed, and aligned with Cisco's broader business risk posture. As a senior Software Security Lead, you're the security authority for the IT and Enterprise Operations portfolio. This is the person who engineering and platform teams turn to when security, architecture, and delivery pressures collide. What does it take to earn that trust? A sharp, risk-based instinct and the independence to act on it. This role is responsible for the full arc of portfolio risk. That means maintaining a current, data-backed view of security posture. It means translating threat trends, architectural shifts, and security debt into priorities that IT, Enterprise Operations, product, and engineering leadership can act on. It also means advising and influencing across Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners, aligning security priorities with business objectives and the operational realities of our enterprise's internal technology. This lead sets the architecture bar, reviewing and approving secure designs across the portfolio. That means adapting "security by design" and "security by default" to each context and making the architecture trade-off calls within scope. Threat modeling follows the same philosophy: lead it portfolio-wide, adjust depth and technique to the system at hand, and make sure every model is defensible, evidence-based, and tied directly to design decisions. AI adds a new frontier, and this role meets it head-on! That means integrating AI securely into in-scope platforms and applying Software Security AI frameworks. This also means advocating for AI capabilities that strengthen the team's security outcomes. It means threat-modeling and thinking like an attacker. Technical judgment ties it together. Coordinating Security SMEs, in areas like cryptography and identity. At release or delivery, this lead presents the prioritized list of unmitigated security risks, giving partners clear insight into residual posture. Finally, impact gets measured, not assumed. Defining and leading all aspects of the security engineering metrics that drive the portfolio, including risk reduction, mean time to remediate, security debt, and developer adoption, turns data into sharper decisions.

Requirements

  • Bachelor’s degree in computer science, Engineering, or a related field (or equivalent practical experience)
  • 7+ years of experience in software/application security, secure software development, or security engineering
  • Experience in a senior or lead role
  • Proven experience leading threat modeling and secure design/architecture reviews for complex software systems, including AI- and LLM-enabled features.
  • Demonstrated experience interpreting SAST, DAST, and SCA results and translating findings into risk-based, evidence-backed remediation guidance, including for cloud-native applications and modern CI/CD pipelines (e.g., containers, Kubernetes).
  • Validated ability to influence engineering and product leadership and drive security outcomes across teams without direct authority.

Nice To Haves

  • Depth in one or more specialized areas: identity and access management, cryptography, data security, enterprise application security, or software supply chain security (including SBOM generation, artifact signing, and SLSA-aligned practices).
  • Experience partnering with internal information technology, operations, or platform engineering teams on enterprise applications and workflow/automation platforms.
  • Experience defining and using security metrics to influence roadmap and investment decisions.
  • Relevant certifications such as CISSP, CSSLP, CCSP, or GIAC.

Responsibilities

  • Responsible for the full arc of portfolio risk.
  • Maintaining a current, data-backed view of security posture.
  • Translating threat trends, architectural shifts, and security debt into priorities.
  • Advising and influencing across Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners.
  • Setting the architecture bar, reviewing and approving secure designs across the portfolio.
  • Adapting "security by design" and "security by default" to each context.
  • Making architecture trade-off calls within scope.
  • Leading threat modeling portfolio-wide, adjusting depth and technique to the system at hand.
  • Integrating AI securely into in-scope platforms and applying Software Security AI frameworks.
  • Advocating for AI capabilities that strengthen the team's security outcomes.
  • Coordinating Security SMEs, in areas like cryptography and identity.
  • Presenting the prioritized list of unmitigated security risks at release or delivery.
  • Defining and leading all aspects of the security engineering metrics that drive the portfolio, including risk reduction, mean time to remediate, security debt, and developer adoption.

Benefits

  • medical, dental and vision insurance
  • a 401(k) plan with a Cisco matching contribution
  • paid parental leave
  • short and long-term disability coverage
  • basic life insurance
  • 10 paid holidays per full calendar year
  • 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • paid year-end holiday shutdown
  • 4 paid days off for personal wellness
  • 16 days of paid vacation time per full calendar year (non-exempt employees)
  • flexible vacation time off program (exempt employees)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter
  • up to 80 hours of unused sick time carried forward
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • annual bonuses (for non-sales roles)
  • performance-based incentive pay (for sales roles)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service