Software Security Lead (Remote)

CiscoOklahoma City, NC
Remote

About The Position

We're the team behind the security of Cisco's IT and Enterprise Operations platforms, tools, and applications. Our portfolio spans enterprise applications, workflow and automation platforms, and the developer and operations tooling that keeps Cisco running. We're AI-forward. We're building a framework that puts AI to work at every step, a framework that drives a risk-based Security Development Lifecycle and clears away the manual bottlenecks that slow security down, so security scales right alongside the business. We own software security across the full range of enterprise technology in scope, spanning application, cloud, identity, data, and supply chain. We act as a strategic partner to Product Management, Engineering, and IT and Enterprise Operations leadership. Together, we keep software security risk understood, managed, and aligned with Cisco's broader business risk posture.

Requirements

  • Bachelor’s degree in computer science, Engineering, or a related field (or equivalent practical experience)
  • 11+ years of experience in software/application security, secure software development, or security engineering
  • Senior or lead role experience
  • Proven experience leading threat modeling and secure design/architecture reviews for complex software systems, including AI- and LLM-enabled features.
  • Demonstrated experience interpreting SAST, DAST, and SCA results and translating findings into risk-based, evidence-backed remediation guidance, including for cloud-native applications and modern CI/CD pipelines (e.g., containers, Kubernetes).
  • Validated ability to influence engineering and product leadership and drive security outcomes across teams without direct authority.

Nice To Haves

  • Depth in one or more specialized areas: identity and access management, cryptography, data security, enterprise application security, or software supply chain security (including SBOM generation, artifact signing, and SLSA-aligned practices).
  • Experience partnering with internal information technology, operations, or platform engineering teams on enterprise applications and workflow/automation platforms.
  • Experience defining and using security metrics to influence roadmap and investment decisions.
  • Relevant certifications such as CISSP, CSSLP, CCSP, or GIAC.

Responsibilities

  • Responsible for the full arc of portfolio risk, maintaining a current, data-backed view of security posture.
  • Translating threat trends, architectural shifts, and security debt into priorities that IT, Enterprise Operations, product, and engineering leadership can act on.
  • Advising and influencing across Product Management, Engineering, IT/Enterprise Operations, and Business Information Security Officer partners, aligning security priorities with business objectives and the operational realities of our enterprise's internal technology.
  • Setting the architecture bar, reviewing and approving secure designs across the portfolio, adapting "security by design" and "security by default" to each context and making the architecture trade-off calls within scope.
  • Leading threat modeling portfolio-wide, adjusting depth and technique to the system at hand, and ensuring every model is defensible, evidence-based, and tied directly to design decisions.
  • Integrating AI securely into in-scope platforms and applying Software Security AI frameworks.
  • Advocating for AI capabilities that strengthen the team's security outcomes.
  • Coordinating Security SMEs, in areas like cryptography and identity.
  • Presenting the prioritized list of unmitigated security risks at release or delivery, giving partners clear insight into residual posture.
  • Defining and leading all aspects of the security engineering metrics that drive the portfolio, including risk reduction, mean time to remediate, security debt, and developer adoption.

Benefits

  • medical, dental and vision insurance
  • a 401(k) plan with a Cisco matching contribution
  • paid parental leave
  • short and long-term disability coverage
  • basic life insurance
  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • paid year-end holiday shutdown
  • 4 paid days off for personal wellness determined by Cisco
  • 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees (non-exempt)
  • flexible vacation time off program (exempt)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter
  • up to 80 hours of unused sick time carried forward from one calendar year to the next
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • annual bonuses (for non-sales roles)
  • performance-based incentive pay (for sales roles)
  • grants of Cisco restricted stock units
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service