> Markdown version of [/jobs/ext/2042912-technical-lead-threat-modeling-psirt](https://www.wearedevelopers.com/jobs/ext/2042912-technical-lead-threat-modeling-psirt). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Technical Lead (Threat Modeling, PSIRT) - **Company:** Arista Networks - **Location:** Dallas, TX, United States - **Experience:** Expert - **Salary:** $120,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Audit Trail, Border Gateway Protocol, Network Operating System (NOS), Cloud Computing, Cloud Computing Security, Cyber Security, Databases, Continuous Integration, Linux, Federal Information Processing Standards (FIPS), Monitoring of Systems, Information Systems Security Architecture Professional, Open Shortest Path First (OSPF), Open Web Application Security, Systems Development Life Cycle, Secure Coding, Simple Network Management Protocols, Software Engineering, Systems Integration, Data Logging, Network Switches, Application Specific Integrated Circuits, Software Security, Git, Cybercrime, Enterprise Integration, Gsuite, Grpc, Software Version Control, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 13, 2026 - **Apply:** https://www.careerjet.com/jobad/us1db7383135af68ef4d1189a35b82763b ## About the Role * Security Vulnerabilities & Exploit Theory: Deep understanding of software vulnerabilities, exploit mechanics (e.g., buffer overflows, race conditions, logical bypasses, dependency vulnerabilities), cryptography, and modern mitigation techniques. Strong familiarity with standard frameworks including CVSS, CWE, OWASP Top 10, and MITRE ATT * Networking & Switch Architecture: In-depth understanding of network switch architecture, composition, and management. Knowledge of network operating system internals (ideally Linux-based, such as Arista EOS), control plane protection, data plane forwarding, ASIC-level considerations, and protocols (e.g., BGP, OSPF, gRPC, SNMP). * Secure Development & SDLC: Robust knowledge of modern software engineering methodologies, version control (Git), and CI/CD pipelines. Hands-on experience integrating and managing AppSec tools (SAST/DAST) and implementing Threat Modeling practices in an enterprise environment. Experience & Operational Skills * Experience: 7+ years of experience in Product Security, Software Security Engineering, PSIRT operations, or Advanced Cloud Security Administration. * Cloud Infrastructure: Proven experience hardening enterprise/federal cloud spaces, specifically Google Workspace or major cloud providers (AWS/GCP), with an emphasis on access controls, logging, and audit logs. * Compliance Standards: Familiarity with Federal, State, and Local compliance regulations (e.g., FedRAMP, NIST, FIPS). * Communication: Exceptional ability to articulate highly technical security flaws and architectural concepts clearly to software developers, enterprise customers, and non-technical business executives alike. ## Description Product Security Program & Operations. In this role, you will serve as a core link between Arista's engineering groups, external security researchers, federal stakeholders, and executive leadership. This is not a purely administrative role; it requires a strong technical background in network operating systems, exploit mechanics, and secure software development. You will drive the product security vulnerability lifecycle, lead threat modeling and penetration testing strategies for Arista's switch architecture, integrate security mechanisms into our software development lifecycle (SDLC), and ensure our federal cloud environments maintain an aggressive security posture. Alternate Work Locations: Dallas, TX | Raleigh, NC What Will You Do?, 1. Technical PSIRT, Vulnerability & Exploit Analysis * Vulnerability Lifecycle Management: Drive the end-to-end process of turning discovered or reported vulnerabilities within Arista products into verified, highly accurate security advisories. * Technical Triage & Root Cause Analysis: Triage incoming vulnerability reports from internal testing, automated tools, and external researchers. Evaluate exploitability, proof-of-concepts (PoCs), and determine blast radius/severity using CVSS and CWE frameworks. * Developer Enablement & Advisory: Partner directly with software engineers to explain root-cause vulnerabilities, provide remediation guidance, and oversee the drafting and structural validation of technical security advisories. * Coordinated Disclosure: Coordinate with the National Vulnerability Database (NVD), MITRE, and external research teams to ensure professional, precise, and timely disclosure. * Metrics Strategy: Analyze vulnerability trends to identify systemic security gaps, delivering data-driven architecture recommendations to senior engineering leadership. 2. Advanced Penetration Testing & Switch Architecture Security * Program Oversight & Scoping: Manage the comprehensive execution of third-party security testing and red-teaming across Arista's product portfolio. * Architectural Threat Modeling: Translate Arista's switch architecture, control/data plane separation, and Sysdb-driven state mechanisms into clear threat vectors to scope high-value targets for penetration testers. * Remediation & Validation: Critically review penetration testing findings, distinguish theoretical risks from practical exploits, and validate that engineering fixes comprehensively eliminate the underlying architectural susceptibility to security issues. * Executive Reporting: Distill complex cryptographic, hardware, or software vulnerabilities into clear risk profiles for executive management and enterprise customers. 3. Secure SDLC & DevSecOps Engineering * Shifting Left: Architect, implement, and optimize security checkpoints throughout Arista's development lifecycles to detect flaws before code reaches production. * Pipeline Integration: Drive the adoption and tuning of automated security tooling (SAST, DAST, SCA, and container scanning) directly into the CI/CD infrastructure. * Secure Coding Standards: Define and evangelize secure coding practices, threat modeling principles (e.g., STRIDE), and framework-level mitigations to mitigate common software flaws (memory unsafety, injection, privilege escalation). * Continuous Improvement: Audit existing development workflows to eliminate friction between engineering velocity and product security compliance. 4. Federal Cloud Security Administration & Infrastructure Monitoring * Federal Workspace Administration: Securely administer and monitor the dedicated Google Workspace environment for Arista Federal. * Compliance Hardening: Configure and audit cloud infrastructure settings in strict accordance with industry frameworks and federal regulations (e.g., FedRAMP, NIST 800-53). * Threat Hunting & Incident Response: Actively monitor logging, alerting systems, and audit trails to identify, investigate, and remediate suspicious activity or misconfigurations. * Change Management: Lead security risk assessments for all proposed system alterations in coordination with Arista IT Security and Federal Management. 5. Customer Trust & Regulatory Compliance * Technical Customer Engagement: Act as the primary technical subject matter expert (SME) during deep-dive security discussions with enterprise and federal customers. * Regulatory Advisory: Authoritatively address complex customer compliance inquiries regarding product architecture, supply chain integrity, and federal security mandates. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)