> Markdown version of [/jobs/ext/2752649-software-security-lead-remote](https://www.wearedevelopers.com/jobs/ext/2752649-software-security-lead-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Lead (Remote) - **Company:** Cisco Systems, Inc. - **Location:** Durham, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $151,600.0 - $222,400.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Data Security, Identity and Access Management, Automation of Marketing, Software Engineering, Enterprise Software Applications, Large Language Models, Software Security, Kubernetes, Information Technology, Cisco, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 6, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88262220/1 ## About the Role * Bachelor's degree in computer science, Engineering, or a related field (or equivalent practical experience), plus11+ years of experience in software/application security, secure software development, or security engineering, including a senior or lead role. * Proven experience leading threat modeling and secure design/architecture reviews for complex software systems, including AI- and LLM-enabled features. * Demonstrated experience interpreting SAST, DAST, and SCA results and translating findings into risk-based, evidence-backed remediation guidance,including forcloud-native applications and modern CI/CD pipelines (e.g., containers, Kubernetes). * Validated ability to influence engineering and product leadership and drive security outcomes across teams without direct authority. Preferred Qualifications * Depth in one or more specialized areas: identity and access management,cryptography, data security, enterprise application security, or software supply chain security (including SBOM generation, artifact signing, and SLSA-aligned practices). * Experience partnering with internal information technology, operations, or platform engineering teams on enterprise applications and workflow/automation platforms. * Experience defining and using security metrics to influence roadmap and investment decisions. * Relevant certifications such as CISSP, CSSLP, CCSP, or GIAC. ## Description This is a remote role and work may be performed anywhere in the contiguous United States. Meet the Team We'rethe team behind the security of Cisco's IT and Enterprise Operations platforms, tools, and applications. Our portfolio spans enterprise applications, workflow and automation platforms, and the developer and operations tooling that keeps Cisco running. We'reAI-forward.We'rebuilding a framework that puts AI to work at every step, a frameworkthatdrives a risk-based Security Development Lifecycle andclearsawaythe manual bottlenecks that slow security down, so security scales right alongside the business. We own software security across the full range of enterprise technology in scope, spanningapplication, cloud, identity, data, and supply chain. We act asa strategic partnertoProduct Management, Engineering, and IT and Enterprise Operations leadership. Together, we keep software security risk understood, managed, and aligned with Cisco's broader business risk posture. Your Impact As a Senior Software Security Lead,you'rethe security authority for the IT and Enterprise Operations portfolio. This is the personwhoengineering and platform teams turn to when security, architecture, and delivery pressures collide. What does it take to earn that trust? A sharp, risk-based instinct and the independence to act on it. This roleis responsible forthe full arc of portfolio risk. That meansmaintaininga current, data-backed view of security posture. It means translating threat trends, architectural shifts, and security debt into priorities that IT, Enterprise Operations, product, and engineering leadership can act on. It also means advising and influencing across Product Management, Engineering, IT/Enterprise Operations, and BusinessInformationSecurityOfficerpartners, aligning security priorities with businessobjectivesand the operational realities of our enterprise's internal technology. This lead sets the architecture bar, reviewing and approving secure designs across the portfolio. That means adapting "security by design" and "security by default" to eachcontext andmaking the architecture trade-off calls within scope. Threat modeling follows the same philosophy: lead it portfolio-wide, adjust depth and technique to the system at hand, and make sure every model is defensible, evidence-based, and tied directly to design decisions. AI adds a new frontier, and this role meets it head-on! That means integrating AI securely into in-scope platforms and applying Software Security AI frameworks.This also meansadvocating forAI capabilities that strengthen the team's security outcomes. It means threat-modelingand thinking like an attacker. Technical judgment ties it together.Coordinating Security SMEs, in areas like cryptography and identity. At release or delivery, this lead presents the prioritized list of unmitigated security risks, giving partners clear insight into residual posture. Finally, impact gets measured, not assumed. Defining and leading all aspects of the security engineering metrics that drive the portfolio, including risk reduction, mean time to remediate, security debt, and developer adoption, turns data into sharper decisions. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)