> Markdown version of [/jobs/ext/3549417-principal-software-engineer-application-security-ai-trust-architecture](https://www.wearedevelopers.com/jobs/ext/3549417-principal-software-engineer-application-security-ai-trust-architecture). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Software Engineer - Application Security & AI Trust Architecture - **Company:** Cisco Systems, Inc. - **Location:** San Jose, CA, United States - **Salary:** $233,900.0 - $330,400.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Business Logic, Computing Platforms, Microsoft Azure, Cloud Engineering, Cyber Security, Software Design Patterns, Protocol Buffers, Identity and Access Management, Python (Programming Language), Node.Js, OAuth, Open Source Technology, OpenID, Open Web Application Security, Role-Based Access Control, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Software Engineering, TypeScript, Openapi, Policy as Code, Retrieval-Augmented Generation, Large Language Models, Software Security, Backend, Agentic-AI, Kubernetes, Information Technology, Api Gateway, Model Context Protocol, Devsecops, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** October 2, 2026 - **Apply:** https://dejobs.org/x/x/FC381514FA61472BA1E8853E9397184E/job/ ## About the Role * Bachelor's degree in Computer Science, Engineering, or a related technical field. * 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications. * Experience in application security frameworks such as OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OR zero-trust application patterns. * Experience in identity and access governance including one or more of OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, or fine-grained authorization models (RBAC, ABAC, ReBAC). * Experience in at least one backend language (Python, Go, TypeScript/Node.js, Rust, or Java). * Experience integrating security controls into cloud-native architectures such as Kubernetes, AWS/GCP/Azure, API gateways, or service meshes., * Experience with security implications of the Model Context Protocol (MCP) or similar AI tool-invocation interfaces. * Experience writing policy-as-code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL). * Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS). * Relevant security certifications (e.g., CISSP, CSSLP, CCSP, or AWS Certified Security). * Experience evaluating and securing LLM-powered applications, tool-use execution loops, and RAG architectures. ## Description As a Principal Engineer leading software security, you will be a primary technical authority responsible for defining and driving the security architecture across our software platforms and services. You will bridge the gap between high-level security strategy and hands-on engineering execution, ensuring that our products are secure from the cloud to the box. You will lead cross-functional initiatives, mentor engineering team members, engage with our customers and leverage AI to revolutionize our development lifecycle and threat prevention capabilities. Rather than focusing on perimeter network defenses or traditional compliance auditing, you will operate as a software-first security leader-collaborating with application teams to design secure-by-default software patterns, implement strict Model Context Protocol (MCP) access boundaries, enforce spec-driven security contracts, and mitigate vulnerabilities unique to autonomous agent workflows (e.g., prompt injection, indirect data exfiltration, unauthorized tool invocation). AI & Agentic Application Security Architecture: * Design trust boundaries, sandboxing models, and execution guardrails for autonomous application agents and LLM tool-calling workflows. * Architect granular authentication, authorization, and least-privilege scoping for Model Context Protocol (MCP) servers, tool registries, and external integrations. * Mitigate emerging AI threat vectors (e.g., OWASP Top 10 for LLMs, indirect prompt injection, tool hijacking, credential harvesting, and context leakage). Spec-Driven Security & API Protection: * Establish spec-driven security standards across application contracts (OpenAPI, TypeSpec, gRPC/Protobuf), embedding authentication schemes, data sanitization, and authorization scopes directly into machine-readable specs. * Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA), and injection vulnerabilities prior to deployment. Threat Modeling & Secure-by-Design Engineering: * Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi-tenant data boundaries. * Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams. DevSecOps & Software Supply Chain Integrity: * Architect and scale automated security gates in CI/CD pipelines (SAST, DAST, IAST, software composition analysis, container image signing, and SBOM tracking). * Define policy-as-code (e.g., OPA/Rego, Cedar) frameworks to enforce deterministic security baselines across service deployments. Technical Direction, Governance & Incident Leadership: * Serve as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures. * Mentor senior software engineers on defensive coding practices, modern API security standards, and zero-trust application design. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)