Unknown Company

Principal Software Engineer — Application Security & AI Trust Architecture

san jose, ca • Posted Today
Onsite Contract IT Management & IT Project Management

In this Principal Software Engineering role at Cisco Systems, you will help set the security direction for software platforms and services, with a specific focus on application security and AI trust architecture. The work spans from defining security architecture and threat modeling to turning high-level strategy into secure-by-default, spec-driven engineering practices across cloud-to-box products.

This onsite position is based in San Jose, CA . The salary range for this role is USD 220,900 - 380,000 per year , and the position requires 15+ years of experience .

What you will do

  • Define and drive security architecture across software platforms and services.
  • Translate security strategy into hands-on engineering execution, ensuring products are secure from the cloud to the box.
  • Lead cross-functional initiatives and mentor engineering team members.
  • Engage with customers and leverage AI to improve the development lifecycle and threat prevention capabilities.
  • Collaborate with application teams to design secure-by-default software patterns.
  • Implement strict Model Context Protocol (MCP) access boundaries.
  • Enforce spec-driven security contracts across application interfaces.
  • Mitigate vulnerabilities unique to autonomous agent workflows, including prompt injection , indirect data exfiltration , and unauthorized tool invocation .
  • Design trust boundaries , sandboxing models, and execution guardrails for autonomous application agents and LLM tool-calling workflows.
  • Architect granular authentication , authorization , and least-privilege scoping for MCP servers, tool registries, and external integrations.
  • Mitigate emerging AI threat vectors such as OWASP Top 10 for LLMs , indirect prompt injection , tool hijacking , credential harvesting , and context leakage .
  • Establish spec-driven security standards across application contracts including OpenAPI , TypeSpec , and gRPC/Protobuf , embedding authentication schemes, data sanitization, and authorization scopes directly into machine-readable specs.
  • Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA) , and injection vulnerabilities before deployment.
  • Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi-tenant data boundaries.
  • Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams.
  • Architect and scale automated security gates in CI/CD pipelines including SAST , DAST , IAST , software composition analysis, container image signing, and SBOM tracking .
  • Define policy-as-code frameworks (for example, OPA/Rego and Cedar ) to enforce deterministic security baselines across service deployments.
  • Act as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures.
  • Mentor senior engineers on defensive coding practices, modern API security standards, and zero-trust application design.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications.
  • Experience with application security frameworks such as OWASP Top 10 , OWASP API Top 10 , CWE/SANS 25 , or zero-trust application patterns.
  • Experience in identity and access governance including one or more of OAuth 2.0 , OIDC , SAML , mTLS , SPIFFE/SPIRE , or fine-grained authorization models (RBAC , ABAC , ReBAC ).
  • Experience in at least one backend language: Python , Go , TypeScript/Node.js , Rust , or Java .
  • Experience integrating security controls into cloud-native architectures such as Kubernetes , AWS/GCP/Azure , API gateways, or service meshes.

Technologies

  • Model Context Protocol (MCP); LLM tool-calling workflows
  • OpenAPI, TypeSpec, gRPC/Protobuf
  • Open Policy Agent (OPA), Rego, Cedar
  • OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OWASP Top 10 for LLMs
  • OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE
  • RBAC, ABAC, ReBAC
  • Python, Go, TypeScript/Node.js, Rust, Java
  • Kubernetes, AWS, GCP, Azure, API gateways, service meshes
  • SAST, DAST, IAST, software composition analysis
  • Container image signing, SBOM tracking
  • OPA/Rego (also listed separately), Semgrep, CodeQL, CVE

Benefits

  • Medical, dental and vision insurance
  • 401(k) plan with a Cisco matching contribution
  • Paid parental leave
  • Short and long-term disability coverage
  • Basic life insurance
  • Cisco restricted stock units that vest following continued employment with Cisco for defined periods
  • 10 paid holidays per full calendar year
  • 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • Paid year-end holiday shutdown
  • 4 paid days off for personal wellness determined by Cisco
  • Non-exempt employees: 16 days of paid vacation time per full calendar year, accrued at 4.92 hours per pay period for full-time employees
  • Exempt employees: flexible vacation time off program with no defined limit (subject to availability and some business limitations)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • For non-sales roles, employees may be eligible to earn annual bonuses subject to Cisco’s policies

Application window

The application window is expected to close on 10/30/2026 .

Preferred qualifications

  • Experience with the security implications of the Model Context Protocol (MCP) or similar AI tool-invocation interfaces
  • Experience writing policy-as-code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL)
  • Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS)
  • Relevant security certifications (for example, CISSP, CSSLP, CCSP, or AWS Certified Security)
  • Experience evaluating and securing LLM-powered applications , tool-use execution loops, and RAG architectures
#J-18808-Ljbffr

Principal Software Engineer — Application Security & AI Trust Architecture in san jose at Unknown Company

This position is listed as contract and onsite.

Back to Job Search