Unknown Company
In this Principal Software Engineering role at Cisco Systems, you will help set the security direction for software platforms and services, with a specific focus on application security and AI trust architecture. The work spans from defining security architecture and threat modeling to turning high-level strategy into secure-by-default, spec-driven engineering practices across cloud-to-box products.
This onsite position is based in San Jose, CA . The salary range for this role is USD 220,900 - 380,000 per year , and the position requires 15+ years of experience .
What you will do
- Define and drive security architecture across software platforms and services.
- Translate security strategy into hands-on engineering execution, ensuring products are secure from the cloud to the box.
- Lead cross-functional initiatives and mentor engineering team members.
- Engage with customers and leverage AI to improve the development lifecycle and threat prevention capabilities.
- Collaborate with application teams to design secure-by-default software patterns.
- Implement strict Model Context Protocol (MCP) access boundaries.
- Enforce spec-driven security contracts across application interfaces.
- Mitigate vulnerabilities unique to autonomous agent workflows, including prompt injection , indirect data exfiltration , and unauthorized tool invocation .
- Design trust boundaries , sandboxing models, and execution guardrails for autonomous application agents and LLM tool-calling workflows.
- Architect granular authentication , authorization , and least-privilege scoping for MCP servers, tool registries, and external integrations.
- Mitigate emerging AI threat vectors such as OWASP Top 10 for LLMs , indirect prompt injection , tool hijacking , credential harvesting , and context leakage .
- Establish spec-driven security standards across application contracts including OpenAPI , TypeSpec , and gRPC/Protobuf , embedding authentication schemes, data sanitization, and authorization scopes directly into machine-readable specs.
- Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA) , and injection vulnerabilities before deployment.
- Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi-tenant data boundaries.
- Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams.
- Architect and scale automated security gates in CI/CD pipelines including SAST , DAST , IAST , software composition analysis, container image signing, and SBOM tracking .
- Define policy-as-code frameworks (for example, OPA/Rego and Cedar ) to enforce deterministic security baselines across service deployments.
- Act as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures.
- Mentor senior engineers on defensive coding practices, modern API security standards, and zero-trust application design.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or a related technical field.
- 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications.
- Experience with application security frameworks such as OWASP Top 10 , OWASP API Top 10 , CWE/SANS 25 , or zero-trust application patterns.
- Experience in identity and access governance including one or more of OAuth 2.0 , OIDC , SAML , mTLS , SPIFFE/SPIRE , or fine-grained authorization models (RBAC , ABAC , ReBAC ).
- Experience in at least one backend language: Python , Go , TypeScript/Node.js , Rust , or Java .
- Experience integrating security controls into cloud-native architectures such as Kubernetes , AWS/GCP/Azure , API gateways, or service meshes.
Technologies
- Model Context Protocol (MCP); LLM tool-calling workflows
- OpenAPI, TypeSpec, gRPC/Protobuf
- Open Policy Agent (OPA), Rego, Cedar
- OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OWASP Top 10 for LLMs
- OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE
- RBAC, ABAC, ReBAC
- Python, Go, TypeScript/Node.js, Rust, Java
- Kubernetes, AWS, GCP, Azure, API gateways, service meshes
- SAST, DAST, IAST, software composition analysis
- Container image signing, SBOM tracking
- OPA/Rego (also listed separately), Semgrep, CodeQL, CVE
Benefits
- Medical, dental and vision insurance
- 401(k) plan with a Cisco matching contribution
- Paid parental leave
- Short and long-term disability coverage
- Basic life insurance
- Cisco restricted stock units that vest following continued employment with Cisco for defined periods
- 10 paid holidays per full calendar year
- 1 floating holiday for non-exempt employees
- 1 paid day off for employee’s birthday
- Paid year-end holiday shutdown
- 4 paid days off for personal wellness determined by Cisco
- Non-exempt employees: 16 days of paid vacation time per full calendar year, accrued at 4.92 hours per pay period for full-time employees
- Exempt employees: flexible vacation time off program with no defined limit (subject to availability and some business limitations)
- 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward
- Additional paid time away may be requested to deal with critical or emergency issues for family members
- Optional 10 paid days per full calendar year to volunteer
- For non-sales roles, employees may be eligible to earn annual bonuses subject to Cisco’s policies
Application window
The application window is expected to close on 10/30/2026 .
Preferred qualifications
- Experience with the security implications of the Model Context Protocol (MCP) or similar AI tool-invocation interfaces
- Experience writing policy-as-code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL)
- Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS)
- Relevant security certifications (for example, CISSP, CSSLP, CCSP, or AWS Certified Security)
- Experience evaluating and securing LLM-powered applications , tool-use execution loops, and RAG architectures
Principal Software Engineer — Application Security & AI Trust Architecture in san jose at Unknown Company
This position is listed as contract and onsite.