Principal Software Engineer — Application Security & AI Trust Architecture

Cybersecurity Jobs

San Jose (CA)

On-site

USD 221,000 - 380,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical insurance
401(k) plan with Cisco match
Paid parental leave
Flexibility in time off

Job summary

Cisco Systems is seeking a Principal Software Engineer to set security direction for software platforms and services, focusing on application security and AI trust architecture. You will translate strategy into secure-by-default engineering practices across cloud-to-box products, with an onsite base in San Jose, CA.

The role requires 15+ years of experience and offers a comprehensive security-focused environment with opportunities to mentor engineers and shape security standards including MCP,

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture.
  • Experience with OWASP Top 10, OWASP API Top 10, CWE/SANS 25, or zero-trust patterns.
  • Experience in identity and access governance: OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, RBAC/ABAC/ReBAC.
  • Experience in at least one backend language: Python, Go, TypeScript/Node.js, Rust, or Java.
  • Experience in cloud-native security: Kubernetes, AWS/GCP/Azure, API gateways, service meshes.

Responsibilities

  • Define and drive security architecture across software platforms and services.
  • Translate security strategy into hands-on engineering execution for secure-by-default software.
  • Lead cross-functional initiatives and mentor engineering teams.
  • Engage with customers and leverage AI to improve threat prevention and lifecycle.
  • Collaborate with application teams to design secure-by-default patterns.
  • Implement MCP access boundaries and spec-driven security contracts.
  • Mitigate AI threat vectors including prompt injection and data leakage.
  • Design trust boundaries, sandboxing, and guardrails for autonomous agents and LLM tool-calling.
  • Architect authentication/authorization with least-privilege scoping for MCP servers and integrations.
  • Develop CI/CD security gates: SAST/DAST/IAST, SBOM tracking, image signing.

Skills

Security architecture
Threat modeling
Zero-trust
Mentoring
Security governance
Customer engagement
AI trust architecture
Hands-on security engineering

Education

Bachelor’s degree

Tools

Kubernetes
AWS
GCP
Azure
OpenAPI
TypeSpec
gRPC/Protobuf
OPA/Rego
Cedar
Semgrep
CodeQL
SBOM tracking

Job description

In this Principal Software Engineering role at Cisco Systems, you will help set the security direction for software platforms and services, with a specific focus on application security and AI trust architecture. The work spans from defining security architecture and threat modeling to turning high-level strategy into secure-by-default, spec-driven engineering practices across cloud-to-box products.

This onsite position is based in San Jose, CA. The salary range for this role is USD 220,900 - 380,000 per year, and the position requires 15+ years of experience.

What you will do
  • Define and drive security architecture across software platforms and services.
  • Translate security strategy into hands-on engineering execution, ensuring products are secure from the cloud to the box.
  • Lead cross-functional initiatives and mentor engineering team members.
  • Engage with customers and leverage AI to improve the development lifecycle and threat prevention capabilities.
  • Collaborate with application teams to design secure-by-default software patterns.
  • Implement strict Model Context Protocol (MCP) access boundaries.
  • Enforce spec-driven security contracts across application interfaces.
  • Mitigate vulnerabilities unique to autonomous agent workflows, including prompt injection, indirect data exfiltration, and unauthorized tool invocation.
  • Design trust boundaries, sandboxing models, and execution guardrails for autonomous application agents and LLM tool-calling workflows.
  • Architect granular authentication, authorization, and least-privilege scoping for MCP servers, tool registries, and external integrations.
  • Mitigate emerging AI threat vectors such as OWASP Top 10 for LLMs, indirect prompt injection, tool hijacking, credential harvesting, and context leakage.
  • Establish spec-driven security standards across application contracts including OpenAPI, TypeSpec, and gRPC/Protobuf, embedding authentication schemes, data sanitization, and authorization scopes directly into machine-readable specs.
  • Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA), and injection vulnerabilities before deployment.
  • Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi-tenant data boundaries.
  • Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams.
  • Architect and scale automated security gates in CI/CD pipelines including SAST, DAST, IAST, software composition analysis, container image signing, and SBOM tracking.
  • Define policy-as-code frameworks (for example, OPA/Rego and Cedar) to enforce deterministic security baselines across service deployments.
  • Act as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures.
  • Mentor senior engineers on defensive coding practices, modern API security standards, and zero-trust application design.
Requirements
  • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications.
  • Experience with application security frameworks such as OWASP Top 10, OWASP API Top 10, CWE/SANS 25, or zero-trust application patterns.
  • Experience in identity and access governance including one or more of OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, or fine-grained authorization models (RBAC, ABAC, ReBAC).
  • Experience in at least one backend language: Python, Go, TypeScript/Node.js, Rust, or Java.
  • Experience integrating security controls into cloud-native architectures such as Kubernetes, AWS/GCP/Azure, API gateways, or service meshes.
Technologies
  • Model Context Protocol (MCP); LLM tool-calling workflows
  • OpenAPI, TypeSpec, gRPC/Protobuf
  • Open Policy Agent (OPA), Rego, Cedar
  • OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OWASP Top 10 for LLMs
  • OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE
  • RBAC, ABAC, ReBAC
  • Python, Go, TypeScript/Node.js, Rust, Java
  • Kubernetes, AWS, GCP, Azure, API gateways, service meshes
  • SAST, DAST, IAST, software composition analysis
  • Container image signing, SBOM tracking
  • OPA/Rego (also listed separately), Semgrep, CodeQL, CVE
Benefits
  • Medical, dental and vision insurance
  • 401(k) plan with a Cisco matching contribution
  • Paid parental leave
  • Short and long-term disability coverage
  • Basic life insurance
  • Cisco restricted stock units that vest following continued employment with Cisco for defined periods
  • 10 paid holidays per full calendar year
  • 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • Paid year-end holiday shutdown
  • 4 paid days off for personal wellness determined by Cisco
  • Non-exempt employees: 16 days of paid vacation time per full calendar year, accrued at 4.92 hours per pay period for full-time employees
  • Exempt employees: flexible vacation time off program with no defined limit (subject to availability and some business limitations)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • For non-sales roles, employees may be eligible to earn annual bonuses subject to Cisco’s policies
Application window

The application window is expected to close on 10/30/2026.

Preferred qualifications
  • Experience with the security implications of the Model Context Protocol (MCP) or similar AI tool-invocation interfaces
  • Experience writing policy-as-code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL)
  • Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS)
  • Relevant security certifications (for example, CISSP, CSSLP, CCSP, or AWS Certified Security)
  • Experience evaluating and securing LLM-powered applications, tool-use execution loops, and RAG architectures
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Security Lead (Remote)
Software Security Lead (Remote)

Cisco • Augusta (ME)

On-site
USD 139,000 - 204,000
Medical, dental, vision insurance
401(k) with company match
Parental leave
+1
Principal Software Engineer – Application Security & AI Trust Architecture
Principal Software Engineer – Application Security & AI Trust Architecture

Engg • San Jose (CA)

On-site
USD 180,000 - 280,000
Principal Software Engineer - Application Security & AI Trust Architecture
Principal Software Engineer - Application Security & AI Trust Architecture

Cisco Systems, Inc. • San Jose (CA)

On-site
USD 234,000 - 330,000
Annual bonuses
Medical, dental, vision coverage
401(k) with company match
+2
Principal Software Engineer – Application Security & AI Trust Architecture
Principal Software Engineer – Application Security & AI Trust Architecture

020 Cisco Systems, Inc. • San Jose (CA)

On-site
USD 234,000 - 330,000
Principal Software Engineer (SSE) (Onsite-Milpitas)
Principal Software Engineer (SSE) (Onsite-Milpitas)

Cisco • Milpitas (CA)

On-site
USD 251,000 - 363,000
Medical, dental and vision insurance
401(k) plan with Cisco matching
Paid parental leave
+3
Principal Software Engineer – Application Security & AI Trust Architecture
Principal Software Engineer – Application Security & AI Trust Architecture

Cisco Systems, Inc • San Jose (CA)

On-site
USD 234,000 - 330,000
Medical, dental and vision insurance
401(k) plan with Cisco matching
Paid parental leave
+1
Software Security Lead (Remote)
Software Security Lead (Remote)

Cisco • Ann Arbor (MI)

On-site
USD 139,000 - 204,000
Software Security Lead (Remote)
Software Security Lead (Remote)

Cisco • Atlanta (GA)

On-site
USD 149,000 - 251,000
Software Engineering Technical Leader - BackEnd
Software Engineering Technical Leader - BackEnd

020 Cisco Systems, Inc. • Richardson (TX)

On-site
USD 152,000 - 222,000
Medical, dental, and vision insurance
401(k) with Cisco matching
Paid parental leave
+5
Software Security Lead (Remote)
Software Security Lead (Remote)

Cisco • United States

Remote
USD 139,000 - 204,000
Medical Insurance
Dental Insurance
Vision Insurance
+4