Principal Software Engineer – Application Security & AI Trust Architecture

Engg

San Jose (CA)

On-site

USD 180,000 - 280,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cisco is seeking a Principal Engineer to lead software security architecture across our platforms and services. You will bridge strategy with hands-on engineering to ensure secure cloud-to-box solutions and mentor engineering teams.

You will shape Model Context Protocol (MCP) access, spec-driven security contracts, and guard against AI-driven threats while guiding DevSecOps, threat modeling, and secure-by-design patterns for distributed applications.

Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field.
  • 15+ years of software engineering and application security architecture experience.
  • Experience with security frameworks such as OWASP Top 10, API Top 10, CWE/SANS 25.
  • Experience with identity and access governance (OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, RBAC/ABAC/ReBAC).
  • Experience in at least one backend language (Python, Go, TypeScript/Node.js, Rust, or Java).
  • Experience securing cloud-native architectures (Kubernetes, AWS/GCP/Azure, API gateways, service meshes).

Responsibilities

  • Define and drive security architecture across software platforms and services.
  • Mentor engineering teams and engage with customers.
  • Lead threat modeling and secure-by-design engineering across architectures.
  • Implement automated security gates in CI/CD pipelines (SAST, DAST, IAST).
  • Develop policy-as-code frameworks to enforce security baselines.

Skills

Security architecture
Threat modeling
DevSecOps
CI/CD security gates
Zero-trust

Education

Bachelor's degree in CS or Engineering

Tools

OWASP
OPA/Rego
Semgrep
CodeQL
SAST/DAST/IAST

Job description

The application window is expected to close on: 10/30/2026

Meet the Team

At Cisco, we are redefining how our customers experience technology through the power of Cisco IQ Services and Applications. Our mission is to transform CX delivery by building intelligent, scalable platforms that anticipate needs rather than just reacting to them. As a member of our global, diverse, and AI-spec driven team, you will operate at the absolute frontier of innovation. We are deeply committed to leveraging the latest advancements in AI to build robust solutions that solve complex technical challenges for our enterprise customers, fostering a culture of curiosity, collaboration, and rapid iteration.

Your Impact

As a Principal Engineer leading software security, you will be a primary technical authority responsible for defining and driving the security architecture across our software platforms and services. You will bridge the gap between high-level security strategy and hands-on engineering execution, ensuring that our products are secure from the cloud to the box. You will lead cross-functional initiatives, mentor engineering team members, engage with our customers and leverage AI to revolutionize our development lifecycle and threat prevention capabilities. Rather than focusing on perimeter network defenses or traditional compliance auditing, you will operate as a software-first security leader—collaborating with application teams to design secure-by-default software patterns, implement strict Model Context Protocol (MCP) access boundaries, enforce spec-driven security contracts, and mitigate vulnerabilities unique to autonomous agent workflows (e.g., prompt injection, indirect data exfiltration, unauthorized tool invocation).

AI & Agentic Application Security Architecture:

Design trust boundaries, sandboxing models, and execution guardrails for autonomous application agents and LLM tool‑calling workflows. Architect granular authentication, authorization, and least‑privilege scoping for Model Context Protocol (MCP) servers, tool registries, and external integrations. Mitigate emerging AI threat vectors (e.g., OWASP Top 10 for LLMs, indirect prompt injection, tool hijacking, credential harvesting, and context leakage).

Spec-Driven Security & API Protection:

Establish spec‑driven security standards across application contracts (OpenAPI, TypeSpec, gRPC/Protobuf), embedding authentication schemes, data sanitization, and authorization scopes directly into machine‑readable specs. Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA), and injection vulnerabilities prior to deployment.

Threat Modeling & Secure-by-Design Engineering:

Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi‑tenant data boundaries. Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams.

DevSecOps & Software Supply Chain Integrity:

Architect and scale automated security gates in CI/CD pipelines (SAST, DAST, IAST, software composition analysis, container image signing, and SBOM tracking). Define policy-as-code (e.g., OPA/Rego, Cedar) frameworks to enforce deterministic security baselines across service deployments.

Technical Direction, Governance & Incident Leadership:

Serve as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures. Mentor senior software engineers on defensive coding practices, modern API security standards, and zero‑trust application design.

Minimum Qualifications
  • Bachelor's degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications.
  • Experience in application security frameworks such as OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OR zero-trust application patterns.
  • Experience in identity and access governance including one or more of OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, or fine-grained authorization models (RBAC, ABAC, ReBAC).
  • Experience in at least one backend language (Python, Go, TypeScript/Node.js, Rust, or Java).
  • Experience integrating security controls into cloud-native architectures such as Kubernetes, AWS/GCP/Azure, API gateways, or service meshes.
Preferred Qualifications
  • Experience with security implications of the Model Context Protocol (MCP) or similar AI tool‑invocation interfaces.
  • Experience writing policy‑as‑code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL).
  • Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS).
  • Relevant security certifications (e.g., CISSP, CSSLP, CCSP, or AWS Certified Security).
  • Experience evaluating and securing LLM‑powered applications, tool‑use execution loops, and RAG architectures.
Why Cisco?

At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Engineer - AI Defense
Principal Engineer - AI Defense

lwtsquad • San Jose (CA)

On-site
USD 150,000 - 200,000
401(k) plan with matching
Paid time off for volunteering
Flexible vacation policy
Principal Software Engineer – Application Security & AI Trust Architecture
Principal Software Engineer – Application Security & AI Trust Architecture

020 Cisco Systems, Inc. • San Jose (CA)

On-site
USD 234,000 - 330,000
Software Security Lead (Remote)
Software Security Lead (Remote)

Cisco • Augusta (ME)

On-site
USD 139,000 - 204,000
Medical, dental, vision insurance
401(k) with company match
Parental leave
+1
Principal Software Engineer (SSE) (Onsite-Milpitas)
Principal Software Engineer (SSE) (Onsite-Milpitas)

Cisco • Milpitas (CA)

On-site
USD 251,000 - 363,000
Medical, dental and vision insurance
401(k) plan with Cisco matching
Paid parental leave
+3
Software Engineering Technical Leader - BackEnd
Software Engineering Technical Leader - BackEnd

020 Cisco Systems, Inc. • Richardson (TX)

On-site
USD 152,000 - 222,000
Medical, dental, and vision insurance
401(k) with Cisco matching
Paid parental leave
+5
Senior Software Engineer AI Platforms
Senior Software Engineer AI Platforms

Cisco Systems, Inc. • San Jose (CA)

On-site
USD 150,000 - 230,000
AI Application Security Engineer
AI Application Security Engineer

020 Cisco Systems, Inc. • North Carolina

On-site
USD 139,000 - 204,000
Security Engineer I
Security Engineer I

Cybersecurity Jobs • North Carolina

On-site
USD 95,000 - 157,000
Health insurance
Paid time off
401(k) plan with Cisco matching
+1
Principal Software Engineer – Application Security & AI Trust Architecture
Principal Software Engineer – Application Security & AI Trust Architecture

Cisco Systems, Inc • San Jose (CA)

On-site
USD 234,000 - 330,000
Medical, dental and vision insurance
401(k) plan with Cisco matching
Paid parental leave
+1
Principal Engineer: AI Trust & Secure-by-Design Architecture
Principal Engineer: AI Trust & Secure-by-Design Architecture

020 Cisco Systems, Inc. • San Jose (CA)

On-site
USD 234,000 - 330,000