Level

Cisco

Principal Software Engineer – Application Security & AI Trust Architecture

AI in this role

rag
The application window is expected to close on: 10/30/2026Meet the Team

At Cisco, we are redefining how our customers experience technology through the power of Cisco IQ Services and Applications. Our mission is to transform CX delivery by building intelligent, scalable platforms that anticipate needs rather than just reacting to them. As a member of our global, diverse, and AI-spec driven team, you will operate at the absolute frontier of innovation. We are deeply committed to leveraging the latest advancements in AI to build robust solutions that solve complex technical challenges for our enterprise customers, fostering a culture of curiosity, collaboration, and rapid iteration.


Your Impact

As a Principal Engineer leading software security, you will be a primary technical authority responsible for defining and driving the security architecture across our software platforms and services. You will bridge the gap between high-level security strategy and hands-on engineering execution, ensuring that our products are secure from the cloud to the box. You will lead cross-functional initiatives, mentor engineering team members, engage with our customers and leverage AI to revolutionize our development lifecycle and threat prevention capabilities.

 

Rather than focusing on perimeter network defenses or traditional compliance auditing, you will operate as a software-first security leader—collaborating with application teams to design secure-by-default software patterns, implement strict Model Context Protocol (MCP) access boundaries, enforce spec-driven security contracts, and mitigate vulnerabilities unique to autonomous agent workflows (e.g., prompt injection, indirect data exfiltration, unauthorized tool invocation).


AI & Agentic Application Security Architecture:

  • Design trust boundaries, sandboxing models, and execution guardrails for autonomous application agents and LLM tool-calling workflows.
  • Architect granular authentication, authorization, and least-privilege scoping for Model Context Protocol (MCP) servers, tool registries, and external integrations.
  • Mitigate emerging AI threat vectors (e.g., OWASP Top 10 for LLMs, indirect prompt injection, tool hijacking, credential harvesting, and context leakage).

 

Spec-Driven Security & API Protection:

  • Establish spec-driven security standards across application contracts (OpenAPI, TypeSpec, gRPC/Protobuf), embedding authentication schemes, data sanitization, and authorization scopes directly into machine-readable specs.
  • Implement automated security contract testing and static/dynamic schema validation to detect authorization bypasses, Broken Object Level Authorization (BOLA), and injection vulnerabilities prior to deployment.

 

Threat Modeling & Secure-by-Design Engineering:

  • Lead comprehensive architectural threat modeling for critical application tiers, distributed business logic, and multi-tenant data boundaries.
  • Create reusable, hardened software design patterns, cryptographic utilities, and session management frameworks for application engineering teams.

 

DevSecOps & Software Supply Chain Integrity:

  • Architect and scale automated security gates in CI/CD pipelines (SAST, DAST, IAST, software composition analysis, container image signing, and SBOM tracking).
  • Define policy-as-code (e.g., OPA/Rego, Cedar) frameworks to enforce deterministic security baselines across service deployments.

Technical Direction, Governance & Incident Leadership:

  • Serve as the principal technical escalation point for complex application security architecture reviews and critical vulnerability disclosures.
  • Mentor senior software engineers on defensive coding practices, modern API security standards, and zero-trust application design.

 

Minimum Qualifications
  • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
  • 15+ years of experience in software engineering and application security architecture, including designing, securing, and operating distributed applications.
  • Experience in application security frameworks such as OWASP Top 10, OWASP API Top 10, CWE/SANS 25, OR zero-trust application patterns.
  • Experience in identity and access governance including one or more of OAuth 2.0, OIDC, SAML, mTLS, SPIFFE/SPIRE, or fine-grained authorization models (RBAC, ABAC, ReBAC).
  • Experience in at least one backend language (Python, Go, TypeScript/Node.js, Rust, or Java).
  • Experience integrating security controls into cloud-native architectures such as Kubernetes, AWS/GCP/Azure, API gateways, or service meshes.

 

Preferred Qualifications 
  • Experience with security implications of the Model Context Protocol (MCP) or similar AI tool-invocation interfaces.
  • Experience writing policy-as-code engines (Open Policy Agent, AWS Cedar, Oso/Polar) or custom linter/SAST rules (Semgrep, CodeQL).
  • Active involvement in application security research, CVE publications, open-source security tooling, or industry working groups (OWASP, CNCF Security, OASIS).
  • Relevant security certifications (e.g., CISSP, CSSLP, CCSP, or AWS Certified Security).
  • Experience evaluating and securing LLM-powered applications, tool-use execution loops, and RAG architectures.

Why Cisco? 

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. 

We are Cisco, and our power starts with you. 

Message to applicants applying to work in the U.S. and/or Canada:

The starting salary range posted for this position is $233,900.00 to $330,400.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.

Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.

U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks.  Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.

U.S. employees are eligible for paid time away as described below, subject to Cisco’s policies:

  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees

  • 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco

  • Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees

  • Exempt employees participate in Cisco’s flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)

  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next

  • Additional paid time away may be requested to deal with critical or emergency issues for family members

  • Optional 10 paid days per full calendar year to volunteer

For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco’s policies.

Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:

  • .75% of incentive target for each 1% of revenue attainment up to 50% of quota;

  • 1.5% of incentive target for each 1% of attainment between 50% and 75%;

  • 1% of incentive target for each 1% of attainment between 75% and 100%; and

  • Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.

For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.

The applicable full salary ranges for this position, by specific state, are listed below:

New York City Metro Area:

$233,900.00 - $380,000.00

Non-Metro New York state & Washington state:

$220,900.00 - $344,300.00

* For quota-based sales roles on Cisco’s sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.

** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.

How we rate this

Principal Software Engineer – Application Security & AI Trust Architecture at Cisco rates 64 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.

Classification

Works on AI. The daily work is on AI products, without building the model.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

RAG

Questions you could be asked

  1. How would you design a retrieval step so the model answers from real data instead of guessing?
  2. Describe a typical day in a role like this one: which parts run through AI directly?
  3. If you removed AI from this role, what would be left, and how do you decide what still needs a human?

Adapt your resume

  • List these exact terms on your resume: RAG. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
  • Show where AI is part of your daily process, not a one-off project — this role expects it to be a running habit.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new software engineer jobs (Works on AI ●●●○ or higher) by email

One email a week with the new software engineer jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that work on AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Cisco

Cisco

$216k-$281kSan Jose, California, US2d

More software engineer jobs

Related searches

Same AI level