Bangalore, Undisclosed, India
18 hours ago
Product Security Engineer - 5+yrs
Who We AreAs the leader in cloud-managed IT, Cisco connects passionate people to their mission by simplifying the digital workplace. Our impact is driven by the innovative, purposeful, and vibrant people who make up our inclusive community. When technology is intuitive, our customers can focus on what matters!
About The team
As a member of the Device Trust Assurance team, you will have a substantial impact on the security of millions of Cisco devices all around the world. We are looking for people who are passionate about security and eager to learn the ropes of vulnerability management (reporting, triaging and driving remediation).
About The Role
As a Product Security Engineer, you will play a critical role in securing firmware that runs on Cisco enterprise networking devices. You will be responsible for implementing security throughout the entire product development lifecycle and ensuring our devices maintain the highest security standards.
As a product security engineer you will:Implement and maintain SecDevOps practices throughout the entire Secure Development Lifecycle (SDL)Build and maintain automated security testing frameworks, including static analysis, dynamic analysis, and fuzz testingImplement and run secure CI/CD pipelines, incorporating security checks and controls at each stageCollaborate with product engineering teams to implement security-by-design principles and ensure consistency to SDL practicesDevelop and maintain security metrics to measure and improve SDL efficiencyMonitor and triage incoming product security issues from our public bug bounty programMentor and train development teams on SecDevOps best practices and tools
Qualifications:5+ years of experience in software or firmware security, with a focus on Secure Development Lifecycle implementationDeep knowledge of Linux and embedded systems security with strong growth mindsetStrong programming skills in languages such as Python, Go, or Ruby, with experience in C/C++ for embedded systemsExperienced knowledge of embedded systems development concepts, including cross-platform development and build tools (GNU toolchain, OpenWrt, buildroot, Yocto), bootloaders (U-Boot, coreboot, UEFI), kernel configuration, device drivers, device treesExperience with DevOps tools and practices (e.g., Jenkins, GitLab CI, Docker, Kubernetes)Experience implementing and running security tools such as SAST, DAST, SCA, and container security solutionsStrong documentation skills and ability to present complex technical findings clearlyProven ability to collaborate effectively across global teams and multiple time zones
Bonus points for:Experience with agile development methodologiesExperience with embedded systems security and IoT device securityExperience with fuzzing, penetration testing, or static analysisKnowledge of AI and machine learning concepts, with experience applying them to security problemsCisco security certifications (CCNA/CCNP Security) and cybersecurity credentials (CISSP, CEH)Knowledge of networking protocols and security frameworks (NIST, ISO 27001)Bachelor's degree in Computer Science, IT, or related field
 
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis. Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records.
Por favor confirme su dirección de correo electrónico: Send Email