Lead Security Architect
Who We Are
Cisco ThousandEyes is a Digital Experience Assurance platform that empowers organizations to deliver flawless digital experiences across every network – even the ones they don’t own. Powered by AI and an unmatched set of cloud, internet and enterprise network telemetry data, ThousandEyes enables IT teams to proactively detect, diagnose, and remediate issues – before they impact end- user experiences.
ThousandEyes is deeply integrated across the entire Cisco technology portfolio and beyond, helping customers deploy at scale while also delivering AI-powered assurance insights within Cisco’s leading Networking, Security, Collaboration, and Observability portfolios.
About The Role
The Application Window is expected to close on 2/22/25. However, the job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.
Cisco ThousandEyes is seeking a skilled and visionary Lead Cloud Security Engineer to transform and enhance our security posture on the AWS platform. This role is essential in our journey to build best-in-class cloud security and compliance practices, drive strategic security initiatives, and support ThousandEyes' mission to deliver secure, reliable, and scalable solutions. You will lead efforts in designing, implementing, and optimizing security controls and automation, driving the adoption of industry-leading security practices.
What You’ll Do
Cloud Security Architecture & Strategy
- Lead the development and implementation of cloud security strategies for AWS, aligning with industry best practices and regulatory standards.
- Partner with cross-functional teams to integrate security into the core of our infrastructure and application deployments.
- Serve as a security subject matter expert, providing guidance on secure architecture patterns and best practices for cloud-native applications and services.
Risk Assessment & Threat Management
- Conduct comprehensive security assessments for AWS services, leveraging the NIST SP 800 series and other relevant frameworks.
- Identify, prioritize, and mitigate risks across AWS environments, with a focus on proactive vulnerability management and continuous monitoring.
- Collaborate with engineering teams to integrate security risk management practices, leveraging frameworks such as Risk Management Framework(RMF) to enhance ThousandEyes' security posture.
FedRAMP Compliance
- Ensure all systems and services comply with FedRAMP requirements.
- Respond to technical inquiries and provide expert advice on FedRAMP compliance.
- Collaborate with external auditors during FedRAMP reviews and audits, providing precise and detailed responses.
Implementation of Security Controls and Automation
- Develop and maintain security controls for AWS environments, including access control, encryption, network security, and identity management.
- Use Infrastructure as Code (IaC) tools like Terraform and Kubernetes to automate security configuration and compliance checks, ensuring cloud infrastructure is secure by design.
- Deploy monitoring solutions to enhance visibility into security events and streamline compliance reporting, including FedRAMP requirements.
Continuous Security Improvement & Compliance Management
- Ensure continuous compliance with FedRAMP, FIPS, and other relevant standards by establishing processes for regular audits, assessments, and reporting.
- Engage with auditors and regulatory bodies to provide documentation and responses related to cloud security compliance.
- Stay updated on the latest security threats, vulnerabilities, and emerging trends in cloud security to continuously improve security controls and practices.
Technical Leadership & Mentorship
- Provide technical mentorship to engineering teams, empowering them to implement security best practices within their code and deployments.
- Serve as an advocate for security throughout the organization, driving security awareness, training, and engagement.
- Collaborate closely with cross-functional teams to ensure security is embedded throughout the software development lifecycle.
Qualifications
- Education: Bachelor's degree in Computer Science, Information Security, or a related field.
- Experience:
- Minimum of 8 years of experience in cloud security engineering, with extensive focus on AWS and security compliance frameworks such as FedRAMP.
- Proven expertise in assessing and mitigating security risks in complex cloud environments.
- In-depth experience with cloud platforms, particularly AWS, and security practices across multi-cloud environments.
- Technical Knowledge:
- Mastery of FedRAMP, NIST standards, and AWS security controls.
- Deep knowledge of cloud security architectures, identity and access management, data protection, and security monitoring tools.
- Proficiency in automation and IaC tools like Terraform, Kubernetes, and scripting languages (e.g., Python, Bash).
- Skills:
- Strong communication skills to articulate complex security issues to both technical and non-technical stakeholders.
- Excellent analytical, problem-solving, and project management abilities.
- Ability to work effectively in both team settings and independently.
Preferred Qualifications
- Advanced knowledge of AWS security services and tools, including AWS Security Hub, AWS WAF, and GuardDuty.
- Advanced scripting skills for security automation.
- Relevant certifications such as AWS Certified Security - Specialty, CISSP, or equivalent.
Cisco values the perspectives and skills that emerge from employees with diverse backgrounds. That's why Cisco is expanding the boundaries of discovering top talent by not only focusing on candidates with educational degrees and experience but also placing more emphasis on unlocking potential. We believe that everyone has something to offer and that diverse teams are better equipped to solve problems, innovate, and create a positive impact.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification. Research shows that people from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy. We urge you not to prematurely exclude yourself and to apply if you're interested in this work.
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis. Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records.
US – COMPENSATION RANGE – MESSAGE TO APPLICANTS
154600 USD - 251300 USD
Message to applicants applying to work in the U.S.:
When available, the salary range posted for this position reflects the projected hiring range for new hire, full-time salaries in U.S. locations, not including equity or benefits. For non-sales roles the hiring ranges reflect base salary only; employees are also eligible to receive annual bonuses. Hiring ranges for sales positions include base and incentive compensation target. Individual pay is determined by the candidate's hiring location and additional factors, including but not limited to skillset, experience, and relevant education, certifications, or training. Applicants may not be eligible for the full salary range based on their U.S. hiring location. The recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees have access to quality medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, short and long-term disability coverage, basic life insurance and numerous wellbeing offerings. Employees receive up to twelve paid holidays per calendar year, which includes one floating holiday, plus a day off for their birthday. Employees accrue up to 20 days of Paid Time Off (PTO) each year and have access to paid time away to deal with critical or emergency issues without tapping into their PTO. We offer additional paid time to volunteer and give back to the community. Employees are also able to purchase company stock through our Employee Stock Purchase Program.
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components. For quota-based incentive pay, Cisco pays at the standard rate of 1% of incentive target for each 1% revenue attainment against the quota up to 100%. Once performance exceeds 100% quota attainment, incentive rates may increase up to five times the standard rate with no cap on incentive compensation. For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.
Apply for this job
*
indicates a required field