|
The application window is expected to close on: 07/31/2026
Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received. Plans, leads, and shares applied security research that defines how AI is built and used securely across Cisco, spanning AI-assisted development, AI features in products, and AI in internal operations. Sets technical direction at the intersection of AI/ML security and hands-on engineering: leads AI-specific threat modeling, red-team and evaluation strategy, and secure architecture patterns that make AI-developed and AI-assisted software at least as secure as traditionally developed software. Serves as a research and security strategy liaison to engineers, product managers, and partners across Cisco's Security and Trust Organization (S&TO). Partners with teams in the systems and workflows they already use, and influences leadership decisions with evidence. The role enables teams rather than gating them: it defines what secure AI looks like, validates that Cisco meets it, and helps teams get there faster, including by using AI for security itself. What You'll Do:
- Leads strategic AI security initiatives and roadmaps with manageable-to-significant complexity (e.g., six-month to one-year plans) across the team's three pillars: securing AI-assisted development, securing AI in products, and securing AI in how we run the business.
- Influences product organizations and partners across S&TO, setting the security bar while partners build and run.
- Applies deep expertise in AI/ML security and research methods (adversarial machine learning, prompt injection, model extraction/inversion, membership inference, data poisoning, and excessive agency) while weighing ethical and responsible-AI considerations.
- Sets AI red-team methodology and evaluation strategy; advances eval harnesses, LLM-as-a-judge approaches, and ground-truth/silver-dataset generation so conformance and agent behavior are measured with evidence rather than described manually.
- Owns secure AI architecture patterns and prohibited design patterns for AI-native features (RAG, tool use, multi-agent workflows, MCP (Model Context Protocol) integrations), including prompts, context, retrieval, model selection, and output handling.
- Authors and shepherds AI security standards and security requirements; defines clear release criteria for AI systems.
- Drives the model and data supply-chain security strategy, including model provenance and data protection requirements such as classification, minimization, residency, and sensitive data handling.
- Defines agent identity, human review, approval, and accountability controls so autonomous agents and AI-assisted outcomes are authenticated, bounded, and accountable.
- Owns reusable platform contributions and architecture (security tooling and agentic workflows) that scale enablement across engineering rather than blocking it.
- Monitors and evaluates emerging AI technologies, attacker techniques, and adversarial research; develops hypotheses, designs experiments and prototypes, and turns discovery into shipped controls.
- Synthesizes findings into triangulated insights and meta-analyses that impact product and security decisions across multiple teams and AI initiatives.
- Independently develops and delivers presentations; leads cross-functional working sessions with diverse audiences and creates clear ownership models with partner teams.
- Leads creation of research artifacts (threat research, patterns, proposals, patents) of scientific quality and rigor; shares in company and industry forums.
- Serves as the AI security technical authority within the team; mentors peers and security champions across engineering through reusable patterns, training, and office hours.
Minimum Qualifications:
- Bachelor's + 7 years of related experience, or Master's + 4 years of related experience, or PhD + 1 year of related experience.
- Demonstrated depth in AI/ML security and hands-on security engineering, with a track record of leading initiatives and influencing cross-functional teams.
- Proficiency in Python; ability to read and review code fluently across multiple languages.
Preferred Qualifications:
- Proven leadership of AI red-team engagements and evaluation programs; familiarity with Cisco AI Defense (Cisco's AI security solution) or an open-source framework such as NVIDIA's Garak.
- Deep command of LLM and agentic-system security: prompt injection (direct and indirect), jailbreaking, insecure output handling, RAG hardening, tool-call governance, and multi-agent trust boundaries.
- Experience authoring security standards or baselines and embedding them into a secure SDLC and CI/CD.
- Authority with OWASP LLM/Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act, with the judgment to apply them proportionately by risk tier.
- Experience shipping or integrating agentic and MCP (Model Context Protocol) systems and AI development tooling (Cursor, Claude Code, Copilot).
- Experience with Go, Rust, or C/C++ is a plus, with C/C++ valuable for Cisco's embedded and networking products.
- Recognized external contributions, such as published threat research, conference talks, open-source security tooling, or patents.
Why Cisco?
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you.
Message to applicants applying to work in the U.S. and/or Canada:
The starting salary range posted for this position is $167,000.00 to $211,400.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process. U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time. U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:
10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations) 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours ofunused sick timecarried forwardfrom one calendar yearto the next Additional paid time away may be requested to deal with critical or emergency issues for family members Optional 10 paid days per full calendar year to volunteer
For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies. Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:
.75% of incentive target for each 1% of revenue attainment up to 50% of quota; 1.5% of incentive target for each 1% of attainment between 50% and 75%; 1% of incentive target for each 1% of attainment between 75% and 100%; and Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid. The applicable full salary ranges for this position, by specific state, are listed below: New York City Metro Area: $199,700.00 - $292,800.00
Non-Metro New York state & Washington state: $174,500.00 - $260,500.00
* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined. ** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
|