Security Engineer I
Job Description
Cisco is seeking an early-career Security Engineer I to help advance applied security research and engineering focused on how AI is built and used securely at Cisco. This onsite role in the Research Triangle Park, NC area supports security assignments, testing and validation activities, and threat modeling for AI-native features, with work guided by Cisco Secure Development Lifecycle and responsible-AI practices.
In this position, you will operate with defined scope and detailed guidance while contributing evidence, results, and documentation that help engineering teams identify and reduce risk across secure software delivery and AI-enabled development workflows.
Your Impact
- Support applied security research and engineering that advances how AI is built and used securely across Cisco.
- Perform routine security assignments under guidance, including defined tests and experiments.
- Contribute to basic security tooling, and document evidence and findings.
- Apply established Cisco Secure Development Lifecycle, security, and responsible-AI practices to reduce risk.
Responsibilities
- Execute routine, well-defined security engineering assignments using established practices and procedures with detailed guidance.
- Support vulnerability and risk assessments, security code reviews, validation testing, remediation, and security-hardening activities.
- Assist with threat models for AI-native features including RAG, tool use, agentic workflows, and MCP integrations, covering risks such as prompt injection, data poisoning, excessive agency, and supply-chain threats.
- Run defined adversarial tests and evaluations, record evidence and results, and escalate complex or unexpected findings.
- Contribute basic Python tooling, evaluation cases, guardrails, and automated security checks under review, including integration into Secure Development Lifecycle and CI/CD workflows.
- Support data-protection and human-oversight controls for AI systems, including sensitive-data handling, review, approval, and accountability.
- Contribute to threat research, reusable patterns, and technical write-ups; communicate findings and participate in security design reviews and incident-response activities.
Minimum Qualifications
- A Bachelor’s degree (completed within the past 3 years or expected to be completed within the next 12 months).
- Qualifying education and work experience in Computer Science, Cybersecurity, Information Technology, or a related field.
- Foundational knowledge of security engineering, software development, AI/ML, or applied research gained through education, internships, projects, or equivalent practical work.
- Working knowledge of Python and the ability to develop and test basic scripts.
Preferred Qualifications
- Coursework, projects, or a portfolio demonstrating applied experience in software, product, or AI/ML security.
- Familiarity with secure software development, vulnerability management, threat modeling, adversarial testing, or AI security evaluations.
- Familiarity with LLM security risks and frameworks, including prompt injection, RAG and agentic-system risks, OWASP LLM/Agentic Top 10, MITRE ATLAS, or NIST AI RMF.
- Exposure to AI red-team or evaluation tooling, such as Cisco AI Defense or NVIDIA’s Garak, and related CI/CD, MCP, or AI development workflows.
Technologies
- Python
- CI/CD
- RAG
- MCP
- OWASP LLM/Agentic Top 10
- MITRE ATLAS
- NIST AI RMF
- Cisco AI Defense
- NVIDIA’s Garak
Team Context
- The mission of Cisco’s Security& Trust Organization (S) is to secure products and services, protect Cisco and its employees, and cultivate trust with customers, partners, and regulators.
- You will join a collaborative team focused on securing the software delivery lifecycle through innovative CI/CD pipeline design and enhancement.
- This team operates at the intersection of security, automation, and AI-enabled DevSecOps, working closely with software engineering and platform teams to deliver secure, scalable, and efficient software delivery solutions.
- The team emphasizes technical leadership, continuous improvement, and collaboration across Cisco’s engineering organizations.
Benefits
- 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
- 1 paid day off for your birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
- Non-exempt employees receive 16 days of paid vacation time per full calendar year, accrued at a rate of 4.92 hours per pay period for full-time employees
- Exempt employees participate in Cisco’s flexible vacation time off program with no defined limit (subject to availability and some business limitations)
- 80 hours of sick time off provided on hire date and each January 1st thereafter, with up to 80 hours of unused sick time carried forward
- Additional paid time away may be requested to deal with critical or emergency issues for family members
- Optional 10 paid days per full calendar year to volunteer
- U.S. benefits may include medical, dental and vision insurance, a 401(k) plan with Cisco matching, paid parental leave, short and long-term disability coverage, and basic life insurance (subject to plan eligibility rules)
- Eligibility for grants of Cisco restricted stock units that vest following continued employment for defined periods
- For non-sales roles, annual bonuses may be available subject to Cisco’s policies
Compensation & Location: Research Triangle Park, NC (onsite). Salary range listed as USD 94,800 - 157,400 per yearly, with applicable full salary ranges by state also provided for certain locations.
Education: Bachelor’s degree.
Applicant notice (U.S. and/or Canada): Individual pay is determined by hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. For locations not listed, the recruiter can share more details about compensation during the hiring process.