About the Role
The Senior Security Engineering & Compliance Lead will bridge the gap between technical infrastructure and regulatory rigor, managing the implementation of security frameworks with automated compliance pipelines, hardened identity systems, and risk-mitigation strategies. This is a hands-on role for an engineer who views compliance as a technical problem to be solved through automation, robust system design, and proactive threat engineering.
Responsibilities
- Design and implement automated controls to satisfy security compliance requirements, reducing manual evidence collection through system integration.
- Conduct technical gap assessments of infrastructure and applications; design remediation plans that integrate directly into the CI/CD pipeline.
- Build and maintain automated data pipelines to provide real-time visibility into control effectiveness for auditors and stakeholders.
- Oversee security alert queues, prioritizing high-severity risks and engineering automated response playbooks to resolve incidents.
- Facilitate and document technical incident response tabletop exercises, using the findings to engineer more resilient system architectures and automated recovery processes.
- Maintain technical documentation and incident logs that serve as the "source of truth" for audit requirements.
- Engineer and enforce automated user access reviews and segregation-of-duties (SoD) testing.
- Audit and optimize privileged account controls, implementing technical guardrails to minimize the blast radius of unauthorized access.
- Perform deep-dive vulnerability analyses on enterprise infrastructure; engineer automated patch management and configuration hardening workflows.
- Quantify business impact through technical risk assessments, collaborating with engineering teams to implement corrective technical controls rather than just policy-based fixes.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or related technical field with 8+ years of experience; or a Master’s degree with 6+ years.
- Experience with security engineering in cloud-native environments (AWS/Azure/GCP) and infrastructure-as-code (Terraform/Ansible).
- Experience working with technical security controls and regulated compliance frameworks such as SOC, ISO, etc.
Skills
- Python
- Go
- Bash scripting/programming for security automation or log analysis
- Compliance-as-Code solutions
- SIEM/SOAR engineering
- Automated incident response orchestration
- Zero trust architecture
- Micro-segmentation engineering
Location
- Remote (US)
Work Type
- Remote
- Full-time
Experience Level
- Senior
Education Level
- Bachelor's degree
- Master's degree
Salary/Compensations
- $183,800.00 - $263,600.00 (US)
- $183,800.00 - $303,100.00 (New York City Metro Area)
- $163,600.00 - $269,800.00 (Non-Metro New York state & Washington state)
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k) plan with Cisco matching contribution
- Paid parental leave
- Short-term disability coverage
- Long-term disability coverage
- Basic life insurance
- 10 paid holidays per full calendar year
- 1 floating holiday for non-exempt employees
- 1 paid day off for employee’s birthday
- Paid year-end holiday shutdown
- 4 paid days off for personal wellness
- 16 days of paid vacation time per full calendar year (non-exempt)
- Flexible vacation time off program (exempt)
- 80 hours of sick time off provided on hire date and each January 1st thereafter
- Up to 80 hours of unused sick time carried forward
- Additional paid time away for critical or emergency issues for family members
- Optional 10 paid days per full calendar year to volunteer
- Annual bonuses (non-sales roles)
- Performance-based incentive pay (sales roles)
- Cisco restricted stock units
About the Company
- At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond.
- We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds.
- These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
- Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions.
- Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless.
- We work as a team, collaborating with empathy to make really big things happen on a global scale.
- Because our solutions are everywhere, our impact is everywhere.
- We are Cisco, and our power starts with you.
