About the Role
Arista Networks is seeking a deeply technical and operationally strategic Technical Lead, Product Security Program & Operations. This role serves as a core link between engineering groups, external security researchers, federal stakeholders, and executive leadership, requiring a strong technical background in network operating systems, exploit mechanics, and secure software development.
Responsibilities
- Drive the end-to-end process of turning discovered or reported vulnerabilities into verified security advisories.
- Triage incoming vulnerability reports, evaluate exploitability, and determine severity using CVSS and CWE frameworks.
- Partner with software engineers to explain root-cause vulnerabilities, provide remediation guidance, and oversee technical security advisories.
- Coordinate with NVD, MITRE, and external research teams for timely disclosure.
- Analyze vulnerability trends to identify systemic security gaps and deliver data-driven architecture recommendations.
- Manage the execution of third-party security testing and red-teaming.
- Translate switch architecture into clear threat vectors to scope penetration testing targets.
- Review penetration testing findings, distinguish theoretical risks from practical exploits, and validate engineering fixes.
- Distill complex vulnerabilities into clear risk profiles for executive management and customers.
- Architect, implement, and optimize security checkpoints throughout development lifecycles.
- Drive the adoption and tuning of automated security tooling into CI/CD infrastructure.
- Define and evangelize secure coding practices, threat modeling principles, and framework-level mitigations.
- Audit existing development workflows to eliminate friction between engineering velocity and product security compliance.
- Securely administer and monitor the dedicated Google Workspace environment for Arista Federal.
- Configure and audit cloud infrastructure settings in accordance with federal regulations.
- Actively monitor systems to identify, investigate, and remediate suspicious activity or misconfigurations.
- Lead security risk assessments for all proposed system alterations.
- Act as the primary technical subject matter expert during security discussions with customers.
- Address complex customer compliance inquiries regarding product architecture, supply chain integrity, and federal security mandates.
Requirements
- Deep understanding of software vulnerabilities, exploit mechanics, cryptography, and modern mitigation techniques.
- Strong familiarity with standard frameworks including CVSS, CWE, OWASP Top 10, and MITRE ATT&CK.
- In-depth understanding of network switch architecture, composition, and management.
- Knowledge of network operating system internals (ideally Linux-based, such as Arista EOS), control plane protection, data plane forwarding, ASIC-level considerations, and protocols.
- Robust knowledge of modern software engineering methodologies, version control (Git), and CI/CD pipelines.
- Hands-on experience integrating and managing AppSec tools (SAST/DAST) and implementing Threat Modeling practices in an enterprise environment.
- 7+ years of experience in Product Security, Software Security Engineering, PSIRT operations, or Advanced Cloud Security Administration.
- Proven experience hardening enterprise/federal cloud spaces, specifically Google Workspace or major cloud providers (AWS/GCP), with an emphasis on access controls, logging, and audit logs.
- Familiarity with Federal, State, and Local compliance regulations (e.g., FedRAMP, NIST, FIPS).
- Exceptional ability to articulate highly technical security flaws and architectural concepts clearly to software developers, enterprise customers, and non-technical business executives.
Skills
- Network operating systems
- Exploit mechanics
- Secure software development
- Product security vulnerability lifecycle
- Threat modeling
- Penetration testing
- Software development lifecycle (SDLC)
- CVSS
- CWE
- OWASP Top 10
- MITRE ATT&CK
- Network switch architecture
- Linux
- Arista EOS
- BGP
- OSPF
- gRPC
- SNMP
- Git
- CI/CD
- SAST
- DAST
- SCA
- Container scanning
- Google Workspace
- AWS
- GCP
- FedRAMP
- NIST 800-53
- NIST
- FIPS
Location
- Dallas, TX
- Raleigh, NC
- Santa Clara, California
Work Type
- Full-time
Experience Level
- 7+ years of experience
About the Company
- Arista Networks is an industry leader in data-driven, client-to-cloud networking for large data center, campus and routing environments.
- Arista is a well-established and profitable company with over $8 billion in revenue.
- Arista’s award-winning platforms, ranging in Ethernet speeds up to 800G bits per second, redefine scalability, agility, and resilience.
- Arista is a founding member of the Ultra Ethernet consortium.
- We have shipped over 20 million cloud networking ports worldwide with Cloud Vision and EOS, an advanced network operating system.
- Arista is committed to open standards, and its products are available worldwide directly and through partners.
- At Arista, we value the diversity of thought and perspectives each employee brings.
- We believe fostering an inclusive environment where individuals from various backgrounds and experiences feel welcome is essential for driving creativity and innovation.
- Our commitment to excellence has earned us several prestigious awards, such as the Great Place to Work Survey for Best Engineering Team and Best Company for Diversity, Compensation, and Work-Life Balance.
- At Arista, we take pride in our track record of success and strive to maintain the highest quality and performance standards in everything we do.
- Arista stands out as an engineering-centric company.
- Our leadership, including founders and engineering managers, are all engineers who understand sound software engineering principles and the importance of doing things right.
- We hire globally into our diverse team.
- At Arista, engineers have complete ownership of their projects.
- Our management structure is flat and streamlined, and software engineering is led by those who understand it best.
- We prioritize the development and utilization of test automation tools.
- Our engineers have access to every part of the company, providing opportunities to work across various domains.
- Arista is headquartered in Santa Clara, California, with development offices in Australia, Canada, India, Ireland, and the US.
- We consider all our R&D centers equal in stature.
- Join us to shape the future of networking and be part of a culture that values invention, quality, respect, and fun.
Equal Opportunity
- Arista Networks is an equal opportunity employer.
- Arista makes all hiring and employment-related decisions in a non-discriminatory manner without regard to race, color, religion, sex, sexual orientation, gender identity, national origin or any other factor determined to be unlawful under applicable federal, state, or law law.
- All your information will be kept confidential according to EEO guidelines.
