Program Lead, Threat Intelligence
Cisco
- Location
- Milpitas, California, US
- Work model
- On-Site
- Level
- Senior
- Posted
- Sep 1, 2026
Skills
About this role
The application window is expected to close on: 09/10/2026 Meet the Team Cisco Cloud Security Group is a leading provider of Cloud Security and DNS services, enabling the world to connect to the Internet with confidence on any device, anywhere, anytime. Our approach is twofold; first Umbrella, our cloud-delivered security service, blocks advanced attacks including malware, botnets, and phishing threats, while our predictive intelligence engine uses machine learning to automate protection against newly-discovered threats before they can reach our customers. Today, we handle more than 80 billion daily Internet requests from 65 million+ users around the world. Our global network has proven reliability and adds no latency. We protect each and every one of our customers' devices globally without any hardware to install or software to maintain. Working at Cisco Cloud Security group means being surrounded by passionate and creative people who are determined to disrupt the Internet security industry with innovative ideas, world-class research and unrivaled products and services. It's a place where the best ideas are quickly transformed into products, features, campaigns and company-wide practices, with nearly 100% year-over-year usage growth!
Your Impact
The Program Lead, Threat Intelligence will own the end-to-end program management of threat intelligence initiatives within Cisco's Security & Networking business unit. This role bridges threat research, engineering, and product teams to ensure timely , accurate , and actionable intelligence is embedded into Cisco's security portfolio (e.g., Talos, SecureX /XDR, firewall , endpoint, and cloud security products). The ideal candidate combines strong program/project management subject area with deep knowledge of threat intelligence lifecycle, risk management, and cross-functional software integration testing.
Key Responsibilities
1. Program Leadership Own the roadmap, planning, and execution of threat intelligence programs across multiple product lines within the Security BU. Drive cross-functional alignment across Threat Research (e.g., Talos), Product Engineering, Data Science, and Product Management teams. Define program milestones, dependencies, resourcing plans, and success metrics (objectives and key results). Provide regular status reporting and executive-level updates on program health, risks, and outcomes. 2. Risk Identification & Management Establish and maintain a risk register for threat intelligence programs, covering technical, operational, data-quality, and third-party/vendor risks. Proactively identify risks related to intelligence feed reliability, false-positive/false-negative rates, data pipeline integrity, and coverage gaps. Partner with security, legal, and compliance teams to assess risks tied to data sourcing, sharing agreements, and regulatory requirements (e.g., export controls, data privacy). Develop and track mitigation plans; raise high-severity risks to leadership with clear options and recommendations. Conduct periodic risk reviews and post-incident/lessons-learned assessments. 3. Integration Testing & Quality Assurance Coordinate integration testing of threat intelligence feeds and services into downstream security products (firewalls, IPS/IDS, XDR, cloud security, endpoint). Define test plans and acceptance criteria in partnership with QA/engineering, covering data ingestion, correlation accuracy, latency, and system performance under load. Oversee regression and interoperability testing when new intelligence sources, detection signatures, or product releases are introduced. Validate that intelligence outputs meet accuracy, timeliness, and actionability requirements before production release. Manage defect triage and resolution tracking through to closure with engineering teams. 4. Program Operations & Stakeholder Management Facilitate program ceremonies (planning,