Senior DevSecOps Security Engineer, Cisco Intersight
Cisco
- Location
- Milpitas, California, US
- Work model
- On-Site
- Level
- Senior
- Posted
- Aug 21, 2026
Skills
About this role
The application window is expected to close on: 09/13/2026 Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received . Meet the Team Cisco Intersight is a cloud-native operations platform that provides unified management, automation, visibility, and lifecycle operations for infrastructure across data center, cloud, and edge environments. Our SaaS, on-premises, and mobile offerings depend on secure, reliable automation that enables engineering teams to build, test, release, and operate software at scale. We are looking for an expert Security Officer / DevSecOps Engineer to provide senior security guidance and hands-on engineering contribution within the Intersight DevSecOps function. This role partners closely with Engineering, Architecture, Product Management, SRE, Compliance, Cisco's Security and Trust Organization (STO), and leadership teams to help Intersight meet security, privacy, corporate, and regulatory requirements while enabling rapid and secure product delivery.
Your Impact
In this role, you will be a senior security partner for Intersight Engineering & DevSecOps. You will assess security impact, clarify requirements, prioritize risk, guide remediation, and contribute to security automation, hardening, and remediation work. Typical responsibilities include: Assess and guide improvements to the security posture of Intersight applications and delivery workflows Interpret Cisco-level security mandates, policies, audit requirements, release gates, and security best practices into clear guidance, control expectations, acceptance criteria, and remediation priorities. Partner with development teams, architects, product management, SRE, compliance, and central security teams to review new features, architecture changes and security-sensitive designs, identifying gaps, recommending mitigations, and helping teams balance security, usability, and delivery needs. Guide vulnerability management and remediation priorities across automated scans, penetration tests, release security reviews, and security incident response activities, ensuring issues are visible, triaged, assigned, and tracked to closure within SLA. Support compliance with Cisco security mandates and Build Environment Security requirements by clarifying requirements, identifying evidence needs, reviewing audit findings, and guiding remediation priorities. Define and contribute to implementation of security automation, reporting, and tooling that improve visibility, reduce manual work, and help teams follow security requirements consistently.
Minimum Qualifications
Bachelors' degree and 8 years of hands-on experience implementing security automation, hardening, vulnerability remediation, secure delivery improvements, or related DevSecOps capabilities. 3+ years' experience conducting security reviews, architecture reviews, threat or risk assessments, and translating findings into practical guidance and remediation plans. Use of a major programming language, preferably Python, with to build, test, and maintain production-quality automation. Experience with vulnerability triage, penetration test findings, automated security scan findings, and SLA-based remediation workflows. Experience working with corporate security mandates, secure development lifecycle requirements, product security standards, compliance requirements, or security audit processes.
Preferred Qualifications
Security engineering experience across multiple areas such as application security, cloud infrastructure security, authentication, encryption, data protection, key management, CI/CD security, vulnerability management, or incident response. Demonstrated ability to partner effectively across engineering, security, compliance, product, SRE, and leadership stakeholders to drive alignment and execution. Experience with Cisco security mandates, policies, tooling, or product security processes. Experience with security frameworks and compliance