Offensive Security Engineer

  • Location:
    Offsite, Fulton, Maryland, US
  • Alternate Location
    Preferred sites: Knoxville, Tennessee; Austin, Texas; or Research Triangle Park, North Carolina. Willing to consider remote
  • Area of Interest
  • Job Type
  • Technology Interest
  • Job Id
Please note this posting is to advertise potential job opportunities. This exact role may not be open today, but could open in the near future. When you apply, a Cisco representative may contact you directly if a relevant position opens.

What You'll Do
As a team member of Cisco's Advanced Security Initiatives Group, you will evaluate our products and services to identify security vulnerabilities, weaknesses, and improvements that result in more resilient and hardened offers used by our global customers. You will learn to adopt an attacker mindset using tools, techniques, and processes that emulate those used by sophisticated and motivated adversaries. You will work with amazingly creative, innovative, and collaborative security researchers to continuously develop new and constantly evolving ethical hacker skills and expansive networking product knowledge. You will partner with Cisco's industry leading engineering teams to review the latest complex and industry leading system and application architectures, contribute to creative security solutions, and gain unparalleled access to and experience with the latest technologies. You will also have opportunities to work on independent and/or team research of advanced topics to explore and develop your own new and novel tools and ideas as part of our "Free Friday" innovation incubation process.

Who You'll Work With
Our security team is dynamic, hardworking, fun, and high-energy, but the work is done in a very casual environment that strongly encourages a good work/life balance. Not only will you will be working alongside a team of expert security researchers with a diverse spectrum of skills and experience levels, you will also be interacting with a variety of engineering teams across Cisco. Cisco ASIG cultivates an environment where every individual's input and experience is valued. Our team prioritizes training sessions and a mentor program to surround you with experts and resources to help get you up to speed.

Who You Are
Would you enjoy finding security flaws in mission-critical systems, modeling prototype attacks that malicious users might take advantage of, and designing mitigations to thwart motivated and inventive adversaries? If you have a passion for computer security, enjoy solving difficult problems, and relish working with emerging technologies, Cisco wants you! Global ISPs, Fortune 500 companies, and world governments all depend on Cisco for critical infrastructure, and we want the best and brightest ensuring that we keep delivering rock-solid secure solutions to meet their needs.

Desired Experience

  • 3+ years of security penetration testing experience, including areas like web applications, APIs, user interfaces, and embedded devices
  • 3+ years of software engineering experience with C, C++, or Python/Ruby, or a commonly used programming language, with experience in secure coding/development and code analysis for vulnerabilities. Recent academic experience may qualify.

Skilled in two or more of following areas:

  • Strong understanding of operating system concepts in the areas of memory management, computer architecture, or binary analysis
  • 3+ years of hands on Unix experience with a solid understanding of security hardening configurations and capabilities
  • 3+ years of experience with applied crypto, through implementation or analysis of crypto algorithms
  • 3+ years of experience with network protocols, through implementation or analysis
  • 3+ years of experience as a DevOps engineer, with a focus on DevOps security

OSCP or related industry certifications are a plus.
Other Desired Skills (and/or skills you'll have a chance to develop)

  • Applied architectural security
  • Cryptographic algorithm design and review
  • Operating system fundamentals and secure configuration
  • Security of virtualization platforms and techniques
  • Network protocol analysis and debugging
  • Web protocols and API security
  • Secure development practices
  • Software vulnerability assessment, fuzzing, and code analysis
  • Reverse engineering
  • Exploit development

Job Requirements:
Preferred sites: Knoxville, Tennessee; Austin, Texas; or Research Triangle Park, North Carolina. Willing to consider remote.
US Citizenship is required due to the nature of the work this position will perform and the government customers with which the role will work.
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis.
Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records

Why Cisco
#WeAreCisco, where each person is unique, but we bring our talents to work as a team and make a difference. Here's how we do it.
We embrace digital, and help our customers implement change in their digital businesses. Some may think we're "old" (30 years strong!) and only about hardware, but we're also a software company. And a security company. A blockchain company. An AI/Machine Learning company. We even invented an intuitive network that adapts, predicts, learns and protects. No other company can do what we do - you can't put us in a box!
But "Digital Transformation" is an empty buzz phrase without a culture that allows for innovation, creativity, and yes, even failure (if you learn from it.)
Day to day, we focus on the give and take. We give our best, we give our egos a break and we give of ourselves (because giving back is built into our DNA.) We take accountability, we take bold steps, and we take difference to heart. Because without diversity of thought and a commitment to equality for all, there is no moving forward.

So, you have colorful hair? Don't care. Tattoos? Show off your ink. Like polka dots? That's cool.

Cisco Covid-19 Vaccination Requirements
The health and safety of Cisco's employees, customers, and partners is a top priority. Our goal is to protect and mitigate the spread of COVID-19 infection for strong business resiliency during the pandemic. Therefore, Cisco may require new hires to be fully vaccinated against COVID-19 if the role requires business-related travel, meeting with customers/partners (including visiting third-party sites on behalf of Cisco), attending trade events, and Cisco office entry, unless otherwise prohibited by applicable law, and in countries where COVID-19 vaccination is legally required. The company will consider legally required accommodations/exceptions for medical, religious, and other reasons as per the requirements of the role and in accordance with applicable law. Additional information will be provided to candidates about the requirements and accommodation process at the offer time based on region.