Offensive Security Engineer
Location:Offsite, Fulton, Maryland, US
Alternate LocationPreferred sites: Knoxville, Tennessee; Austin, Texas; or Research Triangle Park, North Carolina. Willing to consider remote
Area of InterestSecurity
What You'll Do
As a team member of Cisco's Advanced Security Initiatives Group, you will evaluate our products and services to identify security vulnerabilities, weaknesses, and improvements that result in more resilient and hardened offers used by our global customers. You will learn to adopt an attacker mindset using tools, techniques, and processes that emulate those used by sophisticated and motivated adversaries. You will work with amazingly creative, innovative, and collaborative security researchers to continuously develop new and constantly evolving ethical hacker skills and expansive networking product knowledge. You will partner with Cisco's industry leading engineering teams to review the latest complex and industry leading system and application architectures, contribute to creative security solutions, and gain unparalleled access to and experience with the latest technologies. You will also have opportunities to work on independent and/or team research of advanced topics to explore and develop your own new and novel tools and ideas as part of our "Free Friday" innovation incubation process.
Who You'll Work With
Our security team is dynamic, hardworking, fun, and high-energy, but the work is done in a very casual environment that strongly encourages a good work/life balance. Not only will you will be working alongside a team of expert security researchers with a diverse spectrum of skills and experience levels, you will also be interacting with a variety of engineering teams across Cisco. Cisco ASIG cultivates an environment where every individual's input and experience is valued. Our team prioritizes training sessions and a mentor program to surround you with experts and resources to help get you up to speed.
Who You Are
Would you enjoy finding security flaws in mission-critical systems, modeling prototype attacks that malicious users might take advantage of, and designing mitigations to thwart motivated and inventive adversaries? If you have a passion for computer security, enjoy solving difficult problems, and relish working with emerging technologies, Cisco wants you! Global ISPs, Fortune 500 companies, and world governments all depend on Cisco for critical infrastructure, and we want the best and brightest ensuring that we keep delivering rock-solid secure solutions to meet their needs.
- 3+ years of security penetration testing experience, including areas like web applications, APIs, user interfaces, and embedded devices
- 3+ years of software engineering experience with C, C++, or Python/Ruby, or a commonly used programming language, with experience in secure coding/development and code analysis for vulnerabilities. Recent academic experience may qualify.
Skilled in two or more of following areas:
- Strong understanding of operating system concepts in the areas of memory management, computer architecture, or binary analysis
- 3+ years of hands on Unix experience with a solid understanding of security hardening configurations and capabilities
- 3+ years of experience with applied crypto, through implementation or analysis of crypto algorithms
- 3+ years of experience with network protocols, through implementation or analysis
- 3+ years of experience as a DevOps engineer, with a focus on DevOps security
OSCP or related industry certifications are a plus.
Other Desired Skills (and/or skills you'll have a chance to develop)
- Applied architectural security
- Cryptographic algorithm design and review
- Operating system fundamentals and secure configuration
- Security of virtualization platforms and techniques
- Network protocol analysis and debugging
- Web protocols and API security
- Secure development practices
- Software vulnerability assessment, fuzzing, and code analysis
- Reverse engineering
- Exploit development
Preferred sites: Knoxville, Tennessee; Austin, Texas; or Research Triangle Park, North Carolina. Willing to consider remote.
US Citizenship is required due to the nature of the work this position will perform and the government customers with which the role will work.
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis.
Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records
WHY CISCO SECURE
#WeAreCisco, where each person is unique. We bring our talents to work as a team each day, helping power an inclusive future for all. Get to know us!
We’re global, we’re adaptable, we’re diverse, and our security portfolio is as extensive as it is groundbreaking. Have you heard of Threat, Detection & Response, Zero Trust by Duo, Common Services Engineering, or Cloud & Network Security? Those are only a few of our product teams! The only thing we’re missing is YOU.
Join an enterprise security leader with a start-up culture, committed to driving innovation and giving you the opportunity to make an impact. We #InnovateToWin and we know we’re better together, that’s why we’re dedicated to inclusivity, collaboration, and diversity in everything we do.
We’re proud to be the Best Security Company in 2021 with the Best Authentication Technology and the Best Small and Mid-Size Enterprises Security Solution in 2022 by SC Media. Cisco Secure continues to grow and evolve year after year with 100% of Fortune 100 Companies using our products, and we’re excited to see the new heights we’ll reach with your passion for security, your customer focus, and your desire to change things up!
What else can you expect? An ongoing investment in your growth—that’s why we offer many employee resource groups (called Inclusive Communities), mentorship programs, and hundreds of learning resources to consistently level up your skillset and explore your interests. Because when you succeed, we succeed!
“Cisco Secure offers an environment that combines cutting-edge, mission-critical, technology with some of the brightest, most diverse set of people I’ve ever had the pleasure of working with.” – Chief of Staff, Engineering
Join Cisco Secure – Be You, With Us!
The health and safety of Cisco's employees, customers, and partners is a top priority. Our goal is to protect and mitigate the spread of COVID-19 infection for strong business resiliency during the pandemic. Therefore, Cisco may require new hires to be fully vaccinated against COVID-19 if the role requires business-related travel, meeting with customers/partners (including visiting third-party sites on behalf of Cisco), attending trade events, and Cisco office entry, unless otherwise prohibited by applicable law, and in countries where COVID-19 vaccination is legally required. The company will consider legally required accommodations/exceptions for medical, religious, and other reasons as per the requirements of the role and in accordance with applicable law. Additional information will be provided to candidates about the requirements and accommodation process at the offer time based on region.