Technical Lead, Product Security (DevSecOps)
Austin, TX - USA
Job Summary
Who Youll Work With
Arista Networks is seeking a deeply technical and operationally strategic Technical Lead
Product Security Program & this role you will serve as a core link between
Aristas engineering groups external security researchers federal stakeholders and executive
leadership.
This is not a purely administrative role; it requires a strong technical background in network
operating systems exploit mechanics and secure software development. You will drive the
product security vulnerability lifecycle lead threat modeling and penetration testing strategies
for Aristas switch architecture integrate security mechanisms into our software development
lifecycle (SDLC) and ensure our federal cloud environments maintain an aggressive security
posture.
Alternate Work Locations: Dallas TX Raleigh NC
What Will You Do
Key Responsibilities
1. Technical PSIRT Vulnerability & Exploit Analysis
- Vulnerability Lifecycle Management: Drive the end-to-end process of turning discovered or reported vulnerabilities within Arista products into verified highly accurate security advisories.
- Technical Triage & Root Cause Analysis: Triage incoming vulnerability reports from internal testing automated tools and external researchers. Evaluate exploitability proof-of-concepts (PoCs) and determine blast radius/severity using CVSS and CWE frameworks.
- Developer Enablement & Advisory: Partner directly with software engineers to explain root-cause vulnerabilities provide remediation guidance and oversee the drafting and structural validation of technical security advisories.
- Coordinated Disclosure: Coordinate with the National Vulnerability Database (NVD) MITRE and external research teams to ensure professional precise and timely disclosure.
- Metrics Strategy: Analyze vulnerability trends to identify systemic security gaps delivering data-driven architecture recommendations to senior engineering leadership.
2. Advanced Penetration Testing & Switch Architecture Security
- Program Oversight & Scoping: Manage the comprehensive execution of third-party security testing and red-teaming across Aristas product portfolio.
- Architectural Threat Modeling: Translate Aristas switch architecture control/data plane separation and Sysdb-driven state mechanisms into clear threat vectors to scope high-value targets for penetration testers.
- Remediation & Validation: Critically review penetration testing findings distinguish theoretical risks from practical exploits and validate that engineering fixes comprehensively eliminate the underlying architectural susceptibility to security issues.
- Executive Reporting: Distill complex cryptographic hardware or software vulnerabilities into clear risk profiles for executive management and enterprise customers.
3. Secure SDLC & DevSecOps Engineering
- Shifting Left: Architect implement and optimize security checkpoints throughout Aristas development lifecycles to detect flaws before code reaches production.
- Pipeline Integration: Drive the adoption and tuning of automated security tooling (SAST DAST SCA and container scanning) directly into the CI/CD infrastructure.
- Secure Coding Standards: Define and evangelize secure coding practices threat modeling principles (e.g. STRIDE) and framework-level mitigations to mitigate common software flaws (memory unsafety injection privilege escalation).
- Continuous Improvement: Audit existing development workflows to eliminate friction between engineering velocity and product security compliance.
4. Federal Cloud Security Administration & Infrastructure Monitoring
- Federal Workspace Administration: Securely administer and monitor the dedicated Google Workspace environment for Arista Federal.
- Compliance Hardening: Configure and audit cloud infrastructure settings in strict accordance with industry frameworks and federal regulations (e.g. FedRAMP NIST 800-53).
- Threat Hunting & Incident Response: Actively monitor logging alerting systems and audit trails to identify investigate and remediate suspicious activity or misconfigurations.
- Change Management: Lead security risk assessments for all proposed system alterations in coordination with Arista IT Security and Federal Management.
5. Customer Trust & Regulatory Compliance
- Technical Customer Engagement: Act as the primary technical subject matter expert (SME) during deep-dive security discussions with enterprise and federal customers.
- Regulatory Advisory: Authoritatively address complex customer compliance inquiries regarding product architecture supply chain integrity and federal security mandates.
Qualifications :
- Security Vulnerabilities & Exploit Theory: Deep understanding of software vulnerabilities exploit mechanics (e.g. buffer overflows race conditions logical bypasses dependency vulnerabilities) cryptography and modern mitigation techniques. Strong familiarity with standard frameworks including CVSS CWE OWASP Top 10 and MITRE ATT
- Networking & Switch Architecture: In-depth understanding of network switch architecture composition and management. Knowledge of network operating system internals (ideally Linux-based such as Arista EOS) control plane protection data plane forwarding ASIC-level considerations and protocols (e.g. BGP OSPF gRPC SNMP).
- Secure Development & SDLC: Robust knowledge of modern software engineering methodologies version control (Git) and CI/CD pipelines. Hands-on experience integrating and managing AppSec tools (SAST/DAST) and implementing Threat Modeling practices in an enterprise environment.
Experience & Operational Skills
- Experience: 7 years of experience in Product Security Software Security Engineering PSIRT operations or Advanced Cloud Security Administration.
- Cloud Infrastructure: Proven experience hardening enterprise/federal cloud spaces specifically Google Workspace or major cloud providers (AWS/GCP) with an emphasis on access controls logging and audit logs.
- Compliance Standards: Familiarity with Federal State and Local compliance regulations (e.g. FedRAMP NIST FIPS).
- Communication: Exceptional ability to articulate highly technical security flaws and architectural concepts clearly to software developers enterprise customers and non-technical business executives alike.
#LI-TC1
Additional Information :
Arista stands out as an engineering-centric company. Our leadership including founders and engineering managers are all engineers who understand sound software engineering principles and the importance of doing things right.
We hire globally into our diverse team. At Arista engineers have complete ownership of their projects. Our management structure is flat and streamlined and software engineering is led by those who understand it best. We prioritize the development and utilization of test automation tools.
Our engineers have access to every part of the company providing opportunities to work across various domains. Arista is headquartered in Santa Clara California with development offices in Australia Canada India Ireland and the US. We consider all our R&D centers equal in stature.
Join us to shape the future of networking and be part of a culture that values invention quality respect and fun.
Arista Networks is an equal opportunity employer. Arista makes all hiring and employment-related decisions in a non-discriminatory manner without regard to race color religion sex sexual orientation gender identity national origin or any other factor determined to be unlawful under applicable federal state or law law. All your information will be kept confidential according to EEO guidelines.
Remote Work :
No
Employment Type :
Full-time
About Company
Arista Networks is an industry leader in data-driven, client-to-cloud networking for large data center, campus and routing environments. What sets us apart is our relentless pursuit of innovation. We leverage the latest advancements in cloud computing, artificial intelligence, and sof ... View more