Hiring.Camp

Program Lead, Threat Intelligence

Cisco

·

Yesterday

Salary
$195k – $286k
Location
USA-MILPITAS, United States of America
Workplace
Hybrid
Type
Full-time
Department
Human Resources
Seniority
Lead
Education
PhD
Closing date
Today
Source
Workday

Description

The application window is expected to close on: 09/10/2026

Meet the Team 

Cisco Cloud Security Group is a leading provider of Cloud Security and DNS services, enabling the world to connect to the Internet with confidence on any device, anywhere, anytime.  
 
Our approach is twofold; first Umbrella, our cloud-delivered security service, blocks advanced attacks including malware, botnets, and phishing threats, while our predictive intelligence engine uses machine learning to automate protection against newly-discovered threats before they can reach our customers. Today, we handle more than 80 billion daily Internet requests from 65 million+ users around the world. Our global network has proven reliability and adds no latency. We protect each and every one of our customers' devices globally without any hardware to install or software to maintain.  
 
Working at Cisco Cloud Security group means being surrounded by passionate and creative people who are determined to disrupt the Internet security industry with innovative ideas, world-class research and unrivaled products and services. It's a place where the best ideas are quickly transformed into products, features, campaigns and company-wide practices, with nearly 100% year-over-year usage growth!  

Your Impact  

The Program Lead, Threat Intelligence will own the end-to-end program management of threat intelligence initiatives within Cisco's Security & Networking business unit. This role bridges threat research, engineering, and product teams to ensure timely, accurate, and actionable intelligence is embedded into Cisco's security portfolio (e.g., Talos, SecureX/XDR, firewall, endpoint, and cloud security products). The ideal candidate combines strong program/project management subject area with deep knowledge of threat intelligence lifecycle, risk management, and cross-functional software integration testing. 

 

Key Responsibilities:  

1. Program Leadership 

  • Own the roadmap, planning, and execution of threat intelligence programs across multiple product lines within the Security BU. 

  • Drive cross-functional alignment across Threat Research (e.g., Talos), Product Engineering, Data Science, and Product Management teams. 

  • Define program milestones, dependencies, resourcing plans, and success metrics (objectives and key results). 

  • Provide regular status reporting and executive-level updates on program health, risks, and outcomes. 

2. Risk Identification & Management 

  • Establish and maintain a risk register for threat intelligence programs, covering technical, operational, data-quality, and third-party/vendor risks. 

  • Proactively identify risks related to intelligence feed reliability, false-positive/false-negative rates, data pipeline integrity, and coverage gaps. 

  • Partner with security, legal, and compliance teams to assess risks tied to data sourcing, sharing agreements, and regulatory requirements (e.g., export controls, data privacy). 

  • Develop and track mitigation plans; raise high-severity risks to leadership with clear options and recommendations. 

  • Conduct periodic risk reviews and post-incident/lessons-learned assessments. 

3. Integration Testing & Quality Assurance 

  • Coordinate integration testing of threat intelligence feeds and services into downstream security products (firewalls, IPS/IDS, XDR, cloud security, endpoint). 

  • Define test plans and acceptance criteria in partnership with QA/engineering, covering data ingestion, correlation accuracy, latency, and system performance under load. 

  • Oversee regression and interoperability testing when new intelligence sources, detection signatures, or product releases are introduced. 

  • Validate that intelligence outputs meet accuracy, timeliness, and actionability requirements before production release. 

  • Manage defect triage and resolution tracking through to closure with engineering teams. 

4. Program Operations & Stakeholder Management 

  • Facilitate program ceremonies (planning, stand-ups, retrospectives) using Agile/Scrum or hybrid methodologies. 

  • Manage program budget, vendor relationships, and third-party intelligence feed contracts as applicable. 

  • Serve as the main point of contact between the Threat Intelligence function and Security BU leadership, product management, and customer-facing teams. 

  • Support go-to-market readiness by ensuring intelligence capabilities are documented, tested, and communicated to sales engineering and customer success teams. 

  • Drive continuous improvement of program processes, tooling, and reporting frameworks. 

5. Cross-Functional Collaboration 

  • Work closely with Talos (or equivalent threat research organization) to translate research findings into product and program requirements. 

  • Partner with Data Engineering to ensure scalable, reliable pipelines for intelligence data ingestion and distribution. 

  • Collaborate with Security Compliance and Legal on data handling, sharing agreements (e.g., STIX/TAXII, ISACs), and regulatory obligations. 

  • Engage with customer-facing and support teams to incorporate field feedback into program priorities. 

 

Minimum Qualifications:  

  • Bachelor's + 12 years, a Master’s + 8 years, or PhD + 5 years of complex program management (preferred in software cloud environments), using both agile and waterfall, with at least 2–3 years in cybersecurity, threat intelligence, or security operations. Education should be in Engineering, Computer Science or related technical field.   

  • Experience managing multi-functional technical programs involving engineering, data, and research teams. 

  • Knowledge of threat intelligence concepts (IOCs, TTPs, MITRE ATT&CK, threat feeds, STIX/TAXII). 

  • Experience with risk identification, tracking, and mitigation frameworks in a technical/product environment. 

  • Familiarity with integration and QA testing practices for software/data platforms. 

  • Experience with program management tools (e.g., Jira, Confluence, Smartsheet, MS Project). 

 

 

Preferred Qualifications:  

  • PMP, PgMP, CSM, or SAFe certification. 

  • Prefer Security certifications such as GCTI, CISSP, or CEH. 

  • Prior experience at a network/security vendor (Cisco, Palo Alto Networks, Fortinet, CrowdStrike, etc.). 

  • Familiarity with Cisco's security portfolio (Talos, SecureX, XDR, Firepower/Secure Firewall, Umbrella, Duo). 

  • Experience with cloud-native security architectures and DevSecOps practices. 

  • Exposure to data science/ML-driven threat detection pipelines. 

  • Good communication skills with experience presenting to senior leadership and technical stakeholders. 

Why Cisco? 

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. 

We are Cisco, and our power starts with you. 

Message to applicants applying to work in the U.S. and/or Canada:

The starting salary range posted for this position is $194,600.00 to $285,700.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.

Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.

U.S. employees are offered benefits, subject to Cisco’s plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks.  Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.

U.S. employees are eligible for paid time away as described below, subject to Cisco’s policies:

  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees

  • 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco

  • Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees

  • Exempt employees participate in Cisco’s flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)

  • 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next

  • Additional paid time away may be requested to deal with critical or emergency issues for family members

  • Optional 10 paid days per full calendar year to volunteer

For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco’s policies.

Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:

  • .75% of incentive target for each 1% of revenue attainment up to 50% of quota;

  • 1.5% of incentive target for each 1% of attainment between 50% and 75%;

  • 1% of incentive target for each 1% of attainment between 75% and 100%; and

  • Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.

For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.

The applicable full salary ranges for this position, by specific state, are listed below:

New York City Metro Area:

$194,600.00 - $328,600.00

Non-Metro New York state & Washington state:

$179,000.00 - $294,000.00

* For quota-based sales roles on Cisco’s sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.

** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.

Skills

Machine LearningData ScienceData EngineeringJiraConfluenceCybersecurityAgileScrumRisk ManagementComplianceProject ManagementProgram ManagementPMPCISSP

Similar Jobs

1

AOUSC - Insider Threat Program Lead

cFocus Software Incorporated · Washington, DC

1 month ago