Program Lead, Threat Intelligence
Cisco · Milpitas, California, US
Job description
The application window is expected to close on: 09/10/2026Meet the Team Cisco Cloud Security Group is a leading provider of Cloud Security and DNS services, enabling the world to connect to the Internet with confidence on any device, anywhere, anytime. Our approach is twofold; first Umbrella, our cloud-delivered security service, blocks advanced attacks including malware, botnets, and phishing threats, while our predictive intelligence engine uses machine learning to automate protection against newly-discovered threats before they can reach our customers. Today, we handle more than 80 billion daily Internet requests from 65 million+ users around the world. Our global network has proven reliability and adds no latency. We protect each and every one of our customers' devices globally without any hardware to install or software to maintain. Working at Cisco Cloud Security group means being surrounded by passionate and creative people who are determined to disrupt the Internet security industry with innovative ideas, world-class research and unrivaled products and services. It's a place where the best ideas are quickly transformed into products, features, campaigns and company-wide practices, with nearly 100% year-over-year usage growth! Your Impact The Program Lead, Threat Intelligence will own the end-to-end program management of threat intelligence initiatives within Cisco's Security & Networking business unit. This role bridges threat research, engineering, and product teams to ensure timely, accurate, and actionable intelligence is embedded into Cisco's security portfolio (e.g., Talos, SecureX/XDR, firewall, endpoint, and cloud security products). The ideal candidate combines strong program/project management subject area with deep knowledge of threat intelligence lifecycle, risk management, and cross-functional software integration testing. Key Responsibilities: 1. Program Leadership Own the roadmap, planning, and execution of threat intelligence programs across multiple product lines within the Security BU. Drive cross-functional alignment across Threat Research (e.g., Talos), Product Engineering, Data Science, and Product Management teams. Define program milestones, dependencies, resourcing plans, and success metrics (objectives and key results). Provide regular status reporting and executive-level updates on program health, risks, and outcomes. 2. Risk Identification & Management Establish and maintain a risk register for threat intelligence programs, covering technical, operational, data-quality, and third-party/vendor risks. Proactively identify risks related to intelligence feed reliability, false-positive/false-negative rates, data pipeline integrity, and coverage gaps. Partner with security, legal, and compliance teams to assess risks tied to data sourcing, sharing agreements, and regulatory requirements (e.g., export controls, data privacy). Develop and track mitigation plans; raise high-severity risks to leadership with clear options and recommendations. Conduct periodic risk reviews and post-incident/lessons-learned assessments. 3. Integration Testing & Quality Assurance Coordinate integration testing of threat intelligence feeds and services into downstream security products (firewalls, IPS/IDS, XDR, cloud security, endpoint). Define test plans and acceptance criteria in partnership with QA/engineering, covering data ingestion, correlation accuracy, latency, and system performance under load. Oversee regression and interoperability testing when new intelligence sources, detection signatures, or product releases are introduced. Validate that intelligence outputs meet accuracy, timeliness, and actionability requirements before production release. Manage defect triage and resolution tracking through to closure with engineering teams. 4. Program Operations & Stakeholder Management Facilitate program ceremonies (planning, stand-ups, retrospectives) using Agile/Scrum or hybrid methodologies. Manage program budget, vendor relationships, and third-party intelligence feed contracts as applicable. Serve as the main point of contact between the Threat Intelligence function and Security BU leadership, product management, and customer-facing teams. Support go-to-market readiness by ensuring intelligence capabilities are documented, tested, and communicated to sales engineering and customer success teams. Drive continuous improvement of program processes, tooling, and reporting frameworks. 5. Cross-Functional Collaboration Work closely with Talos (or equivalent threat research organization) to translate research findings into product and program requirements. Partner with Data Engineering to ensure scalable, reliable pipelines for intelligence data ingestion and distribution. Collaborate with Security Compliance and Legal on data handling, sharing agreements (e.g., STIX/TAXII, ISACs), and regulatory obligations. Engage with customer-facing and support teams to incorporate field feedback into program priorities. Minimum Qualifications: Bachelor's + 12 years, a Master’s + 8 years, or PhD + 5 years of complex program management (preferred in software cloud environments), using both agile and waterfall, with at least 2–3 years in cybersecurity, threat intelligence, or security operations. Education should be in Engineering, Computer Science or related technical field. Experience managing multi-functional technical programs involving engineering, data, and research teams. Knowledge of threat intelligence concepts (IOCs, TTPs, MITRE ATT&CK, threat feeds, STIX/TAXII). Experience with risk identification, tracking, and mitigation frameworks in a technical/product environment. Familiarity with integration and QA testing practices for software/data platforms. Experience with program management tools (e.g., Jira, Confluence, Smartsheet, MS Project). Preferred Qualifications: PMP, PgMP, CSM, or SAFe certification. Prefer Security certifications such as GCTI, CISSP, or CEH. Prior experience at a network/security vendor (Cisco, Palo Alto Networks, Fortinet, CrowdStrike, etc.). Familiarity with Cisco's security portfolio (Talos, SecureX, XDR, Firepower/Secure Firewall, Umbrella, Duo). Experience with cloud-native security architectures and DevSecOps practices. Exposure to data science/ML-driven threat detection pipelines. Good communication skills with experience presenting to senior leadership and technical stakeholders. Why Cisco? At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere. We are Cisco, and our power starts with you. Message to applicants applying to work in the U.S. and/or Canada: The starting salary range posted for this position is $194,600.00 to $285,700.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits. Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can s
Verified and listed by ActiveJobs. Applications are made directly on Cisco's own career page — we never sit in the middle.