Technical Lead (Threat Modeling, PSIRT)

Arista Networks
Austin, Dallas, Raleigh
Workplace: OnsiteFull timeFunction: Administration & Executive AssistanceSkills: ["Clear technical communication","Developer enablement","Threat assessment","Risk analysis","Stakeholder coordination"]

Drive Arista product security across the vulnerability lifecycle—triaging and analyzing exploits, coordinating disclosure, and advising engineering teams on remediation. Lead advanced penetration testing and threat modeling for switch architecture, and embed secure checkpoints across the SDLC with DevSecOps tooling. Administer and harden Arista’s federal Google Workspace environment, monitor for threats, and support enterprise and federal customer security discussions with regulatory-focused technical guidance.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Arista Networks
Arista Networks
6 hours ago

Technical Lead (Threat Modeling, PSIRT)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live
Reposted: similar role first listed 4 days ago

Job Summary

Drive Arista product security across the vulnerability lifecycle—triaging and analyzing exploits, coordinating disclosure, and advising engineering teams on remediation. Lead advanced penetration testing and threat modeling for switch architecture, and embed secure checkpoints across the SDLC with DevSecOps tooling. Administer and harden Arista’s federal Google Workspace environment, monitor for threats, and support enterprise and federal customer security discussions with regulatory-focused technical guidance.
Location: Austin, Dallas, Raleigh
Workplace: Onsite
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Sr. Manager level

Key Responsibilities

  • •Manage the end-to-end vulnerability lifecycle from reported issues to verified security advisories, including triage, exploitability assessment, and severity using CVSS/CWE.
  • •Oversee advanced penetration testing and red-teaming, scoping targets through architectural threat modeling and validating remediation against practical exploitability.
  • •Architect and implement secure SDLC/DevSecOps controls, integrating SAST/DAST/SCA and container scanning into CI/CD and promoting secure coding standards and threat modeling practices.
  • •Administer and monitor the dedicated federal Google Workspace environment, hardening configurations for FedRAMP/NIST controls and leading threat hunting, incident response, and change risk assessments.
  • •Serve as a technical SME for enterprise and federal customer security discussions, including regulatory advisory and authoring/validating responses related to product architecture and security mandates.

Key Requirements

  • •7+ years in product security, software security engineering, PSIRT operations, or advanced cloud security administration.
  • •Hardening experience for enterprise/federal cloud environments, specifically Google Workspace or major cloud providers (AWS/GCP), with access controls and audit logging.
  • •Familiarity with federal/state/local compliance frameworks such as FedRAMP, NIST, and FIPS.
  • •Strong knowledge of software vulnerabilities and exploit mechanics, including frameworks like CVSS, CWE, OWASP Top 10, and MITRE ATT&CK.
  • •In-depth networking and switch architecture knowledge, including network OS internals (ideally Linux-based like Arista EOS), control/data plane protection, and relevant protocols (e.g., BGP, OSPF, gRPC, SNMP).
Skills:Clear technical communicationDeveloper enablementThreat assessmentRisk analysisStakeholder coordination
Languages:English
Tech Stack:Threat ModelingPSIRTPenetration testingVulnerability Lifecycle ManagementCVSSCWENVDMITRE ATT&CKOWASP Top 10STRIDEFedRAMPNIST 800-53NISTFIPSGoogle WorkspaceAWSGCPSASTDASTSCA

Company Brief

Arista Networks
Designs and sells high-performance cloud networking hardware and software for large-scale data centers and enterprise environments, including switches, routers, and network operating systems focused on programmability, telemetry, and low-latency networking.
Industry: Networking Equipment
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Santa Clara, United States
Founded: 2004
Glassdoor
Glassdoor: 4.1
WebsiteLinkedIn