Security Engineering Manager (GRC Program), Remote within U.S.
About the role
Cisco is seeking a transformational Head of Governance, Risk & Compliance (GRC) to lead the modernization of product security governance, compliance, and risk assurance across the Network Platform Security Organization’s global portfolio of cloud, SaaS, networking, OT/IoT, and hardware products.
Responsibilities
- Lead the transformation of Network Platform Security Organization’s product GRC function into a modern, engineering-driven risk and assurance organization.
- Balance regulatory rigor with speed, scalability, and business enablement.
- Influence senior leaders across security, engineering, product, legal, and enterprise governance organizations.
- Drive a culture of automation, measurable risk transparency, engineering partnership, and operational excellence.
- Own divisional product compliance programs and certifications, including FedRAMP, ISO 27001, SOC, NIST-aligned frameworks, global privacy/security obligations, and emerging regulatory requirements.
- Design and implement AI-enabled GRC operating models that leverage automation, telemetry, analytics, and workflow orchestration to improve risk visibility and operational efficiency.
Requirements
- Bachelor's Degree combined with 8 years of experience in cybersecurity, product security, governance/risk/compliance, or security engineering leadership roles within global technology organizations, or Master's Degree, combined with +6 years of related experience, or PhD, combined with 3 years of similar experience.
- Previous supervisory experience also required.
- Experience leading large-scale GRC transformation initiatives in complex product or cloud environments.
- Understanding of modern compliance and assurance frameworks including FedRAMP, ISO 27001, SOC 2, NIST, GDPR, NIS2, DORA, PCI, and related global regulatory frameworks.
- Experience building or scaling automation-first governance, continuous compliance, or GRC engineering capabilities.
- Leadership experience managing technical and cross-functional teams.
Qualifications
- Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, or related field.
- Master's Degree in Business Administration, Information Technology, or related field.
- PhD in Engineering, Computer Science, or related field.
- Experience leading large-scale GRC transformation initiatives in complex product or cloud environments.
- Understanding of modern compliance and assurance frameworks including FedRAMP, ISO 27001, SOC 2, NIST, GDPR, NIS2, DORA, PCI, and related global regulatory frameworks.
- Experience building or scaling automation-first governance, continuous compliance, or GRC engineering capabilities.
- Leadership experience managing technical and cross-functional teams.
Skills
- Experience within cloud, SaaS, enterprise networking, OT/IoT, or hardware product environments.
- Background in DevSecOps, controls engineering, security automation, or risk engineering.
- Experience with AI/LLM-enabled operational tooling or analytics platforms.
- Experience crafting scalable governance platforms and internal assurance tooling.
- Industry certifications such as CISSP, CISM, CRISC, CISA, ISO Lead Auditor, or equivalent.
Benefits
The successful applicant may be performing work in FedRAMP High or IL-5 environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee).
Pay
The starting salary range posted for this position is $183,800.00 to $263,600.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Schedule
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training.