Technical Lead Threat Modeling PSIRT Arista Networks
Overview
Arista Networks seeks a Technical Lead to own threat modeling and PSIRT at a leading data center networking firm. This role bridges engineering groups and external researchers while driving security initiatives.
What You'll Do16
- 1Lead technical PSIRT and vulnerability exploit analysis to convert discovered issues into security advisories
- 2Perform triage and root cause analysis of vulnerability reports using CVSS and CWE frameworks
- 3Partner with software engineers to explain vulnerabilities and draft technical security advisories
- 4Coordinate disclosure with NVD MITRE and external researchers for timely and accurate reporting
- 5Analyze vulnerability trends to deliver architecture recommendations to senior leadership
- 6Manage third-party security testing and red-teaming across product portfolio
- 7Translate switch architecture into threat vectors for penetration testing scopes
- 8Validate remediation effectiveness after exploitation findings
- 9Distill complex cryptographic issues into risk profiles for executive management
- 10Architect secure SDLC and DevSecOps pipelines with automated security tooling
- 11Define secure coding standards and conduct threat modeling using STRIDE
- 12Administer and monitor Google Workspace for federal cloud environments
- 13Authoritatively address regulatory compliance questions from enterprise customers
- 14Serve as technical SME during security discussions with clients
- 15Implement access controls logging and audit trails for federal workspaces
- 16Lead security risk assessments for system changes in coordination with IT Security
Requirements11
- 15+ years building ETL pipelines with Spark Airflow
- 27+ years in Product Security or PSIRT operations
- 33-5 seasons of cloud infrastructure administration experience
- 45+ years hardening enterprise/federal cloud environments
- 5Familiarity with FedRAMP NIST 800-53 compliance standards
- 6Strong knowledge of CVSS CWE MITRE ATT frameworks
- 7Expertise in network switch architecture and Linux-based OS internals
- 8Proficiency in SAST DAST and container scanning tools
- 9Experience with STRIDE threat modeling methodologies
- 10Background in secure coding practices and privilege escalation mitigation
- 11Demonstrated ability to influence cross-functional teams
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
David Joseph & Company
VerifiedSenior Staff Security Engineer
Lead the end-to-end security posture of an AI coworker product for enterprise IT teams. Own application cloud network and agent security while defining a novel category. Drive secure design reviews build security primitives and manage incident response. This is a full-time role in San Francisco with equity compensation.
Amazon.com Services LLC
VerifiedSecurity Intelligence Engineer Incident Response Threat Intelligence ACTI
Threat Intelligence Engineer leading proactive defense against advanced cyber threats for Amazon employees and assets. This role drives incident response, develops analytic techniques, and collaborates across teams to mitigate malicious activity. Candidates must analyze large datasets, create automation, and contribute to threat intelligence.
Palo Alto Networks
VerifiedPrincipal Network Security Architect | Palo Alto Networks
You will own the architectural blueprint and governance for a global network security footprint spanning hybrid cloud and on-prem. As Principal Enterprise Network Security Architect, you will drive Zero Trust adoption, security automation, and AI/ML integration. You will collaborate with security, infrastructure, and IT teams to embed security into every layer. This role stands out for its automation-first approach and ultimate escalation authority during critical events.
Bright Vision Technologies
VerifiedApplication Security Engineer Bright Vision Technologies
Lead security integration across software development lifecycles for a remote full-time role at Bright Vision Technologies. Own security practices while collaborating with engineering teams to build resilient applications. Drive measurable risk reduction through proactive threat mitigation and secure coding standards.

Belcan, LLC
VerifiedCybersecurity Operations & Communications Lead
Own the security operations and communications strategy for a global enterprise, coordinating incident response across SIEM, SOAR, and EDR platforms. You lead a team of analysts, manage threat intelligence feeds, and craft executive-level briefings. This role sits at the intersection of technical operations and stakeholder communication, reporting directly to the CISO. You will drive the adoption of MITRE ATT&CK framework and NIST guidelines, shaping the organization's cyber resilience.
SPAHR SOLUTIONS GROUP LLC
VerifiedCybersecurity Protect Analyst
Lead technical cybersecurity liaison for subscriber organizations delivering advanced guidance on resolving complex security posture issues and patching delays. Serve as primary auditor for Data Element Dictionary governance overseeing validation rules for identity-attributed network and object-access events. Manage vulnerability tracking and KEV mitigation leveraging CVE NVD CVSS and CWE classifications. Conduct vulnerability assessments using ACAS and other enterprise scanning tools to provide prioritized remediation steps.