yoinka

Technical Lead, Product Security (DevSecOps)

Arista Networks

Austin, TX, United StatesFull TimeSeniorH-1B sponsor company
Sign in to applyVerified 2h ago
Location
Austin, TX, United States
Employment
Full Time
Work model
On-Site
Level
Senior
H-1B history
31 approvals (FY2023)
Posted
2h ago

Skills

Cybersecurity

About this role

Technical Lead, Product Security (DevSecOps) Full-time Company Description Arista Networks is an industry leader in data-driven, client-to-cloud networking for large data center, campus and routing environments. Arista is a well-established and profitable company with over $8 billion in revenue. Arista’s award-winning platforms, ranging in Ethernet speeds up to 800G bits per second, redefine scalability, agility, and resilience. Arista is a founding member of the Ultra Ethernet consortium. We have shipped over 20 million cloud networking ports worldwide with Cloud Vision and EOS, an advanced network operating system. Arista is committed to open standards, and its products are available worldwide directly and through partners. At Arista, we value the diversity of thought and perspectives each employee brings. We believe fostering an inclusive environment where individuals from various backgrounds and experiences feel welcome is essential for driving creativity and innovation. Our commitment to excellence has earned us several prestigious awards, such as the Great Place to Work Survey for Best Engineering Team and Best Company for Diversity, Compensation, and Work-Life Balance. At Arista, we take pride in our track record of success and strive to maintain the highest quality and performance standards in everything we do. Job Description Who You'll Work With Arista Networks is seeking a deeply technical and operationally strategic Technical Lead, Product Security Program & Operations. In this role, you will serve as a core link between Arista’s engineering groups, external security researchers, federal stakeholders, and executive leadership. This is not a purely administrative role; it requires a strong technical background in network operating systems, exploit mechanics, and secure software development. You will drive the product security vulnerability lifecycle, lead threat modeling and penetration testing strategies for Arista’s switch architecture, integrate security mechanisms into our software development lifecycle (SDLC), and ensure our federal cloud environments maintain an aggressive security posture. Alternate Work Locations: Dallas, TX | Raleigh, NC What Will You Do? Key Responsibilities 1. Technical PSIRT, Vulnerability & Exploit Analysis Vulnerability Lifecycle Management: Drive the end-to-end process of turning discovered or reported vulnerabilities within Arista products into verified, highly accurate security advisories. Technical Triage & Root Cause Analysis: Triage incoming vulnerability reports from internal testing, automated tools, and external researchers. Evaluate exploitability, proof-of-concepts (PoCs), and determine blast radius/severity using CVSS and CWE frameworks. Developer Enablement & Advisory: Partner directly with software engineers to explain root-cause vulnerabilities, provide remediation guidance, and oversee the drafting and structural validation of technical security advisories. Coordinated Disclosure: Coordinate with the National Vulnerability Database (NVD), MITRE, and external research teams to ensure professional, precise, and timely disclosure. Metrics Strategy: Analyze vulnerability trends to identify systemic security gaps, delivering data-driven architecture recommendations to senior engineering leadership. 2. Advanced Penetration Testing & Switch Architecture Security Program Oversight & Scoping: Manage the comprehensive execution of third-party security testing and red-teaming across Arista’s product portfolio. Architectural Threat Modeling: Translate Arista’s switch architecture, control/data plane separation, and Sysdb-driven state mechanisms into clear threat vectors to scope high-value targets for penetration testers. Remediation & Validation: Critically review penetration testing findings, distinguish theoretical risks from practical exploits, and validate that engineering fixes comprehensively eliminate the underlying architectural

Technical Lead, Product Security (DevSecOps) at Arista Networks, Austin, TX, United States | Yoinka