Jobs and Careers
PA

Principal Product Security Engineer

Palo Alto Networks
Santa Clara, United Statesfull_timeVerifiedPosted 1 Aug 2023
💰 $247,500/yr($153,000/yr$247,500/yr)

About the role

Company Description

Our Mission

At Palo Alto Networks® everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

FLEXWORK is an employee-centric reimagining of how we work. We built FLEXWORK based on employee feedback – it is about flexibility, trust, and choice whenever possible. It’s been a journey of disruption that has yielded the best of our values. We offer as much flexibility as possible, and choices that enable you to be most productive, including benefits that meet your needs and learning opportunities that you feel passionate about.

Job Description

Your Career 

Developing industry-leading security tools is tough, and ensuring they are built securely is just as tough, especially when operating at scale. It takes a lot of effort, coordination, and often custom tooling on top of the already industry-leading tools that are used to secure some of the largest companies in the world.

Palo Alto Networks is disrupting the Cyber Security industry! We are looking for a Principal Product Security Engineer to join our Product Security team, which works with all Palo Alto Networks product engineering teams to provide assistance and guidance on how to secure our products. With your security skills, help identify and report security issues via SAST. You’ll also collaborate with other team members to drive remediation of security issues, and drive continuous improvement of results. In this role you will provide technology leadership in development of security programs by helping to drive disruptive vision, technology planning and estimation. If you are a fast learner and passionate about Cyber Security, this is a great opportunity for you.

We expect office-based employees to be in the office four days per week, with one day working from where they choose. We believe being together facilitates casual conversations and those magic moments where we can work on issues and ideas informally. These moments build capability and deepen trusted relationships and allow our people to feel safe in taking risks and being disruptive. Like so many companies, we are working through the details and things could change …. but in general if a role is deemed office-based we want our teams to be together four days per week.

Your Impact 

  • Static Application Security Testing 
    • Take ownership of the Appsec offering to product development teams
    • Work with security engineers and product development teams to provide accurate, actionable results
    • Build next gen appsec technologies with automation into complex engineering CI/CD pipelines
    • Build risk driven intelligent automation to optimize Security findings and remediations
  • Products/Tools Design & Development
    • Design and implement consumable software and services for internal and external customers -Ensure on-schedule delivery of a high-quality product that meets technical requirements 
    • Solutions design for new services (in partnership with Architecture and SRE)
    • Build vs Buy Research and Evaluation
    • Take ownership and/or lead the engineering responsibility for multiple components in a project
  • Consulting & Support
    • Evangelize and lead the adoption of Secure SDLC and security best practices across the entire SDLC - You’re someone that possesses strong knowledge of security from code to cloud and wants to help people apply it
    • Implement programs to automate complex data analysis for high priority security missions
    • Build tools/reports to support urgent requests
    • Evaluate options and provide recommendations on scope and scale of effort required to develop solutions
    • This includes creating reference implementations and reusable templates that are used to make our products secure by default
  • Clearly communicate on the status of projects or other issues - Establish a working relationship with other groups across the organization to successfully implement business requirements while applying the latest available tools and technology

Qualifications

Your Experience

  • Experience performing threat modeling and design reviews to assess security implications and requirements
  • Experience in defining and documenting security reference architectures and standards
  • Experience explaining impact of identified security issues to technical and non-technical audiences
  • Experience guiding remediation of security issues with soft

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Palo Alto Networks

View company profile →