Principal Consultant, Security Research Services (Unit 42)
Palo Alto NetworksAbout the role
Company Description
Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
We have the vision of a world where each day is safer and more secure than the one before. These aren’t easy goals to accomplish – but we’re not here for easy. We’re here for better. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
We’re changing the nature of work. Palo Alto Networks is evolving to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. From benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.
Job Description
Your Career
Unit 42 is looking for Consultants to work with a single, long-term client across a wide range of unique security and regulatory needs. Unit 42 has nine distinct teams working on this engagement, and understands nobody will have all of the skills listed below - but the ability to be versatile and work across multiple teams is highly desirable. Unit 42 is looking for someone who can help us help our clients better manage their data risk, exposure, and compliance obligations.
Your Impact
- Investigate mobile applications, websites, browser extensions, and other digital assets
- Leverage physical and emulated sandboxed environments for analysis
- Leverage proxy technologies to capture web traffic generated by applications
- Inspect web traffic logs to identify anomalous or suspicious activity
- Identify unauthorized exfiltration, handling, or use of end-user data including Personally Identifiable Information (“PII”), created content, credentials, etc
- Understand and adhere to best practices for operational security (“OPSEC”) concepts
- Edit and write SQL queries or scripts to query APIs
- Review application source code and artifacts
- Reverse engineering of applications, tools, etc
- Leverage formal and informal internal documentation to quickly interpret unknown data behavior
- Create replicable processing scripts/notebooks, and document steps taken
- Help develop and refine ongoing data and code review strategies and workflows
- Regularly and uniformly report findings. Create a narrative to the analysis performed
- Understand how web requests are formed including POST parameters, HTTP headers, user agents, request parameters, request cookies, etc
- Query back-end databases using Presto SQL
- Utilize web logs to identify traffic and request patterns
- Review and validate external penetration test results to determine severity
- Actively participate in the development, documentation, and implementation of new processes to expand and mature capabilities for the organization
- Continuous involvement in workstream growth and process improvement
Qualifications
Your Experience
- Ideal candidate will have 7+ years of following
- Bachelor’s Degree, or equivalent military experience, preferably in a technical or security-related field
- Knowledge of fundamental computer science concepts
- Positions or experience with corporate data environments, databases, and/or security experience preferred
- Analytical problem-solving skills, including how to interpret technical requirements and turn them into operational steps that can scale
- Ability to work both independently and as an effective team member, in a fast-paced environment - Strong multi-tasking and time-management skills
- Privacy or cybersecurity industry certifications are a plus
- Proven ability to work analytically while demonstrating effective leadership, project management, teamwork, and innovation
- Experience in working with smaller teams and/or start-up organizations.
- Software development or scripting experience is a plus
- Identified ability to grow into a valuable contributor to the practice and, specifically
- have an external presence via public speaking, conferences, and/or publications
- have credibility, executive presence, and gravitas
- be able to have a meaningful and rapid delivery contribution
- have the potential and capacity to understand all aspects of the business and an excellent understanding of PANW products
- be collaborative and able to build relationships internally, externally, and across all PANW functions, including
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s