Incident Commander (Information Security)
Palo Alto NetworksAbout the role
Company Description
Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
We have the vision of a world where each day is safer and more secure than the one before. These aren’t easy goals to accomplish – but we’re not here for easy. We’re here for better. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
Disruption is at the core of our technology and on our way of work to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. We’re changing the nature of work from benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.
We expect office-based employees to be in the office four days per week, with one day working from where they choose. We believe being together facilitates casual conversations and those magic moments where we can work on issues and ideas informally. These moments build capability and deepen trusted relationships and allow our people to feel safe in taking risks and being disruptive. Like so many companies, we are working through the details and things could change …. but in general if a role is deemed office-based we want our teams to be together four days per week.
Job Description
Your Career
The nature of cyber incidents is evolving, becoming more supply chain in nature, highly complex and requiring coordination and execution across multiple fronts. And as cyber threats evolve, so does Palo Alto Networks.
We are looking for a ‘calm-under-pressure’ Incident Commander to join our world class Information Security organization to coordinate responses to major cyber incidents. This person will act as commander for InfoSec Partnering accross SOC, Attack Surface Management, Product Security, Product Engineering, IT, GRC, Legal, People Team and Crisis Management. They will provide oversight, delegate and track tasks across organizations, be the source of truth for the big picture and drive containment and closure of cyber incidents. When the dust settles, they will lead a post-mortem, sharing learnings and driving remediation.
Is this you? You will be responding to threats to the fastest growing cyber security company in the world….are you ready to be the tip of the spear for the tip of the spear?
Your Impact
- Lead security incident response processes coordinating across all incident response and Information Security domains (SOC, GRC, Product Security, Attract Surface Management, Crisis Management, Legal, People Team, IT); identify and measure critical incident metrics and continually improve the efficiency and effectiveness of cross functional Security Incident Response.
- Align and coordinate responses from various Information Security functions so as to provide an integrated response and tracking.
- Work closely with peer managers Product, Legal, Crisis and Corporate IT teams to identify and implement process improvements and efficiencies to world class security practices; monitor incoming escalation channels, coordinate with teams, and drive incidents to closure.
- Lead root cause analysis and remediation actions; track and drive to closure.
- Align Security Response functions with the organization's overall business objectives
- Analyze incidents to help determine which changes and common controls need to be implemented to prevent reoccurrence and frequency of incidents
- Optimize and enhance existing processes with an eye to reducing a high operational load
Qualifications
Your Experience
- 8+ years hands-on experience in cybersecurity in general - Experience across the breadth of cybersecurity practices is desirable
- Effective written and oral communication with multiple levels of leadership involving both the business and technical sides of the business
- Experience with adversarial tactics through an offensive (e.g. Red Team-related roles) or defensive (e.g. Blue/Purple Team, Network Security roles etc.)
- Experience explaining impact of identified security issues to technical and non-technical audiences
- Problem solving and analytical skills gained through cybersecurity experience
- Experience with a broad range of technology paradigms, especially, enterprise IAM, networking, and Cloud-native engineering
Education
- Bachelor's degree from four-year college or
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s