Principal Consultant, Cloud DFIR, Reactive Services (Unit 42)
Palo Alto NetworksAbout the role
Company Description
Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
Our Approach to Work
We lead with flexibility and choice in all of our people programs. We have disrupted the traditional view that all employees have the same needs and wants. We offer personalization and offer our employees the opportunity to choose what works best for them as often as possible - from your wellbeing support to your growth and development, and beyond!
At Palo Alto Networks, we believe in the power of collaboration and value in-person interactions. This is why our employees generally work from the office three days per week, leaving two days for choice and flexibility to work where you feel most effective. This setup fosters casual conversations, problem-solving, and trusted relationships. While details may evolve, our goal is to create an environment where innovation thrives, with office-based teams coming together three days a week to collaborate and thrive, together!
Job Description
Your Career
This role is client-facing and requires the Principal Consultant to lead and produce deliverables based on reactive services client engagements. The Principal Consultant will work directly with multiple customers and key stakeholders (Admins, C-Suite, etc) to drive the security priorities of the Cloud Platforms (Azure, AWS, GCP) and Cloud Related Applications/Services (CASB).
Your Impact
- Perform reactive incident response functions in public cloud environments, primarily Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and AliCloud
- Examine compute, storage, network, IAM, Kubernetes, serverless, and other log sources to identify evidence of malicious activity
- Investigate data breaches leveraging traditional forensic tools, cloud-specific tools, and custom Unit 42 techniques to determine the source of compromises and malicious activity that occurred in client environments
- Manage incident response engagements to scope work, guide clients through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations
- Ability to perform travel requirements as need to meet business demands (on average 20%)
- Mentorship of team members in incident response and forensics best practices
Qualifications
Your Experience
- 6+ years of incident response or digital forensics consulting experience with a passion for cyber security
- 3+ years in a cloud environment as an administrator, security operator, or consultant- DevOps experience welcome
- Hands-on experience with architecting, building, operating, investigating, and troubleshooting large and complex cloud environments
- Understand and demonstrate best practices for architecting and operating in a cloud environment
- Experience with large-scale application administration and debugging, Cloud Security Posture Management (CSPM) solutions, or automation via scripting or cloud-native approaches
- Strong leadership skills including experience managing a team or individuals
- Experience with leading complicated engagements including scoping, interfacing with the client, and have executed on a technical front
- Proficient with host-based forensics and data breach response
- Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open source forensic tools
- Identified ability to grow into a valuable contributor to the practice and, specifically -
- have an external presence via public speaking, conferences, and/or publications
- have credibility, executive presence, and gravitas
- be able to have a meaningful and rapid delivery contribution
- have the potential and capacity to understand all aspects of the business and an excellent understanding of PANW products
- be collaborative and able to build relationships internally, externally, and across all PANW functions, including the sales team
- Incident response consulting experience required
- Ability to perform travel requirements as needed to meet business demands (on average 20%)
- Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security or related field or equivalent military experience required
Additional Information
The Team
U
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s