Jobs and Careers
PA

Sr. Staff Security Engineer, Attack Surface Management

Palo Alto Networks
Santa Clara, United Statesfull_timeVerifiedPosted 7 Mar 2024
💰 $233,200/yr($144,200/yr$233,200/yr)

About the role

Company Description

Our Mission

At Palo Alto Networks® everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

Our Approach to Work

We lead with flexibility and choice in all of our people programs. We have disrupted the traditional view that all employees have the same needs and wants. We offer personalization and offer our employees the opportunity to choose what works best for them as often as possible - from your wellbeing support to your growth and development, and beyond!

At Palo Alto Networks, we believe in the power of collaboration and value in-person interactions. This is why our employees generally work from the office three days per week, leaving two days for choice and flexibility to work where you feel most effective. This setup fosters casual conversations, problem-solving, and trusted relationships. While details may evolve, our goal is to create an environment where innovation thrives, with office-based teams coming together three days a week to collaborate and thrive, together!

Job Description

Your Career

As a member of the Attack Surface Management team within the Information Security organization, your duties will include protecting mission-critical platforms, tools, and applications that will ensure the highest levels of security, availability and reliability of all our services and applications. You will use your creative and innovative problem solving abilities to partner with and support our IT and product teams to ensure their cloud based and data center services maintain our high security standards while supporting availability and functionality. 

Your Impact

  • Discover and analyze vulnerabilities for on-prem and cloud environments
  • Engage with IT and product teams to remediate vulnerability findings
  • Collaborate with Governance Risk Compliance (GRC) on attack surface management controls and audits
  • Collaborate with product teams to provide first customer feedback
  • Develop automation and orchestration around attack surface management
  • Manage attack surface tool suite used for internal and external assessments
  • Develop and utilize reporting to support metrics and to drive remediation
  • Continuously adapt and improve the efficiency of attack surface management

Qualifications

Your Experience

  • 8+ years of experience in Information Security engineering or architecture role(s)
  • Prior experience with a vulnerability scanning technology (i.e. Prisma Cloud Compute (Twistlock), Tenable, Qualys, Rapid7, etc)
  • Recent hands-on experience with GCP and AWS at a minimum, nice to have Azure and other clouds
  • Strong Experience in at least one language (Python preferred) or shell scripting
  • Previous experience with DB table management and query building (SQL, Big Query, etc)
  • Previous experience with SOAR Platforms (e.g. XSOAR, XSIAM, Phantom, Swimlane, etc)
  • Previous experience with CI/CD pipeline tools and processes
  • Some experience with Linux system administration or a DevOps, Site Reliability, or infrastructure engineering role
  • Strong understanding of TCP/IP
  • Information security certifications such as SANS, CompTIA, ISC2, etc are a plus
  • Familiarity with one of of Federal-relevant programs and Governance, Risk Management and Compliance frameworks such as CDM, EIS - MITRE ATT&CK, TIC, FISMA, FedRAMP (moderate, high, IL5), DISA Cloud Computing Security Requirements Guide, NIST RMF, etc.
  • Excellent problem solving, critical thinking, communication, and teamwork skills
  • Excellent written and verbal communication, able to collaborate and rally support
  • Excellent interpersonal skills and the ability to work well in a team
  • Self-disciplined, self-managed, self-motivated and strong sense of ownership, urgency, and drive
  • Passionate to learn, understand, and dissect new technology stacks quickly

Additional Information

The Team

Serious mission, fun culture; We’re not your ordinary Information Security team. We’re a diverse group of security professionals who embrace challenging the status quo to protect Palo Alto Networks and our customers. They say it’s the people you work with that make you want to go to work, and it’s true here; we love our work. 

Think about it:  Driving innovation on the Information Security team of the fastest-growing high-tech cybersecurity

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Palo Alto Networks

View company profile →