Sr. Staff Security Engineer, Attack Surface Management
Palo Alto NetworksAbout the role
Company Description
Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
Our Approach to Work
We lead with flexibility and choice in all of our people programs. We have disrupted the traditional view that all employees have the same needs and wants. We offer personalization and offer our employees the opportunity to choose what works best for them as often as possible - from your wellbeing support to your growth and development, and beyond!
At Palo Alto Networks, we believe in the power of collaboration and value in-person interactions. This is why our employees generally work from the office three days per week, leaving two days for choice and flexibility to work where you feel most effective. This setup fosters casual conversations, problem-solving, and trusted relationships. While details may evolve, our goal is to create an environment where innovation thrives, with office-based teams coming together three days a week to collaborate and thrive, together!
Job Description
Your Career
As a member of the Attack Surface Management team within the Information Security organization, your duties will include protecting mission-critical platforms, tools, and applications that will ensure the highest levels of security, availability and reliability of all our services and applications. You will use your creative and innovative problem solving abilities to partner with and support our IT and product teams to ensure their cloud based and data center services maintain our high security standards while supporting availability and functionality.
Your Impact
- Discover and analyze vulnerabilities for on-prem and cloud environments
- Engage with IT and product teams to remediate vulnerability findings
- Collaborate with Governance Risk Compliance (GRC) on attack surface management controls and audits
- Collaborate with product teams to provide first customer feedback
- Develop automation and orchestration around attack surface management
- Manage attack surface tool suite used for internal and external assessments
- Develop and utilize reporting to support metrics and to drive remediation
- Continuously adapt and improve the efficiency of attack surface management
Qualifications
Your Experience
- 8+ years of experience in Information Security engineering or architecture role(s)
- Prior experience with a vulnerability scanning technology (i.e. Prisma Cloud Compute (Twistlock), Tenable, Qualys, Rapid7, etc)
- Recent hands-on experience with GCP and AWS at a minimum, nice to have Azure and other clouds
- Strong Experience in at least one language (Python preferred) or shell scripting
- Previous experience with DB table management and query building (SQL, Big Query, etc)
- Previous experience with SOAR Platforms (e.g. XSOAR, XSIAM, Phantom, Swimlane, etc)
- Previous experience with CI/CD pipeline tools and processes
- Some experience with Linux system administration or a DevOps, Site Reliability, or infrastructure engineering role
- Strong understanding of TCP/IP
- Information security certifications such as SANS, CompTIA, ISC2, etc are a plus
- Familiarity with one of of Federal-relevant programs and Governance, Risk Management and Compliance frameworks such as CDM, EIS - MITRE ATT&CK, TIC, FISMA, FedRAMP (moderate, high, IL5), DISA Cloud Computing Security Requirements Guide, NIST RMF, etc.
- Excellent problem solving, critical thinking, communication, and teamwork skills
- Excellent written and verbal communication, able to collaborate and rally support
- Excellent interpersonal skills and the ability to work well in a team
- Self-disciplined, self-managed, self-motivated and strong sense of ownership, urgency, and drive
- Passionate to learn, understand, and dissect new technology stacks quickly
Additional Information
The Team
Serious mission, fun culture; We’re not your ordinary Information Security team. We’re a diverse group of security professionals who embrace challenging the status quo to protect Palo Alto Networks and our customers. They say it’s the people you work with that make you want to go to work, and it’s true here; we love our work.
Think about it: Driving innovation on the Information Security team of the fastest-growing high-tech cybersecurity
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Sr. Director, Inside Sales (R-16268)
Dun & Bradstreet
Advanced Practice Provider - Nurse Practitioner or Physician’s Assistant – CU Medicine Family Medicine - Centerfield Clinic - Sr. Instructor
University of Colorado Anschutz Medical Campus
$147,522/yr
Sr. Manager, M&A Integration Office
Nextracker