Jobs and Careers
PA

Senior Security Researcher (Xpanse)

Palo Alto Networks
San Francisco, United Statesfull_timeVerifiedPosted 30 Oct 2023
💰 $233,200/yr($144,200/yr$233,200/yr)

About the role

Company Description

Our Mission

At Palo Alto Networks® everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

Our Approach to Work

We lead with flexibility and choice in all of our people programs. We have disrupted the traditional view that all employees have the same needs and wants. We offer personalization and offer our employees the opportunity to choose what works best for them as often as possible - from your wellbeing support to your growth and development, and beyond!

At Palo Alto Networks, we believe in the power of collaboration and value in-person interactions. This is why our employees generally work from the office three days per week, leaving two days for choice and flexibility to work where you feel most effective. This setup fosters casual conversations, problem-solving, and trusted relationships. While details may evolve, our goal is to create an environment where innovation thrives, with office-based teams coming together three days a week to collaborate and thrive, together!

Job Description

Your Career

We’re looking for a Senior Security Researcher, Vulnerability Detection for Cortex Xpanse’s policy and payload generation (PPG) team. You will be responsible for the creation, validation and deployment of vulnerability signatures and protocol payloads which will be used by our scanning infrastructure to understand what vulnerabilities are exposed across customer networks. You will also be responsible for creating new policies, which encode risky device configurations as code that is run over observations from our global scanning data. You will be a key member of a team that proactively sources vulnerabilities and misconfigurations from newly discovered CVEs and responds to Xpanse customer requests.

Our mission is to find risks online and protect the world’s largest organizations from malicious software and hackers. Expanse’s Internet intelligence platform collects petabytes of Internet data, leverages artificial intelligence to discover “unknown unknown” risks for customers, and delivers those insights via a SaaS web application. On this team, you will directly contribute to our mission by defining and delivering on Expanse’s technical roadmap. 

Your Impact

  • Contribute to Xpanse’s critical vulnerability response by implementing the necessary vulnerability signatures and payloads to detect presence of critical CVEs while effectively communicating with the Xpanse team, across the Cortex business unit, and across Palo Alto Networks
  • Research trending threats and develop proof of concepts to detect presence of confirmed and inferred vulnerabilities
  • Research and develop fingerprints that can help Xpanse identify and structure more and more types of services running on the global Internet
  • Proactively add customer-requested policies and implement protocol payloads while minimizing false positives & false negatives
  • Research emerging vulnerability threats on the global Internet and contribute to Cortex Research blogs/publications
  • Mentor junior researchers and continuously improve the team’s best practices

Qualifications

Your Experience

  • Bachelor's degree in Computer Science, Data Science, Engineering, or other technical discipline (or equivalent professional experience or equivalent military experience required)
  • High level knowledge of  network security vulnerabilities, CVSS scoring and exploit techniques
  • Experience with vulnerability detection, protocol analysis and in-depth knowledge of common protocols such as TLS, HTTP, SSH, SMB, SMTP
  • Experience using network analysis tools like tcpdump, Burpsuite and Wireshark
  • Experience with open source vulnerability detection frameworks and a detailed understanding of exploit development lifecycle
  • Familiarity with one or more programming languages (Java, Python, Go, Bash)
  • Ability to concisely communicate complex subject matter to technical and non-technical audiences
  • Ability to work independently as a researcher as well as part of larger cross-functional teams
  • Prior experience performing open-ended security research and showcasing externally via blogs and publications is a plus
  • Hands-On  experience in areas of security research/systems security/network security

Additional Information

The Team

Security Research at Cortex Xpanse helps protect some of the world

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Palo Alto Networks

View company profile →