Principal Security Researcher (Xpanse)

Palo Alto Networks, Inc.

Santa Clara (CA)

On-site

USD 162,700 - 263,175

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Palo Alto Networks, Inc. is seeking a skilled professional for the Vulnerability Assessment Research team within the Cortex platform. This position involves conducting cutting-edge research into vulnerabilities, creating robust tests, and building necessary tooling. You will shape the future of cybersecurity while ensuring quick response to critical vulnerabilities.

A strong background in vulnerability management and familiarity with various security tools is essential. The role offers a competitive salary between $162,700.00 and $263,175.00 annually, reflecting the importance and expertise required for this position.

Qualifications

  • 5+ years of experience in vulnerability management, offensive security, or security research.
  • Experience contributing to public vulnerability research and submitting CVEs.
  • Strong understanding of TCP/IP and networking protocols like HTTP and FTP.
  • Proficient in Python; familiarity with Java, Golang, C/C++ or RUST is a plus.
  • Cybersecurity knowledge demonstrated with base level certifications or willingness to obtain.

Responsibilities

  • Develop and maintain a repository of vulnerability content.
  • Shape tactical responses to zero-day and critical vulnerabilities.
  • Conduct research, enhance automation processes, and ensure smooth workflows.
  • Collaborate with teams to drive best practices and technological advancements.
  • Mentor other researchers and ensure high-quality output.

Skills

Vulnerability Management
Offensive Security
Security Research
TCP/IP and Networking Protocols
Common Open Source Security Software
Cybersecurity Frameworks
Penetration Testing Tools
Programming in Python
Windows/Linux/macOS/Unix Systems

Education

Cybersecurity Certifications (e.g., OSCP, GPEN, Pentest+)

Tools

Metasploit
Nmap
Burp Suite
Wireshark

Job description

Job Summary

Cortex Platform – Cortex is the industry's only open and integrated, AI‑based, continuous security platform. Cortex is a significant evolution of the Application Framework designed to simplify security operations and considerably improve outcomes. Deployed on a global, scalable public cloud platform, Cortex allows security operations teams to speed the analysis of massive data sets.

Join the elite Vulnerability Assessment Research team within Cortex Exposure Management and be at the forefront of cybersecurity! You’ll be instrumental in groundbreaking research into vulnerabilities and exposures, engineering cutting‑edge exploits and robust vulnerability tests, and building and maintaining the essential, high‑impact tooling that powers our team. This is your chance to directly shape the future of exposure management. This capability serves as the cyber knowledge backbone of the exposure management product, and is crucial for customers to prioritize and fix critical vulnerabilities using the XSIAM platform.

Key Responsibilities
  • Develop and maintain a comprehensive, industry‑leading repository of vulnerability content to enhance detection and mitigation strategies.
  • Shape and drive the tactical response to zero‑day and critical vulnerabilities across all attack surfaces, ensuring rapid containment and mitigation.
  • Conduct research and testing, enhance automation processes, and ensure a smooth workflow for identifying, validating and mitigating security risks.
  • Analyze existing solutions, identify barriers to quality, recommend changes, then implement.
  • Take part in architecture strategy sessions; design solutions that accommodate the requirements of the various groups across Cortex.
  • Collaborate with teams to solve problems, reduce technical debt, and evolve development practices. Drive technical best practices and evangelize new technologies within the engineering organization.
  • Mentor other researchers and ensure that your team delivers high‑quality output.
  • Take ownership of projects, drive them to completion, and support them in production.
Qualifications
Required Qualifications
  • 5+ years of experience in vulnerability management, offensive security or security research.
  • Experience contributing to public vulnerability research, submitting CVEs or creating proof‑of‑concept exploits.
  • Strong understanding of TCP/IP and networking protocols (e.g., HTTP, FTP, SSH, SNMP).
  • Familiarity with common open source security software such as Nuclei, OpenVAS, and Nmap.
  • Knowledge of cybersecurity frameworks and vulnerability methodologies.
  • Familiarity with current penetration and security assessment tools such as Metasploit, Nmap, Burp Suite, Wireshark, etc.
  • Proficient in Python. Familiar with, or eager to learn Java, Golang, C/C++ or RUST.
  • Deep understanding of Windows, Linux, macOS and Unix‑based systems.
  • Able to switch between research, design, prototype, and implementation.
  • Cybersecurity knowledge demonstrated with base level certifications (e.g., OSCP, GPEN, or Pentest+) or willingness to obtain.
Preferred Qualifications
  • Familiarity with patch management processes and tools (e.g., WSUS or SCCM) knowing how vulnerabilities are remediated.
  • Familiarity with enterprise/cloud deployed embedded systems.
  • Experience using cloud managed services (ideally in GCP).
  • Knowledge of network architectures; understands subnetting and routing and how VLANs work and affect network scanning.
  • Are familiar with distributed data stores, such as BigQuery and BigTable, as well as relational databases such as PostgreSQL and MySQL.
  • Experience working in security operations centers (SOC), red/blue teams or as a security analyst.
Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non‑sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus.

$162,700.00 - $263,175.00/yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

Accommodations

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at accommodations@paloaltonetworks.com.

Equal Opportunity Employer

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

EEO Statement

All your information will be kept confidential according to EEO guidelines.

Immigration Sponsorship

Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Researcher (Xpanse)
Principal Security Researcher (Xpanse)

Palo Alto Networks • California (MO)

On-site
USD 163,000 - 263,000
Principal Security Researcher (Xpanse)
Principal Security Researcher (Xpanse)

Jobs Paloaltonetworks • United States

On-site
USD 163,000 - 263,000
Sr. Staff Engineer (Cortex Vulnerability Experience Platform)
Sr. Staff Engineer (Cortex Vulnerability Experience Platform)

Palo Alto Networks • United States

On-site
USD 126,000 - 205,000
Sr. Staff Engineer (Cortex Vulnerability Experience Platform)
Sr. Staff Engineer (Cortex Vulnerability Experience Platform)

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 147,000 - 237,500
Principal Software Engineer (Cortex Xpanse)
Principal Software Engineer (Cortex Xpanse)

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 147,000 - 238,000
Senior Security Researcher
Senior Security Researcher

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 139,000 - 226,000
Principal Security Researcher (AI-Assisted Vulnerability Research)
Principal Security Researcher (AI-Assisted Vulnerability Research)

Palo Alto Networks • Santa Clara (CA)

On-site
USD 162,700 - 263,175
Restricted stock units
Bonuses
Comprehensive health benefits
Senior Software Engineer (Xpanse)
Senior Software Engineer (Xpanse)

Palo Alto Networks • Santa Clara (CA)

Hybrid
USD 180,000 - 260,000
Principal Security Researcher (AI-Assisted Vulnerability Research)
Principal Security Researcher (AI-Assisted Vulnerability Research)

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 162,000 - 264,000
Sr. Staff Security Researcher
Sr. Staff Security Researcher

Palo Alto Networks • San Jose (CA)

On-site
USD 139,000 - 226,000