Principal Product Security Engineer
Santa Clara, CA, United States
Applications have closed
Palo Alto Networks
Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud...Company Description
Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
We have the vision of a world where each day is safer and more secure than the one before. These aren’t easy goals to accomplish – but we’re not here for easy. We’re here for better. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
We’re changing the nature of work. Palo Alto Networks is evolving to meet the needs of our employees now and in the future through FLEXWORK, our approach to how we work. From benefits to learning, location to leadership, we’ve rethought and recreated every aspect of the employee experience at Palo Alto Networks. And because it FLEXes around each individual employee based on their individual choices, employees are empowered to push boundaries and help us all evolve, together.
Job Description
Your Career
Palo Alto Networks is disrupting the Cyber Security industry! We are looking for a Principal Product Security Engineer to join our Product Security team, which works with all Palo Alto Networks product engineering teams to provide assistance and guidance on how to secure our products. With your security skills, help identify and report security issues via SAST. You’ll also collaborate with other team members to drive remediation of security issues, and drive continuous improvement of results. In this role you will provide technology leadership in development of security programs by helping to drive disruptive vision, technology planning and estimation. If you are a fast learner and passionate about Cyber Security, this is a great opportunity for you.
Your Impact
- Static Application Security Testing
- Take ownership of the SAST offering to product development teams
- Work with security engineers and product development teams to provide accurate, actionable results
- Build next gen appsec technologies with automation into complex engineering CI/CD pipelines
- Build risk driven intelligent automation to optimize SAST, SCA, CVA, and DAST integrations with advanced tooling integration
- Products/Tools Design & Development
- Design and implement consumable software and services for internal and external customers - Ensure on-schedule delivery of a high-quality product that meets technical requirements
- Solutions design for new services (in partnership with Architecture and SRE)
- Build vs Buy Research and Evaluation
- Take ownership and/or lead the engineering responsibility for multiple components in a project
- Consulting & Support
- Evangelize and lead the adoption of Secure SDLC and security best practices across the entire SDLC - You’re someone that possesses strong knowledge of security from code to cloud and wants to help people apply it
- Implement programs to automate complex data analysis for high priority security missions
- Build tools/reports to support urgent requests
- Evaluate options and provide recommendations on scope and scale of effort required to develop solutions
- This includes creating reference implementations and reusable templates that are used to make our products secure by default
- Clearly communicate on the status of projects or other issues - Establish a working relationship with other groups across the organization to successfully implement business requirements while applying the latest available tools and technology
Qualifications
Your Experience
- Experience explaining impact of identified security issues to technical and non-technical audiences
- Experience guiding remediation of security issues with software engineers
- Experience tuning and creating SAST queries based on identified vulnerabilities
- Experience triaging SAST issues to determine validity and impact
- Knowledge of SCA/CVA security tooling is a plus
- 8+ years hands-on experience in cybersecurity in general
- 5+ years of experience with hands on keyboard application security, pen testing, security benchmarks, and automation
- 3+ years experience with REST APIs, Automation, Integration using Python, Go or Java/C++
- 3+ years of software engineering full stack experience desired
- Ability to quickly solve problems through automation
- Experience in software security testing, methodologies, and frameworks
- Experience with GCP or AWS
- Experienced in variety of cloud and database technologies - Google BigQuery, GCS Postgres, Mysql, ElasticSearch
- Experience with Kubernetes and Docker
- Experience in designing, building and maintaining scalable cloud infrastructure and applications
- Working knowledge of and experience with CI/CD tools - Jenkins, Bamboo, Gitlab is a plus
- Basic knowledge of system administration with Windows and Linux is a plus
- Experience with Infrastructure As Code(IaC), Terraform, Ansible, Cloud Formation, Chef is a plus
- "Self-starter" attitude and ability to troubleshoot independently
- Effective written and oral communication with multiple levels of leadership involving both the business and technical sides of the business
- BS/MS in Computer Science or related area or equivalent experience or equivalent military experience required
Additional Information
The Team
Think about it, security for an information security company. Working at a high-tech cybersecurity company within the Information Security team is a once in a lifetime opportunity. You’ll be joined with the brightest minds in technology, our global teams on the front line of defense against cyberattacks. We’re joined by one mission – but driven by the impact of that mission and what it means to protect our way of life in the digital age. Join a dynamic and fast-paced team that feels excitement at the prospect of a challenge and feels a thrill at resolving security gaps that inhibit our privacy.
Our Commitment
We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.
We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at accommodations@paloaltonetworks.com.
Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.
All your information will be kept confidential according to EEO guidelines.
#LI-MR1
Covid-19 Vaccination Information for Palo Alto Networks Jobs
- Vaccine requirements and disclosure obligations vary by country.
- Unless applicable law requires otherwise, you must be vaccinated for COVID or qualify for a reasonable accommodation if:
- The job requires accessing a company worksite
- The job requires in-person customer contact and the customer has implemented such requirements
- You choose to access a Palo Alto Networks worksite
- If you have questions about the vaccine requirements of this particular position based on your location or job requirements, please inquire with the recruiter.
Tags: Ansible APIs Application security Automation AWS C CI/CD Cloud Computer Science DAST Docker Elasticsearch Full stack GCP Java Kubernetes Linux MySQL Pentesting PostgreSQL Privacy Product security Python SAST SDLC Terraform Vulnerabilities Windows
Perks/benefits: Career development Medical leave
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Cyber Security Specialist jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Information Security Engineer jobs
- Open Consultant SOC / CERT H/F jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Specialist jobs
- Open Security Specialist jobs
- Open Security Researcher jobs
- Open Chief Information Security Officer jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open IT Security Engineer jobs
- Open Agile-related jobs
- Open ISO 27001-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open CISM-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open CISA-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open Security Clearance-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open IDS-related jobs
- Open APIs-related jobs
- Open CEH-related jobs
- Open CI/CD-related jobs