Sr Staff Product Security Researcher

Santa Clara, CA, United States

Applications have closed

Palo Alto Networks

Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud...

View company page

Company Description

Our Mission

At Palo Alto Networks® everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

FLEXWORK is an employee-centric reimagining of how we work. We built FLEXWORK based on employee feedback – it is about flexibility, trust, and choice whenever possible. It’s been a journey of disruption that has yielded the best of our values. We offer as much flexibility as possible, and choices that enable you to be most productive, including benefits that meet your needs and learning opportunities that you feel passionate about.

Our Approach to Work

At Palo Alto Networks, we believe in the power of collaboration and value in-person interactions. This is why our employees generally work from the office three days per week, leaving two days for choice and flexibility to work where you feel most effective. This setup fosters casual conversations, problem-solving, and trusted relationships. While details may evolve, our goal is to create an environment where innovation thrives, with office-based teams coming together three days a week to collaborate and thrive, together!

Job Description

Your Career 

These days, the threat landscape is fluid and always changing. Cyber bad-actors are constantly finding new and diabolically creative ways to get to your data and there’s just no telling what door they’ll knock on next. As a Sr. Staff Product Security Researcher, you will be helping Palo Alto Networks in a high visibility role to stay ahead of the curve in addressing these latest threats, overseeing vulnerability response and remediation across all of Palo Alto Networks offerings. As part of the Palo Alto Networks Product Security Assurance team, the highly visible Sr. Staff Product Security Research & Vulnerability Engineer was created to address these latest threats, overseeing vulnerability response and remediation across all of Palo Alto Networks offerings.

Your Impact 

  • Research security vulnerabilities identified in our products or cloud offerings
  • Work with exceptional security professionals from across the company as well as across the industry
  • Ensure appropriate vulnerability remediation: developing and reviewing   solutions
  • Collaborate with stakeholders across the company and beyond including   executives, engineering, infosec, privacy, legal, support, sales, customers,   security researchers, and industry partners
  • Work with a growth mindset and learn about the latest trends in cybersecurity


Your Experience 

  • Familiarity with secure programming concepts
  • Familiarity with Linux, Operating System Concepts, Networking, Cloud   computing
  • Good understanding of web/application security threats and defenses (code   injection, XSS, etc.,)
  • Familiarity with OWASP guidelines - Participation in Capture the Flag (CTF)   events, local OWASP chapter, or similar security-focused communities is a plus
  • Familiarity with agile software development/continuous integration/automation
  • Excellent written and verbal communication skills
  • An existing public blog entry on a technical issue, comment on a mailing list or   open-source issue, or other technical comments on social media
  • Strong analytical and problem-solving skills, ability to work independently
  • Ability to collaborate across functional teams as well as external partners, security researchers, and other security teams
  • Demonstrated experience (such as academic projects) in Javascript, NodeJS, Java, C
  • Relational and NoSQL databases - Ability to read and understand multiple programming languages
  • Experience in a red/blue/purple team would be a plus


  • Bachelor's degree from four-year college or university or equivalent training, education, and experience in information / cyber security, computer systems, IT, etc. or equivalent military experience required

Additional Information

The Team

Serious mission, fun culture; We’re not your ordinary Information Security team.  We’re a diverse group of security professionals that embraces challenging the status quo in order to protect Palo Alto Networks and our customers.  They say it’s the people you work with that make you want to go to work and it’s true here; we love our work. 

Think about it:  Driving innovation on the Information Security team of the fastest-growing high-tech cybersecurity company is a once in a lifetime opportunity. You’ll be joined by the brightest minds in technology, and our global teams are on the front line of defense against cyberattacks. 

We’re joined by one mission – but driven by the impact of that mission and what it means to protect our way of life in the digital age. Join a dynamic and fast-paced team that feels excitement at the prospect of a challenge and feels a thrill every time we beat the bad guys.

We hope to meet you soon!

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $145,500/yr to $235,400/yr. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.


Tags: Agile Application security Automation C Cloud CTF Java JavaScript Linux Node.js NoSQL OWASP Privacy Product security Vulnerabilities XSS

Perks/benefits: Career development Flex vacation Medical leave Salary bonus Startup environment Team events

Region: North America
Country: United States
Job stats:  17  3  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.