Staff GRC Engineer (Information Security)

Santa Clara, CA, United States

Palo Alto Networks

Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’s, Head of Infrastructure, Network Security Engineers, Cloud...

View company page

Company Description

Our Mission

At Palo Alto Networks® everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

Our Approach to Work

We lead with flexibility and choice in all of our people programs. We have disrupted the traditional view that all employees have the same needs and wants. We offer personalization and offer our employees the opportunity to choose what works best for them as often as possible - from your wellbeing support to your growth and development, and beyond!

At Palo Alto Networks, we believe in the power of collaboration and value in-person interactions. This is why our employees generally work from the office three days per week, leaving two days for choice and flexibility to work where you feel most effective. This setup fosters casual conversations, problem-solving, and trusted relationships. While details may evolve, our goal is to create an environment where innovation thrives, with office-based teams coming together three days a week to collaborate and thrive, together!

Job Description

Your Career 

We support Palo Alto Networks in improving security posture, enabling sales of our products, and meeting our compliance obligations. We are seeking an Information Security Governance, Risk & Compliance Engineer to join our Information Security Governance, Risk, and Compliance team and partner with Palo Alto Networks business groups to assess and improve our global information security posture. In this role, you will work directly with key stakeholders and leaders across the organization to identify, mitigate and monitor security risks. This role will indirectly support Palo Alto Networks Enterprise Risk Management (ERM) and Internal Audit (IA) initiatives. 

Your Impact  

  • Analyze technical risks of existing network / system and application architectures (IAAS/PAAS/SAAS and on premise) against correlating policies and risks, and provides appropriate remediation or risk reduction plans
  • Evaluate ongoing  practices and procedures, technical documentation, and diagrams for appropriate security measure maturity and effectiveness
  • Generates and monitors effective and actionable Information Security reporting across the InfoSec technical landscape and provides pertinent input to briefing presentations


Your Experience 

  • 5+ years of combined experience as an software engineer, infrastructure engineer, network engineer or cloud security engineer 
  • In-depth understanding of technical risk management practices, including risk identification, assessment, mitigation, and monitoring.
  • Data analysis and reporting  skills for assessing, interpreting and reporting  risk data
  • Proficiency in programming languages such as Python, Java, or Ruby to develop automation scripts and tools for monitoring controls effectively
  • Strong knowledge of scripting languages (e.g., Bash, PowerShell) for  automation tasks.
  • Competence in working with version control systems like Git
  • Understanding of DevOps practices and principles
  • Understanding of cloud platforms (e.g., AWS, Azure, Google Cloud) and infrastructure as code (IaC) concepts
  • Knowledge of industry-specific regulations and compliance standards (e.g., ISO 27001, NIST, GDPR)
  • Familiarity with security frameworks (e.g., CIS, OWASP) and best practices
  • Experience in security engineering related to vulnerability management, intrusion prevention, data protection, monitoring, analytical and correlation tools a PLUS
  • Certification in any of the following is a plus - OSCP; OSCE; PCNSE, Google Cloud Architect, AWS Cloud Architect, CISSP-ISSEP - Sec. Eng. Professional, GIAC Certified Enterprise Defender (GCED), CCSP, Splunk Cert. Enterprise Security Administrator
  • Education
  • Bachelor's degree from four-year college or university or equivalent training, education, and experience in information / cyber security, computer systems, IT, etc or equivalent military experience required
  • Master’s degree is a plus in any relevant domain (Engineering / IT / Computer science)

Additional Information

The Team

Think about it, security for an information security company. Working at a high-tech cybersecurity company within the Information Security team is a once in a lifetime opportunity. You’ll be joined with the brightest minds in technology, our global teams on the front line of defense against cyberattacks. We’re joined by one mission – but driven by the impact of that mission and what it means to protect our way of life in the digital age. Join a dynamic and fast-paced team that feels excitement at the prospect of a challenge and feels a thrill at resolving security gaps that inhibit our privacy.

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $119,000/yr to $192,500/yr. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.


Is role eligible for Immigration Sponsorship?: Yes

Apply now Apply later
  • Share this job via
  • or

Tags: Automation AWS Azure Bash CCSP CERT CISSP Cloud Compliance Computer Science DevOps GCED GCP GDPR GIAC Governance IaaS Intrusion prevention ISO 27001 Java Monitoring NIST OSCE OSCP OWASP PaaS PowerShell Privacy Python Risk management Ruby SaaS Scripting Splunk Vulnerability management

Perks/benefits: Career development Medical leave Salary bonus Startup environment

Region: North America
Country: United States
Job stats:  5  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.