> Markdown version of [/jobs/ext/1743203-principal-consultant-offensive-security-proactive-services-unit-42](https://www.wearedevelopers.com/jobs/ext/1743203-principal-consultant-offensive-security-proactive-services-unit-42). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Consultant, Offensive Security, Proactive Services (Unit 42) - **Company:** Palo Alto Networks - **Location:** Burbank, CA, United States - **Experience:** Expert - **Salary:** $151,000.0 - $208,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, C++ (Programming Language), Cloud Computing, Cyber Security, Computer Programming, Linux, Python (Programming Language), Windows PowerShell, Ruby, Web Applications, Scripting, Google Cloud, GWAPT, Information Technology, Metasploit, Nessus, Vulnerability Analysis - **Published:** July 1, 2026 - **Apply:** https://dejobs.org/x/x/A5DEBDA2CD3140198903ACCC411269EC/job/ ## About the Role * Bachelor's Degree in Information Security, Computer Science, or a related field, or equivalent professional experience. * 6+ years of professional experience in information security, with a focus on penetration testing and vulnerability assessments. * Expertise with security assessment tools such as Metasploit, Burp Suite Pro, Cobalt Strike, Nessus, and Bloodhound. * Proficiency in scripting or programming with languages like Python, PowerShell, Ruby, or C++. * Demonstrated experience in conducting penetration tests across various environments including Windows, Linux, and cloud platforms (AWS, GCP, Azure)., * Experience managing or mentoring junior consultants on security engagements. * Certifications such as OSCP, OSCE, GPEN, GWAPT, or GXPN. * Experience with public speaking, publishing research, or contributing to the security community. * Knowledge of computer forensic tools, technologies, and incident response methods. ## Description As a Principal Consultant on the Offensive Security team, you will be a key leader in assessing and challenging the security posture of a diverse client portfolio. You will leverage a variety of advanced tools and methodologies to act as the client's advocate for cybersecurity best practices. This role is critical in providing strong, actionable recommendations to enhance our clients' defenses against sophisticated threats ., * Conduct comprehensive penetration tests (network, web application, cloud, mobile) to identify and exploit vulnerabilities. * Develop custom scripts, tools, and methodologies to automate and enhance offensive security engagements and internal processes. * Lead client engagements, clearly articulating testing approaches and methodologies to both technical and executive audiences. * Generate detailed reports that communicate test results, identified risks, and concrete remediation recommendations to clients. * Perform cyber risk assessments using industry frameworks such as NIST CSF, ISO 27001, and CIS Top 20. * Conduct threat hunting and compromise assessment engagements to identify active or dormant indicators of compromise (IoCs) in client environments. * Proactively collaborate with internal teams and clients, exchanging information to ensure alignment and accomplish shared security objectives. * Assist in scoping new opportunities and developing internal infrastructure for offensive security research and development. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)