Sr Cloud Infrastructure Security Engineer (Devops)

Palo Alto Networks
Santa Clara, CA, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Application Frameworks Computing Platforms Automation of Tests Big Data Burp Suite Cloud Computing Cloud Computing Security Cyber Security Data Centers Linux
+18 more
DevOps Distributed Systems Networking Hardware Python (Programming Language) Software Tools Ansible Software Vulnerability Management Web Applications Saltstack Kubernetes Iptables Palo Alto Networks Bare Metal Data Analytics Malware Detection Nexpose Qualys Docker

Job description

We are reshaping the cybersecurity market through our cloud-delivered security services, and our cloud infrastructure is quickly and massively growing with a global footprint. We’re looking for great SREs, as well as software engineers interested in production engineering, to help us scale the largest enterprise security cloud infrastructure in the world., Palo Alto Networks reinvented the enterprise firewall, growing from a start-up to a multi-billion-dollar company. Our Application Framework, the latest offering in our cloud-delivered security services, ingests security events from hundreds of thousands of firewalls deployed across the globe to provide a massive data analytics platform for deep inspection, anomaly detection, and actionable security automation. Our cloud infrastructure is home to a series of massive and complicated distributed systems and virtualization software platforms which enable big data processing around security services, sandboxing and malware detection, URL categorization and malicious site/domain identification, and security research/response., + Working with teams to work through, and contribute to, our security roadmap - from a reference architecture and design to implementation

  • Working with system/platform SREs and application SREs to make sure security is properly implemented and monitored
  • Write automation code and leverage tools for large-scale vulnerability management, security rule enforcement, auditing, reporting
  • Interface with InfoSec team on planning and implementing security-focused projects, participate in incident response
  • Incorporate hardening best practices in our core automation and builds in bare metal implementations, Kubernetes-managed compute clusters, and public cloud
  • Work with application SREs and application developers to incorporate security in different layers of application and infrastructure Learn more about Palo Alto Networks here and check out our fast facts #LI-MB1

Requirements

  • Deep knowledge of Linux and the networking stack, with hands-on experience in large infrastructure security in data centers and public cloud
  • Experience with security at the host level including iptables and rule automation, as well as network-level east-west and north-south security best practices.
  • Experience in creating automated frameworks for vulnerability management such as automated OS/kernel patching including kernel patching, Java upgrades, Python upgrades, and Docker security at large scale
  • Experience and knowledge of working with security tool APIs such as Nexpose, Tenable, etc.
  • Experience and knowledge of various security compliance standards such as PCI, FedRAMP, SOC2 controls, as well as auditing and reporting
  • Knowledge and understanding of WAS application tools such as Qualys/Burp suite and building tools as necessary to facilitate web application remediation
  • Experience in automated provisioning of network devices (ie Arista switches with Ansible or Saltstack or building Python tools to interface with network devices)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all