Staff Engineer (Product Security Incident Response

Palo Alto Networks
United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$151,500.0 - $245,025.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Databases Data Security Software Debugging Internet Security Reverse Engineering Software Engineering Software Security Information Technology Palo Alto Networks Vulnerability Analysis

Job description

As a Senior Staff PSIRT Engineer, you will play a critical role in protecting Palo Alto Networks products and services by leading complex vulnerability investigations. You will serve as a senior technical expert in the Product Security Incident Response Team (PSIRT), driving deep technical analysis, root cause determination, and remediation guidance. This role demands a high level of technical acumen and cross-functional collaboration to navigate sensitive situations with both internal teams and external stakeholders., * Lead the technical investigation of reported security vulnerabilities, including reproduction, impact analysis, and severity scoring (CVSS).

  • Drive root cause analysis for reported vulnerabilities and partner with product engineering teams to develop and validate remediations.
  • Proactively collaborate and ensure alignment with product, engineering, legal, privacy, and threat intelligence teams on vulnerability response strategies.
  • Engage with customers, security researchers, and industry partners to discuss vulnerability details, mitigation steps, and disclosure timelines.
  • Maintain deep familiarity with industry vulnerability handling standards and organizations such as CNA, NIST, and FIRST.
  • Contribute to the continuous improvement of PSIRT workflows, automation, and tooling to simplify and accelerate vulnerability response.
  • Mentor junior engineers in vulnerability research, triage, and incident response methodologies, empowering others to develop their skills.

Requirements

  • BS or MS Degree in Computer Science, Engineering, or Cybersecurity.
  • 4+ years of experience in product security, application security, or vulnerability research.
  • Strong expertise in reverse engineering, debugging, and secure software development practices.
  • Demonstrated ability to reproduce, analyze, and assess the exploitability of complex vulnerabilities in large-scale systems.
  • Deep familiarity with CVSS, CVE, and public vulnerability databases.

Preferred Qualifications

  • Experience handling responsible disclosure and coordinating with external researchers and industry partners.
  • Strong written and verbal communication skills, with an ability to articulate technical risk to diverse audiences.
  • Experience working in a fast-paced, collaborative environment with strict SLAs for vulnerability response., Analysis Skills, Applications Security, Artificial Intelligence (AI), Automation, Communication Skills, Computer Science, Computer Security, Continuous Improvement, Cross-Functional, Debugging Tools, Employee Benefits, High Tech Industry, Incident Response, Industry Standards, Information/Data Security (InfoSec), Internet Security, Investigative Reports, Large-Scale Systems, Leading Edge Technology, Legal, Machine Tool, Mentoring, Presentation/Verbal Skills, Problem Solving Skills, Product Engineering, Reverse Engineering, Risk, Root Cause Analysis, Service Level Agreement (SLA), Software Development, Team Player, Technical Analysis, U.S. National Institute of Standards and Technology (NIST), Writing Skills

Benefits & conditions

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

$151,500.00 - $245,025.00/yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

About the company

At Palo Alto Networks®, we’re united by a shared mission-to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all