> Markdown version of [/jobs/ext/2718258-sr-principal-engineer-software-security-detections](https://www.wearedevelopers.com/jobs/ext/2718258-sr-principal-engineer-software-security-detections). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Principal Engineer Software - Security & Detections - **Company:** Palo Alto Networks - **Location:** Santa Clara, CA, United States - **Experience:** Expert - **Salary:** $183,600.0 - $297,000.0 - **Contract:** Permanent contract - **Skills:** Automation of Tests, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Packet Analyzer, Regular Expressions, Regression Testing, Snort (Software), Mitre Att&ck, Deep Learning, Information Technology - **Published:** September 4, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3377291865&tx=JJ4135FFP&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * BS/MS in Computer Science, Cyber Security, or equivalent practical experience. * 4+ years of dedicated experience in detection engineering, threat analysis, or security research. * Deep expertise in writing and optimizing signature-based patterns (e.g., custom Snort/Suricata rules, Yara, PAN-OS custom threat signatures). * Thorough understanding of application-layer evasion techniques. * Strong knowledge of the detection-as-code philosophy and building automated testing pipelines for signature validation. * Experience with Python, Regex, or other scripting tools to automate packet capture analysis, rule creation, and parsing threat telemetry. * Solid understanding of the MITRE ATT&CK framework and translating offensive techniques into robust defensive controls. The Team We believe collaboration thrives in person. That's why most of our teams work from the office full time (3 days a week at our Santa Clara headquarters), with flexibility when it's needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes. ## Description As a Security / Detection Engineer, you will analyze multi-stage attack behavior sequences and translate complex threat patterns into highly deterministic signatures. You will own the end-to-end detection lifecycle-from rule creation to continuous false-positive (FP) tuning-ensuring our defense mechanisms are performant, accurate, and resilient against evasion. Your Impact * Analyze complex, multi-stage attack behavior sequences and transform them into precise, deterministic signatures. * Develop and maintain high-performance, signatures that can be safely enforced by our inline engines without impacting network throughput. * Own the entire signature lifecycle, from initial research and threat modeling to deployment, automated regression testing, and deprecation. * Drive continuous False Positive (FP) tuning and validation processes to minimize alert fatigue while maximizing true positive detection rates. * Implement robust version pinning strategies and dependency management for threat prevention content updates, ensuring consistency across distributed firewall deployments. * Partner with threat research groups and inline machine learning teams to integrate behavioral signatures with automated deep learning classifiers. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Getting Started with Machine Learning](https://www.wearedevelopers.com/videos/260-getting-started-with-machine-learning) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Geometric deep learning for drug discovery](https://www.wearedevelopers.com/videos/264-geometric-deep-learning-for-drug-discovery) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)