Jobs · Information Technology · California

Principal Offensive Security Engineer

Palo Alto Networks · Santa Clara, CA · 1 mo ago
On-siteInformation Technology$168k–$271k/yrFull-time

About Us

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have.

We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

About the Role

The Offensive Security team is seeking a Principal Offensive Security Engineer to support the team responsible for testing the security of all the products and services that make up the Palo Alto Networks portfolio. This role involves choreographing a routine of on-demand and continuous penetration testing engagements with multiple, trusted third-party partners, supplemented by in-house penetration testing and red team operations to ensure comprehensive coverage across the attack surface.

Responsibilities

  • Conduct comprehensive penetration tests across a diverse portfolio of cloud-native applications, large-scale infrastructure, and complex network architectures, covering all FedRAMP-mandated attack vectors.
  • Execute multi-tenant isolation testing and segmentation validation.
  • Identify, exploit, and document vulnerabilities in cloud services, container orchestration platforms, and automated deployment pipelines.
  • Plan and lead assumed-breach, objective-based red team operations against systems—including lateral movement, privilege escalation, and persistence—to test the effectiveness of defensive controls, monitoring, and alerting systems.
  • Provide expert-level security guidance to SRE and Engineering teams during remediation planning and secure architectural design.
  • Lead the security assessment of internal tooling, identity management systems, and third-party integrations.
  • Research and develop custom tooling or scripts to automate testing and improve the efficiency of offensive engagements.
  • Translate complex technical findings into high-impact reports and presentations for both technical stakeholders and executive leadership.
  • Mentor junior team members and act as a subject matter expert on emerging threats and exploitation trends.

Qualifications

  • 8+ years of professional experience in Offensive Security, Red Teaming, or Penetration Testing.
  • Deep technical mastery of at least one major cloud provider (GCP, AWS, or Azure), including identity management and network security controls.
  • Experience with multi-tenant SaaS/PaaS isolation testing and authorization-boundary segmentation validation.
  • Proven expertise in Kubernetes and Container Security, with the ability to identify flaws in orchestration and runtime environments.
  • Strong experience auditing Infrastructure as Code (IaC) and CI/CD pipelines for security misconfigurations.
  • Hands-on experience leading pentesting, assumed-breach operations: post-exploitation, lateral movement, Active Directory and cloud IdP attack paths, C2 infrastructure, and EDR/XDR evasion.
  • Solid understanding of networking protocols, authentication frameworks (LDAP/AD, OAuth, SAML), and modern application security.
  • Experience operating within high-compliance or highly regulated environments (e.g., FedRAMP, IL5, SOC2).
  • Working knowledge of MITRE ATT&CK for operation planning and reporting.
  • Ability to think creatively and work independently to solve complex security problems in a fast-paced environment.
  • Strong written and verbal communication skills, with the ability to influence security outcomes across different business units.

Pay

The starting base salary for this position is expected to be in the range of $167,600.00 - $271,150.00 per year, depending on qualifications, experience, and work location. The offered compensation may also include restricted stock units and a bonus.

Benefits

A description of our employee benefits may be found here.

Similar jobs