Senior Staff Information Security Engineer – AI & Attack Surface Management
Palo Alto Networks · Santa Clara, CA · 2 days ago
On-siteInformation Technology$152k–$245k/yrFull-time
Your Impact
- Architect, design, and build next-generation AI-powered platforms and services that advance the maturity of the Attack Surface Management program.
- Design and develop AI-powered capabilities that automate security investigations, identify root causes, recommend remediation actions, and enable engineers and analysts to quickly understand security exposures, business impact, and remediation guidance.
- Build scalable automation and orchestration frameworks that streamline security operations, improve analyst productivity, and accelerate remediation at enterprise scale
- Leverage AI, automation, and enterprise security data to continuously improve the accuracy, efficiency, and scalability of Attack Surface Management capabilities.
Security Automation
- Design and develop automation frameworks that eliminate repetitive security operations.
- Build intelligent workflows that automatically enrich, correlate, prioritize, and triage security findings.
- Develop scalable orchestration services integrating security platforms, cloud providers, CMDBs, ticketing systems, and engineering workflows.
- Improve analyst efficiency through automation, self-service tooling, and AI-assisted decision making.
Auto Remediation
- Design and implement automated remediation playbooks capable of immediately mitigating critical security exposures.
- Build policy-driven remediation capabilities for cloud infrastructure, endpoints, Kubernetes, networking, and enterprise systems.
- Integrate with Infrastructure-as-Code, CI/CD pipelines, cloud APIs, and security orchestration platforms to enable autonomous remediation where appropriate.
Security Platform Engineering
- Build scalable services that ingest, correlate, enrich, and normalize security telemetry from cloud, infrastructure, vulnerability scanners, asset inventories, identity platforms, and threat intelligence.
- Develop APIs and reusable platform services supporting enterprise-scale Attack Surface Management.
- Design distributed systems capable of processing millions of security findings.
Cross-Functional Engineering
- Partner with Cloud Engineering, Infrastructure, Product Security, IT, and Platform Engineering teams to build integrated security capabilities.
- Translate complex security challenges into scalable software solutions that improve operational efficiency and security outcomes.
- Drive engineering excellence through software design best practices, automation, testing, observability, and operational reliability.
Qualifications
- 8+ years of experience in software engineering, security engineering, platform engineering, or infrastructure engineering, with a track record of building enterprise-scale security platforms, automation frameworks, AI-powered solutions, or cloud-native applications.
- Strong software development experience with Python, Go, Java, or similar languages, building production-grade systems designed for scalability, reliability, and maintainability.
- Experience designing APIs, micro services, distributed systems, event-driven architectures, data services, and cloud-native applications.
- Hands-on experience building AI-powered applications and intelligent automation that streamline complex workflows, improve decision-making, and reduce manual operational effort.
- Deep understanding of enterprise security and infrastructure, including Attack Surface Management, Exposure Management, cloud security, networking, identity, vulnerability management, and security operations.
- Experience designing and securing large-scale cloud and hybrid environments across AWS, Azure, or GCP, including Kubernetes, containers, Linux and Windows infrastructure, Infrastructure-as-Code, and CI/CD pipelines.
- Experience integrating security platforms with cloud providers, asset inventories, CMDBs, ticketing systems, and engineering tools to deliver scalable, data-driven security capabilities.
- Demonstrated ability to lead complex technical initiatives, influence architecture across organizations, mentor engineers, and communicate effectively with engineers, security practitioners, and executive leaders.
- Passion for applying emerging technologies to improve security outcomes, engineering efficiency, and the maturity of Attack Surface Management capabilities.
Preferred Qualifications
- Experience building AI-powered applications, intelligent automation platforms, or enterprise security products.
- Familiarity with modern AI technologies, cloud-native architectures, distributed systems, platform engineering, Infrastructure-as-Code, CI/CD, and workflow orchestration.
- Knowledge of enterprise security platforms such as Cortex XSIAM, Cortex ASM/Xpanse, Tenable, Nexpose or similar technologies is a plus.
- Experience supporting regulated cloud environments and security compliance frameworks such as FedRAMP, NIST, PCI, MLPS, and UK Cyber Essentials is highly desirable.
- Relevant certifications such as CISSP, AWS Certified Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent are preferred but not required.
Pay
$151,500.00 - $245,025.00/yr