Jobs · Information Technology · California

Senior Staff Information Security Engineer – AI & Attack Surface Management

Palo Alto Networks · Santa Clara, CA · 2 days ago
On-siteInformation Technology$152k–$245k/yrFull-time

Your Impact

  • Architect, design, and build next-generation AI-powered platforms and services that advance the maturity of the Attack Surface Management program.
  • Design and develop AI-powered capabilities that automate security investigations, identify root causes, recommend remediation actions, and enable engineers and analysts to quickly understand security exposures, business impact, and remediation guidance.
  • Build scalable automation and orchestration frameworks that streamline security operations, improve analyst productivity, and accelerate remediation at enterprise scale
  • Leverage AI, automation, and enterprise security data to continuously improve the accuracy, efficiency, and scalability of Attack Surface Management capabilities.

Security Automation

  • Design and develop automation frameworks that eliminate repetitive security operations.
  • Build intelligent workflows that automatically enrich, correlate, prioritize, and triage security findings.
  • Develop scalable orchestration services integrating security platforms, cloud providers, CMDBs, ticketing systems, and engineering workflows.
  • Improve analyst efficiency through automation, self-service tooling, and AI-assisted decision making.

Auto Remediation

  • Design and implement automated remediation playbooks capable of immediately mitigating critical security exposures.
  • Build policy-driven remediation capabilities for cloud infrastructure, endpoints, Kubernetes, networking, and enterprise systems.
  • Integrate with Infrastructure-as-Code, CI/CD pipelines, cloud APIs, and security orchestration platforms to enable autonomous remediation where appropriate.

Security Platform Engineering

  • Build scalable services that ingest, correlate, enrich, and normalize security telemetry from cloud, infrastructure, vulnerability scanners, asset inventories, identity platforms, and threat intelligence.
  • Develop APIs and reusable platform services supporting enterprise-scale Attack Surface Management.
  • Design distributed systems capable of processing millions of security findings.

Cross-Functional Engineering

  • Partner with Cloud Engineering, Infrastructure, Product Security, IT, and Platform Engineering teams to build integrated security capabilities.
  • Translate complex security challenges into scalable software solutions that improve operational efficiency and security outcomes.
  • Drive engineering excellence through software design best practices, automation, testing, observability, and operational reliability.

Qualifications

  • 8+ years of experience in software engineering, security engineering, platform engineering, or infrastructure engineering, with a track record of building enterprise-scale security platforms, automation frameworks, AI-powered solutions, or cloud-native applications.
  • Strong software development experience with Python, Go, Java, or similar languages, building production-grade systems designed for scalability, reliability, and maintainability.
  • Experience designing APIs, micro services, distributed systems, event-driven architectures, data services, and cloud-native applications.
  • Hands-on experience building AI-powered applications and intelligent automation that streamline complex workflows, improve decision-making, and reduce manual operational effort.
  • Deep understanding of enterprise security and infrastructure, including Attack Surface Management, Exposure Management, cloud security, networking, identity, vulnerability management, and security operations.
  • Experience designing and securing large-scale cloud and hybrid environments across AWS, Azure, or GCP, including Kubernetes, containers, Linux and Windows infrastructure, Infrastructure-as-Code, and CI/CD pipelines.
  • Experience integrating security platforms with cloud providers, asset inventories, CMDBs, ticketing systems, and engineering tools to deliver scalable, data-driven security capabilities.
  • Demonstrated ability to lead complex technical initiatives, influence architecture across organizations, mentor engineers, and communicate effectively with engineers, security practitioners, and executive leaders.
  • Passion for applying emerging technologies to improve security outcomes, engineering efficiency, and the maturity of Attack Surface Management capabilities.

Preferred Qualifications

  • Experience building AI-powered applications, intelligent automation platforms, or enterprise security products.
  • Familiarity with modern AI technologies, cloud-native architectures, distributed systems, platform engineering, Infrastructure-as-Code, CI/CD, and workflow orchestration.
  • Knowledge of enterprise security platforms such as Cortex XSIAM, Cortex ASM/Xpanse, Tenable, Nexpose or similar technologies is a plus.
  • Experience supporting regulated cloud environments and security compliance frameworks such as FedRAMP, NIST, PCI, MLPS, and UK Cyber Essentials is highly desirable.
  • Relevant certifications such as CISSP, AWS Certified Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent are preferred but not required.

Pay

$151,500.00 - $245,025.00/yr

Similar jobs