Palo Alto Networks-posted 5 months ago
$157,000 - $255,000/Yr
Full-time • Senior
Santa Clara, CA
5,001-10,000 employees

As a Principal Security Researcher at Palo Alto Networks, you will be part of the team that builds and delivers the threat detection capabilities powering our Advanced Threat Prevention (ATP). You will play a key leadership role in shaping detection methodologies and driving multiple projects in parallel. This position offers a unique opportunity to influence our detection strategy at scale while making a measurable impact on protecting enterprises worldwide from advanced threats.

  • Propose innovative detection ideas and lead the design and delivery of 2–3 major projects simultaneously.
  • Mentor and guide 2–3 junior or mid-level researchers, providing both technical direction and career development support.
  • Drive advanced research into vulnerabilities, Zero-Day exploits, and emerging attack vectors, and translate findings into effective IPS and ML-based detections.
  • Ensure rapid response to Zero-Day vulnerabilities with IPS protections released to customers within 24 hours.
  • Conduct reverse engineering efforts to uncover new vulnerabilities and build proactive defenses.
  • Define detection methodologies for complex or emerging attack vectors, ensuring scalability and robustness across products.
  • Partner with product, QA, and cross-functional engineering teams to align detection strategy with product roadmap and customer needs.
  • Represent the team in technical discussions internally and externally, helping shape industry direction in threat prevention.
  • Strong leadership and communication skills with proven ability to mentor and guide other researchers.
  • Deep technical expertise in exploit techniques such as buffer overflows, use-after-free, format string, XSS, SQL injection, CSRF, MITM, and DoS.
  • Extensive knowledge of core network protocols including HTTP, UDP, FTP, SMTP, DNS, and SMB.
  • Proficiency in analyzing network traffic using tcpdump, Wireshark, or equivalent tools.
  • Experience applying AI/ML to security problems is highly desirable.
  • Advanced proficiency in Windows and Linux development environments.
  • Strong programming skills in scripting and system-level languages (Python, Bash, Perl, C/C++).
  • Hands-on experience with penetration testing tools (Metasploit, Burp Suite, Nmap) and debugging tools (WinDbg, OllyDbg, GDB) is a strong plus.
  • BS/MS in Computer Science, Computer Engineering, or related field, or equivalent professional/military experience.
  • Demonstrated track record of successfully leading multiple projects end-to-end with measurable impact.
  • Publications or presentations at top security conferences (e.g., Black Hat, DEF CON) are a strong plus.
  • Ability to influence detection strategy within the team and across related groups.
  • FLEXBenefits wellbeing spending account with over 1,000 eligible items selected by employees.
  • Mental and financial health resources.
  • Personalized learning opportunities.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service