Staff Security Researcher

3 weeks ago


Washington, United States Palo Alto Networks Full time
Job DescriptionJob DescriptionCompany Description

Our Mission

At Palo Alto Networks® everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.

Who We Are

We take our mission of protecting the digital way of life seriously. We are relentless in protecting our customers and we believe that the unique ideas of every member of our team contributes to our collective success. Our values were crowdsourced by employees and are brought to life through each of us everyday - from disruptive innovation and collaboration, to execution. From showing up for each other with integrity to creating an environment where we all feel included.  

As a member of our team, you will be shaping the future of cybersecurity. We work fast, value ongoing learning, and we respect each employee as a unique individual. Knowing we all have different needs, our development and personal wellbeing programs are designed to give you choice in how you are supported. This includes our FLEXBenefits wellbeing spending account with over 1,000 eligible items selected by employees, our mental and financial health resources, and our personalized learning opportunities - just to name a few 

Job Description

Your Career

We’re looking for a Staff Security Researcher for Cortex Xpanse’s Security Research Engineering team. You will be responsible for the creation, validation and deployment of vulnerability signatures and protocol payloads which will be used by our scanning infrastructure to understand what vulnerabilities are exposed across customer networks. You will also be responsible for creating new policies, which encode risky device configurations as code that is run over observations from our global scanning data. You will be a key member of a team that proactively sources vulnerabilities and misconfigurations from newly discovered CVEs and responds to Xpanse customer requests.

Our mission is to find risks online and protect the world’s largest organizations from malicious software and hackers. Expanse’s Internet intelligence platform collects petabytes of Internet data, leverages artificial intelligence to discover “unknown unknown” risks for customers, and delivers those insights via a SaaS web application. On this team, you will directly contribute to our mission by defining and delivering on Expanse’s technical roadmap. 

Your Impact

  • Contribute to Xpanse’s critical vulnerability response by implementing the necessary vulnerability signatures and payloads to detect presence of critical CVEs while effectively communicating with the Xpanse team, across the Cortex business unit, and across Palo Alto Networks
  • Research trending threats and develop proof of concepts to detect presence of confirmed and inferred vulnerabilities
  • Research and develop fingerprints that can help Xpanse identify and structure more and more types of services running on the global Internet
  • Proactively add customer-requested policies and implement protocol payloads while minimizing false positives & false negatives
  • Research emerging vulnerability threats on the global Internet and contribute to Cortex Research blogs/publications
Qualifications

Your Experience

  • Bachelor's degree in Computer Science, Data Science, Engineering, or other technical discipline (or equivalent professional or military experience) - We don’t look for a specific number of years of experience, but typically people who are successful at Staff level positions are early to mid-level in their careers
  • High level knowledge of network security vulnerabilities, CVSS scoring and exploit techniques
  • Familiarity with one or more programming languages (Java, Python, Go, Bash)
  • Ability to concisely communicate complex subject matter to technical and non-technical audiences
  • Ability to work independently as a researcher as well as part of larger cross-functional teams

Nice to have, but not required

  • Experience with SQL and Regex
  • Prior experience performing open-ended security research and showcasing externally via blogs and publications
  • Hands-on  experience in security research/systems security/network security


Additional Information

The Team

Cortex Xpanse helps protect some of the world’s most important organizations by finding risks on the Internet that no one else can find. Our security research teams are at the core of our products and are responsible for building security detections for our products that allow customers to turn trillions of Internet data points into critical cybersecurity insights. We are constantly innovating — challenging the way we, and the industry, think about cybersecurity. Our engineers don’t shy away from building products to solve problems no one has pursued before.

We define the industry instead of waiting for directions. We need individuals who feel comfortable in ambiguity, excited by the prospect of a challenge, and empowered by the unknown risks facing our everyday lives that are only enabled by a secure digital environment.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be between $107,400/yr to $173,800/yr. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

Our Commitment

We’re problem solvers that take risks and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at  accommodations@paloaltonetworks.com.

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.



  • Washington, United States Non-Departmental Agency Full time

    Summary Cyber Security Researchers focus in the cyber arena and specialize in the design, development, integration, and deployment of cutting-edge tools, techniques, and systems to support cyber operations. ...


  • Washington, Washington, D.C., United States United States Institute of Peace Full time

    About Us The United States Institute of Peace is dedicated to promoting global peace and security. We embody the collective values of the American populace, striving to foster peace across the globe. Our belief is that peace is integral to security, enhancing both national and international stability by averting, managing, and alleviating violent...


  • Washington, Washington, D.C., United States International Turbo Sytems Inc Full time

    Job OverviewInternational Turbo Systems is currently looking for a Legal Research Associate to join our team. This is a full-time role within a long-term contract framework with the Securities and Exchange Commission. The position offers a comprehensive benefits package, including paid holidays and vacation time.Key ResponsibilitiesConducts in-depth legal...


  • Washington, Washington, D.C., United States United States Institute of Peace Full time

    About Us The United States Institute of Peace is dedicated to fostering global peace and security. Our mission reflects the American people's commitment to promoting peace and preventing conflict on an international scale. As an independent and non-partisan organization, we engage in peacebuilding initiatives worldwide, addressing complex challenges...


  • Washington, Washington, D.C., United States United States Institute of Peace Full time

    About Us The United States Institute of Peace embodies the collective values of the American populace, dedicating itself to fostering peace on a global scale. We understand that peace is integral to security, enhancing both U.S. and international safety by averting, managing, and alleviating violent conflicts. As an independent and non-partisan entity,...


  • Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewTCS Security is a recognized leader in the field of security services, specializing in comprehensive security solutions for various sectors. We pride ourselves on our commitment to excellence and the safety of our clients.Position SummaryThe Armed Security Supervisor will be responsible for overseeing security operations to ensure the protection...


  • Washington, United States National Nuclear Security Administration Full time

    As an Operation Research Analyst, duties include: Serve as a subject matter expert for cost estimating, life-cycle cost analysis, cost modeling and the development of cost databases, risk management, and operational research Use knowledge of applying appropriate cost estimating and statistics principles and methods, as well as risk management principles,...


  • Washington, United States Booz Allen Hamilton Full time

    Exciting Career OpportunityBecome a vital member of our team at Booz Allen Hamilton as a Quantum Security Research Specialist. We are in search of a skilled professional who is enthusiastic about network architecture and software engineering to develop and implement advanced post-quantum cryptography solutions. If you possess a background in data analysis,...

  • Security Officer

    2 weeks ago


    Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewPosition Summary: The role of the security officer is crucial in ensuring the safety and security of individuals and property. This position requires a dedicated individual who can maintain a professional demeanor while performing various security-related tasks.Key Responsibilities:1. Security personnel must be at least 21 years of age.2. A high...

  • Security Officer

    2 weeks ago


    Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewPosition Summary: The role of the security officer is crucial in ensuring the safety and security of individuals and property within the designated premises.Key Responsibilities:1. Security personnel must be at least 21 years of age.2. A high school diploma or equivalent is required.3. Security officers must be physically capable of performing...

  • Research Assistant

    4 hours ago


    Washington, Washington, D.C., United States United States Institute of Peace Full time

    About the PositionThe United States Institute of Peace is seeking a highly skilled Research Assistant to provide research, writing, and administrative support for the Governance, Justice, and Security (GJS) team.Key ResponsibilitiesSupport the Security Governance Advisor and Senior Program Officers by providing research support through data collection and...


  • Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewPosition: Armed Security Supervisor/RoverTCS Security, a recognized leader in security services, is seeking a dedicated Armed Security Supervisor/Rover. Our firm specializes in providing comprehensive security solutions to various clients, ensuring the safety of personnel and property.At TCS Security, we pride ourselves on fostering a diverse and...

  • Security Officer

    2 weeks ago


    Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewPosition: Unarmed Security GuardThe responsibilities of the unarmed security personnel encompass a variety of essential functions aimed at maintaining safety and security. These include, but are not limited to:Monitoring the premises and conducting perimeter checks.Providing assistance to the public and responding to inquiries.Maintaining a...


  • Washington, United States United States-China Economic and Security Review Commission Full time

    Job SummaryWe are seeking a highly skilled and experienced professional to join our team as a Director, Security and Foreign Affairs. The successful candidate will be responsible for leading and managing a small team of policy research staff, overseeing unclassified work in Security and Foreign Affairs subject matter areas, and contributing to the broader...

  • Security Officer

    2 weeks ago


    Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewPosition: Unarmed Security OfficerThe responsibilities of the unarmed security officer encompass a variety of essential tasks aimed at ensuring safety and security. These duties include, but are not limited to:Monitoring the premises and conducting perimeter checks.Providing assistance to the public and addressing inquiries.Maintaining a...


  • Washington, Washington, D.C., United States TCS Security Full time

    Job OverviewPosition: Armed Security Supervisor/RoverTCS Security, a distinguished firm recognized for its expertise in various management sectors, is seeking a dedicated Armed Security Supervisor/Rover. Our organization prides itself on fostering an inclusive workplace, valuing diversity, and honoring military veterans.The Armed Security Supervisor/Rover...


  • Washington, United States Bureau of Industry and Security Full time

    Position OverviewThis role is for an Industry and Trade Analyst within the Bureau of Industry and Security, part of the Department of Commerce.EligibilityThis position is available to federal employees classified as "surplus" or "displaced" and to the general public, including U.S. Citizens and Nationals.Agency ClarificationThis opportunity is being...

  • Armed Security Guard

    4 weeks ago


    Washington, United States TCS Security Full time

    Job DescriptionJob DescriptionDescription:Trust Consulting Services, Inc. is a certified 8(a), SDVOSB firm specializing in Acquisition Management, Program Management, Financial Management, Information Technology and Facility Management in support of state, local and federal agencies.At Trust Consulting, we value every employee. We are an equal opportunity...


  • Washington, Washington, D.C., United States Cyber Security Innovations Full time

    Job OverviewCyber Security Innovations is seeking a Security Assessment Specialist to become a vital part of our team for an upcoming Security and Privacy Evaluation initiative within the non-profit telecommunications sector. This role is essential in fortifying our defenses against potential technical security vulnerabilities.This position offers a hybrid...


  • Washington, United States Intelligence and National Security Alliance Full time

    Company OverviewThe Intelligence and National Security Alliance (INSA) collaborates with technology and research clients to achieve mission success and enhance business operations. Since its inception, INSA has integrated core competencies in analytics and engineering with specialized knowledge. Our teams assist government entities, leading corporations, and...