Principal Consultant, Offensive Security, Proactive Services; Unit
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
Our Mission
At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.
WhoWe Are
In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values:
Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!
This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.
Job SummaryAs a Principal Consultant on the Offensive Security team, you will be a key leader in assessing and challenging the security posture of a diverse client portfolio. You will leverage a variety of advanced tools and methodologies to act as the client’s advocate for cybersecurity best practices. This role is critical in providing strong, actionable recommendations to enhance our clients’ defenses against sophisticated threats.
Key Responsibilities- Conduct comprehensive penetration tests (network, web application, cloud, mobile) to identify and exploit vulnerabilities.
- Develop custom scripts, tools, and methodologies to automate and enhance offensive security engagements and internal processes.
- Lead client engagements, clearly articulating testing approaches and methodologies to both technical and executive audiences.
- Generate detailed reports that communicate test results, identified risks, and concrete remediation recommendations to clients.
- Perform cyber risk assessments using industry frameworks such as NIST CSF, ISO 27001, and CIS Top 20.
- Conduct threat hunting and compromise assessment engagements to identify active or dormant indicators of compromise (IoCs) in client environments.
- Proactively collaborate with internal teams and clients, exchanging information to ensure alignment and accomplish shared security objectives.
- Assist in scoping new opportunities and developing internal infrastructure for offensive security research and development.
Required Qualifications
- Bachelor’s Degree in Information Security, Computer Science, or a related field, or equivalent professional experience.
- 6+ years of professional experience in information security, with a focus on penetration testing and vulnerability assessments.
- Expertise with security assessment tools such as Metasploit, Burp Suite Pro, Cobalt Strike, Nessus, and Bloodhound.
- Proficiency in scripting or programming with languages like Python, Power Shell, Ruby, or C++.
- Demonstrated experience in conducting penetration tests across various environments including Windows, Linux, and cloud platforms (AWS, GCP, Azure).
- Experience managing or mentoring junior consultants on security engagements.
- Certifications such as OSCP, OSCE, GPEN, GWAPT, or GXPN.
- Experience with public speaking, publishing research, or contributing to the security community.
- Knowledge of computer forensic tools, technologies, and incident response methods.
The compensation offered for this position…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).