Skip to main content

Palo Alto Networks is on a mission to keep the digital world safe, and this extends to job seekers as well. Please be mindful of a current bad actor practice of recruiters impersonating us. If you receive an email from someone who does not have a @paloaltonetworks.com email address, please do not respond or engage.

Two women reviewing a computer screen

求人の詳細

セキュリティ対策に革命を。

サイバーセキュリティの未来を創造する。

Principal Security Researcher (AI-Assisted Vulnerability Research)

サンタクララ, カリフォルニア州, アメリカ合衆国 Product Engineering 参照ID JR-018442

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

Job Summary

Your Career

As a Principal Security Researcher, you will work at the forefront of AI-assisted vulnerability research, focusing on the design, implementation, and improvement of AI/security harnesses for discovering, validating, understanding, and reporting high-impact vulnerabilities in real-world software and open-source projects. You will leverage LLMs, AI agents, fuzzing, static and dynamic analysis, reverse engineering, exploitability analysis, and security automation to build reliable workflows for vulnerability discovery, PoC generation, finding validation, patch validation, variant analysis, and remediation support.

Your Impact

This is a research-heavy role for a self-directed researcher-builder. The ideal candidate can independently identify high-impact security problems, build reliable harnesses and evaluation pipelines, analyze large-scale vulnerability data, and drive projects toward concrete outcomes such as improved harness capabilities, validated findings, technical reports, benchmarks, responsible disclosures, open-source tools, CVEs where appropriate, or production-impacting security workflows. We prioritize finding quality and research impact over raw vulnerability counts.

  • Design, build, and improve AI/security harnesses for vulnerability research, with emphasis on reproducibility, validation quality, exploitability clarity, false-positive reduction, and stable evidence generation.

  • Produce high-quality research and security artifacts, such as improved harness capabilities, validated findings, root-cause analyses, technical reports, benchmarks, internal research artifacts, open-source tools, responsible disclosures, publications, or CVEs where appropriate.

  • Conduct deep technical analysis across real-world software and open-source projects, including reverse engineering, fuzzing, root-cause analysis, exploitability assessment, patch analysis, variant analysis, and PoC validation.

  • Build reusable research infrastructure, including target setup automation, fuzzing harnesses, AI agent workflows, benchmark environments, validation oracles, triage pipelines, evaluation metrics, and maintainer-facing reporting workflows.

  • Use LLMs, AI agents, fuzzing, static/dynamic analysis, program analysis, reverse engineering automation, and security automation to improve the quality, speed, coverage, and reliability of vulnerability research workflows.

  • Analyze large-scale harness outputs, including successful findings, failed attempts, crash clusters, validation traces, false positives, patch comparisons, and target patterns, to identify new research opportunities and improve future harness capabilities.

Qualifications

Your Experience

Required Qualifications:

  • Master's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.

  • Demonstrated ability to independently drive a technical research project from problem formulation to implementation, evaluation, and written results.

  • Evidence of original security research or high-signal technical output, such as CVEs, responsible disclosures, bug bounty findings, security conference papers, technical writeups, GitHub projects, fuzzers, harnesses, exploit analyses, AI/security benchmarks, open-source security tools, or comparable research artifacts.

  • 7+ years of experience in vulnerability research, offensive security research, reverse engineering, fuzzing, exploit development, program analysis, security automation, or a closely related security research role.

  • Demonstrated experience in one or more of the following: vulnerability research, reverse engineering, fuzzing, exploit development, root-cause analysis, exploitability assessment, PoC development, patch analysis, program analysis, or security tooling.

  • Experience designing or building reproducible security experiments, including target setup, harness development, validation logic, oracle design, evaluation metrics, false-positive analysis, or reporting workflows.

  • Strong programming skills. Strong knowledge of modern operating systems, network protocols, application security, software vulnerability classes, and common exploitation or validation techniques.

  • Strong written communication skills, including the ability to document methods, evidence, limitations, reproduction steps, impact, and remediation guidance clearly.

Preferred Qualifications:

  • PhD in Computer Science, Cybersecurity, AI/ML, Systems, Programming Languages, or a related field, or equivalent demonstrated research experience.

  • Experience building AI agent harnesses, fuzzing harnesses, evaluation harnesses, vulnerability validation workflows, exploitability triage systems, patch validation pipelines, security benchmarks, or open-source vulnerability research tooling.

  • Experience handling real vulnerabilities end-to-end, including target selection, environment setup, harnessing, reproduction, root-cause analysis, exploitability assessment, patch comparison, responsible disclosure, and maintainer communication.

  • Knowledge of security in one or more of the following areas: Web Security, OS & Kernel Security, Browser Security, Software Supply Chain Security, OT/IoT Security, Network/Protocol Security, Cloud Security, Application Security, file parser security, or protocol parser security.

  • Strong practical artifacts are highly valued. A public track record of security research, such as conference presentations, publications, CVEs, responsible disclosures, bug bounty results, technical blogs, GitHub projects, open-source security tools, AI/security benchmarks, agent frameworks, or security research artifacts.

  • High-impact maintainer relationships, experience reporting vulnerabilities to major open-source projects, or a track record of clear, actionable, well-received vulnerability disclosures is a strong plus.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

$162,700.00 - $263,175.00/yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at  accommodations@paloaltonetworks.com.

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

Is role eligible for Immigration Sponsorship?: Yes

最近見た求人はありません

最近見た求人はありません

常に最新の求人情報を受け取ることができます。最新のニュースやイベントもご案内します。

関心

  • Product Engineering, サンタクララ, カリフォルニア州, アメリカ合衆国削除

By signing up, I acknowledge I have read the Palo Alto Networks privacy policy, and I wish to receive email communications and SMS communications. I understand I can opt-out from receiving email and SMS communications at any time.

キャリアへの知見を深め、希望に合うここだけの情報を手に入れましょう。