Senior Consultant - Offensive Security

Palo Alto Networks

Job Summary

The Senior Consultant on the Offensive Security team at Palo Alto Networks assesses and challenges client security postures. This role involves conducting network scans, penetration testing (web, mobile, cloud), and threat hunting using various tools. The consultant will identify vulnerabilities, exploit weaknesses with client permission, and provide recommendations for cybersecurity best practices, including incident response and recovery. Key responsibilities also include report generation and developing automation scripts.

Must Have

  • Conduct periodic network vulnerability scans
  • Perform client penetration testing (open-source, custom, commercial tools)
  • Scope engagements and articulate penetration approaches
  • Generate reports on testing, results, and remediation
  • Develop scripts, tools, and methodologies for automation
  • Conduct IT application testing and cybersecurity tool analysis
  • Perform mobile application testing, penetration testing, application, security, and hardware testing
  • Conduct threat hunting and compromise assessment engagements (Crypsis, Palo Alto Networks tools)
  • Conduct cloud penetration testing (AWS, GCP, Azure, containers, PaaS, SaaS)
  • Provide recommendations for data and system protection
  • 3+ years experience with risk assessment tools, Information Assurance, Network Security, Infrastructure Design, Vulnerabilities Assessments
  • Deep understanding of malicious software (malware, trojans, rootkits)
  • Ability to modify/craft custom exploits manually
  • Knowledge of network, wireless, web application penetration testing tools/techniques
  • Familiarity with web application penetration testing and code auditing
  • Experience with cyber risk assessments using industry standards
  • Experience with penetration testing, administering, troubleshooting Linux, Windows, and major cloud providers (AWS, GCP, Azure)
  • Experience with security assessment tools
  • Knowledge of network vulnerability assessments, web/cloud application security testing, red teaming, security operations, 'hunt'
  • Knowledge of computer forensic tools, technologies, and methods
  • Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security, or equivalent experience

Perks & Benefits

  • FLEXBenefits wellbeing spending account (over 1,000 eligible items)
  • Mental health resources
  • Financial health resources
  • Personalized learning opportunities
  • Reasonable accommodations for individuals with disabilities
  • Equal opportunity employer

Job Description

Your Career

The Senior Consultant on the Offensive Security team is focused on assessing and challenging the security posture across a comprehensive portfolio of clients. The individual will utilize a variety of tools developed and act as a key team member in client engagements. They will be the client’s advocate for cybersecurity best practices and will provide recommendations in this domain.

Your Impact

  • Conducts periodic scans of networks to find and detect vulnerabilities
  • Performs client penetration testing to find any vulnerabilities or weaknesses that might be exploited by a malicious party, using open-source, custom, and commercial testing tools
  • Ability to assist in scoping engagements by clearly articulating various penetration approaches and methodologies to audiences ranging from highly technical to executive personnel
  • Report generation that clearly communicates testing and assessment details, results, and remediation recommendations to clients
  • Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements
  • Conducts IT application testing, cybersecurity tool and systems analysis, system and network administration, and systems engineering support for the sustainment of information technology systems (mobile application testing, penetration testing, application, security, and hardware testing)
  • Conduct threat hunting and/or compromise assessment engagements to identify active or dormant indicators of compromise (IoCs) using Crypsis and Palo Alto Networks’ threat hunting tools (and/or client owned hunting instrumentation where applicable)
  • Conduct cloud penetration testing engagements to assess specific workloads (i.e., AWS, GCP, Azure, containers, or other PaaS and SaaS instances) for vulnerabilities and subsequently attempt to exploit identified weakness after receiving permission from client stakeholders
  • Provide recommendations to clients on specific security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks including response and recovery of a data security breach
  • Ability to perform travel requirements as needed to meet business demands

Your Experience

  • 3+ years of professional experience with risk assessment tools, technologies, and methods focused on Information Assurance, Information Systems/Network Security, Infrastructure Design, and Vulnerabilities Assessments
  • Demonstrate a deep understanding of how malicious software works (i.e.-malware, trojans, rootkits, etc.)
  • Ability to modify known and/or craft custom exploits manually without dependence on consumer tools such as Metasploit
  • Knowledge of tools and techniques used to conduct network, wireless, and web application penetration testing
  • Familiarity with web application penetration testing and code auditing to find security gaps and vulnerabilities
  • Knowledge and experience in conducting cyber risk assessments using industry standards
  • Experience with penetration testing, administering, and troubleshooting major flavors of Linux, Windows, and major cloud IaaS, PaaS, and SaaS providers (i.e., AWS, GCP, and Azure)
  • Experience with security assessment tools
  • Knowledge of network vulnerability assessments, web and cloud application security testing, network penetration testing, red teaming, security operations, or 'hunt'
  • Knowledge of computer forensic tools, technologies, and methods
  • Assist in the development of internal infrastructure design for research, development, and testing focused on offensive security
  • Identified ability to grow into a valuable contributor to the practice
  • Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security, or equivalent years of professional experience to meet job requirements and expectations or equivalent experience required

The Team

Our Unit 42 organization is dynamic, high-energy, and highly collaborative. If you have an inner entrepreneurial spirit, are comfortable working in fast-paced environments, and yearn for hands-on impact, then this organization is the right one for you. As a member of the Unit 42 team, you will be one of the founding members of a newly formed team responsible for the successful adoption of purchased offerings and driving the increased up-sell of additional services/products. We are looking for experienced SaaS sales or customer success professionals, ideally with cybersecurity domain expertise, who want to make an impact in a fast-paced, high-growth environment.

Our Commitment

We’re problem solvers that take risks and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at accommodations@paloaltonetworks.com.

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

Is role eligible for Immigration Sponsorship?: Yes

12 Skills Required For This Role

Saas Business Models Problem Solving Risk Management Internal Audit Risk Assessment Ethical Hacking Game Texts Security Testing Linux Aws Azure Metasploit

Similar Jobs