- Company Name
- Palo Alto Networks
- Job Title
- Senior Cloud Security Engineer (InfoSec)
- Job Description
-
**Job Title**
Senior Cloud Security Engineer (InfoSec)
**Role Summary**
Lead the design, implementation, and automation of security controls for enterprise, SaaS, and public cloud (GCP, AWS, Azure) services. Provide architectural guidance, incident response, and governance support to maintain a robust, Zero‑Trust posture across on‑prem and cloud infrastructure.
**Expectations**
- 4‑7 years of hands‑on experience in network and infrastructure security.
- 2+ years with firewall technologies, deep expertise in Palo Alto Networks NGFW and rule evaluation.
- 2+ years managing and securing multi‑cloud environments (AWS, GCP, Azure) using native security tools.
- Demonstrated ability to develop and maintain security baselines aligned with CIS, NIST, and SOC 2/ISO 27001 requirements.
**Key Responsibilities**
- Assess and review security and cloud infrastructure in IT and production environments.
- Design and enforce Zero‑Trust Network Architecture, including segmentation and identity controls.
- Build and maintain SOAR‑based automation to streamline repetitive security tasks.
- Collaborate with Vulnerability Management, Network Engineering, OS Engineering, and product SRE teams.
- Prioritize and resolve critical vulnerabilities and data exposures.
- Develop and maintain security baselines for VMs, containers, and network devices.
- Support incident response: containment, forensic investigation, root cause analysis, and documentation.
- Conduct regular policy and firewall rule reviews to ensure alignment with access requirements.
- Contribute to GRC activities: audit participation, third‑party risk assessments, evidence collection for SOC 2, ISO 27001, or FedRAMP.
**Required Skills**
- Network security fundamentals (firewalls, IDS/IPS, VPN, SD‑WAN).
- Cloud security: architecture, IAM, VPC, key‑management, security tools (GCP Security Command Center, AWS GuardDuty, Azure Security Center).
- Zero‑Trust principles and architecture design.
- Governance, risk, compliance frameworks (CIS Benchmarks, NIST, SOC 2, ISO 27001).
- SOAR/automation platforms and scripting (Python, Terraform, Ansible).
- Incident response processes and forensic analysis.
- Strong communication; ability to coordinate across cross‑functional teams.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (preferred).
- Relevant professional certifications (e.g., Palo Alto Networks NGFW certification, CompTIA Security+, CISSP, or similar).
Santa clara, United states
On site
Senior
19-09-2025