Principal Consultant, Proactive Services (Unit 42)
About the role
Our Mission
At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.
Who We Are
In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!
This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.Job Summary
This client-facing role requires the Principal Consultant to lead and produce deliverables for cyber risk management (CRM) engagements. You will work directly with multiple customers and key stakeholders, from administrators to the C-suite, to define and drive security priorities for their security operations center (SOC) and broader information security teams, acting as a trusted advisor to help them achieve and maintain a strong cybersecurity posture.
Key Responsibilities
Lead comprehensive security audits of client security operations programs, including organization, processes, and technology.
Analyze security monitoring and alerting to perform a gap analysis on asset visibility, log coverage, and detection effectiveness.
Conduct cyber risk assessments using industry frameworks such as MITRE ATT&CK, NIST CSF, and ISO 27001/2.
Utilize command-line and graphical interfaces of security tools to perform technical validation of security controls.
Assess client security architecture and the implementation and integration of security monitoring and protection tools.
Advise on and develop strategic roadmaps with actionable recommendations for clients to mature their SOC capabilities.
Collaborate with prospective clients to scope new opportunities, including the creation of proposals and statements of work.
Qualifications
Required Qualifications
Bachelor's degree in a relevant field, or equivalent military experience, or a Master's degree with 6 years of experience, or a PhD with 3 years of experience.
8+ years of experience in information security, with at least 3 years in a consulting capacity focused on SOC, security engineering, or incident management for large organizations.
Deep technical knowledge of SIEM platforms, EDR/XDR tools, Next-Gen Firewalls, and Vulnerability Management solutions.
Experience serving as a security advisor and managing relationships with client stakeholders.
Ability to travel as needed to meet business demands, averaging approximately 30%.
Preferred Qualifications
Hands-on experience with SIEM engineering, management, or advanced security analytics.
Knowledge of or certification in the MITRE ATT&CK framework.
Experience with command-line interfaces or scripting tools (e.g., Python, PowerShell) for security tasks.
Proven track record of strengthening client relationships and developing new business opportunities.
Our Commitment
We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.
We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at [email protected].
Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.
All your information will be kept confidential according to EEO guidelines.
Is role eligible for Immigration Sponsorship?: YesAbout Cortex by Palo Alto Networks
Demisto Enterprise is a security operations platform that combines intelligent automation and collaboration into a single ChatOps interface. It combines security orchestration and automation, incident management, and interactive investigation to help security teams meet these challenges and best leverage existing and new security investments.
Demisto’s automation is provided by DBot, who interacts with your team via ChatOps for playbook-based workflows, cross-correlation, and information sharing, helping security teams scale while working and learning the way humans are wired to – together.
The company was founded in 2015 and is based in Cupertino, California.
Other roles at Cortex by Palo Alto Networks
Job details
Funding
Total raised
$69M
Last stage
Series C
Investors
Founders
What happens next.
No applications, no recruiter spam. Just the intro.
Confirm the fit
A few questions to make sure this role is the right shape for you. Two minutes.
I pitch you to the company
I write the intro, send it to the founder, and handle the back-and-forth.
A meeting lands on your calendar
If they’re a yes, I book the chat. You show up — that’s the whole job-hunt.
