Palo Alto Networks

Principal Security Researcher (AI-Assisted Vulnerability Research)

Palo Alto Networks$162K — $263K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Master's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
  • Proven ability to independently manage technical research projects to completion.
  • Evidence of original security research such as CVEs, bug bounties, or security conference papers.
  • 7+ years of relevant experience in vulnerability research or offensive security roles.
  • Experience in vulnerability research techniques like reverse engineering and fuzzing.
  • Strong programming and systems knowledge, especially in security contexts.
  • Excellent written communication skills for documenting research findings.

Responsibilities

  • Design and enhance AI/security harnesses for vulnerability validation.
  • Produce comprehensive security research artifacts and reports.
  • Conduct technical analyses on software and open-source vulnerabilities.
  • Build reusable research infrastructures and automated workflows.
  • Utilize advanced techniques like AI and fuzzing to improve vulnerability discovery.
  • Analyze large datasets of vulnerability research results to extract insights.

Benefits

  • Eligible for immigration sponsorship.
  • Participation in employee stock option programs.
  • Access to comprehensive health and wellness benefits.
Full Job Description
Job Summary

Your Career

As a Principal Security Researcher, you will work at the forefront of AI-assisted vulnerability research, focusing on the design, implementation, and improvement of AI/security harnesses for discovering, validating, understanding, and reporting high-impact vulnerabilities in real-world software and open-source projects. You will leverage LLMs, AI agents, fuzzing, static and dynamic analysis, reverse engineering, exploitability analysis, and security automation to build reliable workflows for vulnerability discovery, PoC generation, finding validation, patch validation, variant analysis, and remediation support.

Your Impact

This is a research-heavy role for a self-directed researcher-builder. The ideal candidate can independently identify high-impact security problems, build reliable harnesses and evaluation pipelines, analyze large-scale vulnerability data, and drive projects toward concrete outcomes such as improved harness capabilities, validated findings, technical reports, benchmarks, responsible disclosures, open-source tools, CVEs where appropriate, or production-impacting security workflows. We prioritize finding quality and research impact over raw vulnerability counts.
  • Design, build, and improve AI/security harnesses for vulnerability research, with emphasis on reproducibility, validation quality, exploitability clarity, false-positive reduction, and stable evidence generation.
  • Produce high-quality research and security artifacts, such as improved harness capabilities, validated findings, root-cause analyses, technical reports, benchmarks, internal research artifacts, open-source tools, responsible disclosures, publications, or CVEs where appropriate.
  • Conduct deep technical analysis across real-world software and open-source projects, including reverse engineering, fuzzing, root-cause analysis, exploitability assessment, patch analysis, variant analysis, and PoC validation.
  • Build reusable research infrastructure, including target setup automation, fuzzing harnesses, AI agent workflows, benchmark environments, validation oracles, triage pipelines, evaluation metrics, and maintainer-facing reporting workflows.
  • Use LLMs, AI agents, fuzzing, static/dynamic analysis, program analysis, reverse engineering automation, and security automation to improve the quality, speed, coverage, and reliability of vulnerability research workflows.
  • Analyze large-scale harness outputs, including successful findings, failed attempts, crash clusters, validation traces, false positives, patch comparisons, and target patterns, to identify new research opportunities and improve future harness capabilities.


Qualifications

Your Experience

Required Qualifications:
  • Master's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.


  • Demonstrated ability to independently drive a technical research project from problem formulation to implementation, evaluation, and written results.


  • Evidence of original security research or high-signal technical output, such as CVEs, responsible disclosures, bug bounty findings, security conference papers, technical writeups, GitHub projects, fuzzers, harnesses, exploit analyses, AI/security benchmarks, open-source security tools, or comparable research artifacts.


  • 7+ years of experience in vulnerability research, offensive security research, reverse engineering, fuzzing, exploit development, program analysis, security automation, or a closely related security research role.


  • Demonstrated experience in one or more of the following: vulnerability research, reverse engineering, fuzzing, exploit development, root-cause analysis, exploitability assessment, PoC development, patch analysis, program analysis, or security tooling.


  • Experience designing or building reproducible security experiments, including target setup, harness development, validation logic, oracle design, evaluation metrics, false-positive analysis, or reporting workflows.


  • Strong programming skills. Strong knowledge of modern operating systems, network protocols, application security, software vulnerability classes, and common exploitation or validation techniques.


  • Strong written communication skills, including the ability to document methods, evidence, limitations, reproduction steps, impact, and remediation guidance clearly.


Preferred Qualifications:
  • PhD in Computer Science, Cybersecurity, AI/ML, Systems, Programming Languages, or a related field, or equivalent demonstrated research experience.


  • Experience building AI agent harnesses, fuzzing harnesses, evaluation harnesses, vulnerability validation workflows, exploitability triage systems, patch validation pipelines, security benchmarks, or open-source vulnerability research tooling.


  • Experience handling real vulnerabilities end-to-end, including target selection, environment setup, harnessing, reproduction, root-cause analysis, exploitability assessment, patch comparison, responsible disclosure, and maintainer communication.


  • Knowledge of security in one or more of the following areas: Web Security, OS & Kernel Security, Browser Security, Software Supply Chain Security, OT/IoT Security, Network/Protocol Security, Cloud Security, Application Security, file parser security, or protocol parser security.


  • Strong practical artifacts are highly valued. A public track record of security research, such as conference presentations, publications, CVEs, responsible disclosures, bug bounty results, technical blogs, GitHub projects, open-source security tools, AI/security benchmarks, agent frameworks, or security research artifacts.


  • High-impact maintainer relationships, experience reporting vulnerabilities to major open-source projects, or a track record of clear, actionable, well-received vulnerability disclosures is a strong plus.


Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

$162,700.00 - $263,175.00/yr

Is role eligible for Immigration Sponsorship?: Yes

About Palo Alto Networks

Palo Alto Networks, Inc. is an American multinational cybersecurity company with headquarters in Santa Clara, California. Its core products are a platform that includes advanced firewalls and cloud-based offerings that extend those firewalls to cover other aspects of security. The company serves over 70,000 organizations in over 150 countries, including 85 of the Fortune 100. It is home to the Unit 42 threat research team and hosts the Ignite cybersecurity conference.
Learn more about Palo Alto Networks
Size
11,870 employees
Market Cap
$42.6 billion
Industry
Net Income
-$368.2 million
Founded
2005
5 Year Trend
+25.7%
Revenue
$3.7 billion
NASDAQ

Similar Jobs

More Jobs at Palo Alto Networks

More Information Technology Jobs

Find similar Principal Security Researcher (AI-Assisted Vulnerability Research) jobs: