Palo Alto Networks

Sr Staff Researcher (Agentic AI Systems Security - Prisma AIRS)

Palo Alto Networks$139K — $225K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Deep hands-on experience in vulnerability research, exploit analysis, or offensive security.
  • Proven expertise with agentic-AI systems and identifying potential loopholes.
  • Strong ability to analyze mechanisms behind vulnerabilities and their exploitability.
  • Experience in translating exploit understanding into customer-facing protections or scanning capabilities.
  • Strong programming or scripting skills for automation and detection development.
  • Excellent communication skills to influence cross-functional technical decisions.

Responsibilities

  • Shape detection strategies by identifying vulnerabilities in the agentic-AI domain.
  • Drive innovative detection ideas from concept to production with measurable improvements.
  • Expand capabilities in protection delivery through automation and research workflows.
  • Lead technical efforts by providing direction and execution guidance to team members.
  • Collaborate with cross-functional teams to ensure sound and relevant detection mechanisms.
  • Support operational excellence of the detection pipeline and team infrastructure.

Benefits

  • Flexible work arrangements to promote work-life balance.
  • Opportunity to drive cutting-edge research in AI security.
  • Collaborative environment fostering innovation and technical growth.
  • Access to professional development resources and training programs.
Full Job Description
Job Summary

About the Team

Prisma AIRS AI Supply Chain Security owns the full supply-chain security posture for agentic-AI systems at Palo Alto Networks, covering the models, artifacts, tools, and extensions that enterprise AI applications are built on. We turn threat research into the scanning and detection capabilities that let customers adopt agentic AI without inheriting its supply-chain risk.

About the Role

We are looking for a security engineer to lead threat research and detection strategy for agentic AI systems, in a hands-on role split across research and engineering. You will model the threat surface across the full agentic stack - agents, skills, MCP servers, and traditional model artifacts, including their configurations and deployment architecture - for both proprietary hosted models and in-house custom deployments, then build that research into production scanning capabilities and own the services that ship them.

Core Technical Focus & Ownership

You bring systemic fluency in the agentic threat landscape: direct and indirect (cross-domain) prompt injection, jailbreak and guardrail bypass, instruction-hierarchy violations, and the agent-loop failures they enable - excessive agency, goal drift, and memory or RAG poisoning. That extends into the tool and extension layer: MCP tool poisoning, tool shadowing, server rug pulls, OAuth scope and token-passthrough abuse, and supply-chain risk in third-party skills and plugins. Deployment posture matters equally - exposed inference endpoints, least-privilege tool scoping and ephemeral credentials, insecure output handling, and egress control over the channels that turn a single injection into data loss. In production, you run the pipeline itself: service health, latency and availability targets, release quality, and false-positive/false-negative regression gates, with on-call response and observability as day-to-day work.

Qualifications
Impact
  • Shape detection and scanning strategy by identifying the vulnerability, exploit, and attack-technique areas in the agentic-AI domain where new or improved protections are needed.
  • Drive innovative detection ideas from concept to production, delivering measurable improvements in coverage, quality, speed, or scalability.
  • Expand the team's ability to deliver protections at scale through practical automation, detection pipeline improvements, and AI-assisted research workflows.
  • Provide hands-on technical leadership to researchers and developers through direction, review, problem decomposition, and execution guidance.
  • Influence cross-functional decisions with product, QA, engineering, and research partners to ensure detections are technically sound, customer-relevant, and production-ready.
  • Support the operational excellence of the detection pipeline and other common infrastructure owned by the team.
Qualifications
  • Deep hands-on experience in vulnerability research, exploit analysis, offensive security, or closely related threat prevention work.
  • Deep and proven expertise using agentic-AI systems with an eye for finding loopholes, across both proprietary hosted models and in-house custom model deployments. Using agentic-AI practices as tooling and automation to improve security analysis, detection development, validation, or response workflows is highly desirable.
  • Proven ability to identify important technical problems, propose detection ideas, drive execution, and deliver measurable product or customer impact, specifically in the agentic-AI threat research domain.
  • Deep understanding of common vulnerability classes and exploit techniques - including memory corruption, injection, authentication bypass, path traversal, SSRF, RCE, XSS, SQL injection, CSRF, MITM, and DoS - and how these classes resurface through agent tool wrappers, tool parameters, and insecurely handled model output.
  • Strong ability to analyze vulnerability root cause, exploitability, PoC behavior, network traffic, protocol behavior, application-layer attack patterns, and detection tradeoffs.
  • Experience translating vulnerability or exploit understanding into production-quality scanning capabilities or other customer-facing protections.
  • Strong programming or scripting skills for research automation, tooling, test generation, detection development, or pipeline improvements.
  • Ability to lead complex technical work under ambiguity, guide other researchers or developers, and make sound technical decisions under time pressure.
  • Strong communication skills with the ability to influence technical direction across research, product, QA, and engineering partners.
  • BS/MS in Computer Science, Computer Engineering, Cybersecurity, or related field, or equivalent professional experience.


Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

$139,600.00 - $225,775.00/yr

About Palo Alto Networks

Palo Alto Networks, Inc. is an American multinational cybersecurity company with headquarters in Santa Clara, California. Its core products are a platform that includes advanced firewalls and cloud-based offerings that extend those firewalls to cover other aspects of security. The company serves over 70,000 organizations in over 150 countries, including 85 of the Fortune 100. It is home to the Unit 42 threat research team and hosts the Ignite cybersecurity conference.
Learn more about Palo Alto Networks
Size
11,870 employees
Market Cap
$42.6 billion
Industry
Net Income
-$368.2 million
Founded
2005
5 Year Trend
+25.7%
Revenue
$3.7 billion
NASDAQ

Similar Jobs

More Jobs at Palo Alto Networks

More Information Technology Jobs

Find similar Sr Staff Researcher (Agentic AI Systems Security - Prisma AIRS) jobs: