Staff InfoSec Engineer – Endpoint, Identity & AI Security

paloaltonetworks· Palo Alto Networks Ltd
Apply Now ↗
📍 Office - Israel - CyberArk Petach TikvaFull time
Full timeNoPalo Alto Networks Ltd

About this role

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

Job Summary

The Team

Information Security - We’re not your ordinary Information Security team. We’re a diverse group of security professionals who challenge the status quo in order to protect Palo Alto Networks and our customers. Driving innovation on the Information Security team of the fastest-growing high-tech cybersecurity company is a once-in-a-lifetime opportunity. You’ll be joined by the brightest minds in technology, and our global teams are on the front line of defense against cyberattacks.

Job Summary

Lead the design, implementation, and management of security controls across three critical domains: Endpoint Security, Identity & Access Management, and AI Security, safeguarding Palo Alto Networks' global infrastructure with a Zero Trust approach.

Key Responsibilities

  • Design, build and implement enterprise security capabilities to protect Palo Alto Networks global infrastructure
  • Develop strategies to maintain security architecture, prevent unauthorized access, and ensure identity governance across the enterprise
  • Establish, maintain, and enforce hardened security baselines for Endpoints, Identity, and AI tools
  • Lead AI security governance, define controls, policies, and threat models for safe enterprise adoption of AI tools and models
  • Evaluate and secure AI-related data flows, including prompt injection risks, model access controls, and data exfiltration vectors
  • Implement and manage Identity Security, Endpoint security, and Access Management capabilities with a Zero Trust approach
  • Design and enforce endpoint hardening strategies across managed and unmanaged devices, endpoint DLP controls, drive mobile security and BYOD posture management
  • Be the first customer for Palo Alto Networks products and provide practitioner feedback to the product teams
  • Perform threat modeling and security architecture reviews for complex enterprise systems, infrastructure, and third-party integrations
  • Work with Security Operations team to investigate identity and endpoint breach incidents, identify root cause and provide appropriate remediation or risk reduction plans
  • Collaborate with legal and governance, risk and compliance (GRC) teams to ensure adherence to Identity and data protection regulations
  • Evaluate ongoing practices and procedures, technical documentation, and diagrams for appropriate security measure maturity and effectiveness
  • Lead hands-on POCs and technology evaluations with rigorous benchmarks; champion adoption with a collaborative team mindset
  • Be a strong thought leader and clearly communicate and build support for your ideas

    Qualifications

    • 8+ years of hands-on experience in enterprise security engineering, spanning identity & access management, endpoint security, and/or cloud security, with a Zero Trust mindset
    • Deep understanding of the AI security domain, trends, and risks, with hands-on experience securing AI models, LLM integrations, and implementing enterprise security controls
    • Strong experience in designing and securing Enterprise Identity architecture, including Identity Providers (Okta, Ping, Entra ID), Access Governance & IGA (SailPoint, Saviynt), and directory services (Active Directory, RedHat)
    • In depth knowledge of public cloud architecture, such as GCP, AWS and Azure, with focus on securing Identities in the cloud environments
    • Hands-on experience with endpoint security platforms like Palo Alto Networks XDR, device management (Microsoft Intune, JAMF), and endpoint DLP
    • In depth knowledge of threat model, application security assessments, network security, encryption, authentication and authorization
    • Proficiency in programming / scripting / automation (e.g. Python, Golang, or Powershell) for security engineering workflows
    • Bachelor's degree or equivalent training and education.

    Preferred Qualifications

    • Experience in security engineering related to identity & access, data security, network security, intrusion prevention, monitoring, analytical and correlation tools a PLUS
    • Certification in any of the following is a plus: Google Cloud Architect; AWS Cloud Architect, CISSP-ISSEP - Sec. Eng. Professional, GIAC Certified Enterprise Defender (GCED), CCSP

    Our Commitment

    We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

    We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at  accommodations@paloaltonetworks.com.

    Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

    All your information will be kept confidential according to EEO guidelines.

    Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

    Frequently Asked Questions

    Is the salary disclosed for the Staff InfoSec Engineer – Endpoint, Identity & AI Security position at paloaltonetworks?
    The salary for this Staff InfoSec Engineer – Endpoint, Identity & AI Security role at paloaltonetworks is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
    Where is the Staff InfoSec Engineer – Endpoint, Identity & AI Security position at paloaltonetworks located?
    This Staff InfoSec Engineer – Endpoint, Identity & AI Security role at paloaltonetworks is based in Office - Israel - CyberArk Petach Tikva. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
    Is the Staff InfoSec Engineer – Endpoint, Identity & AI Security role at paloaltonetworks full-time or part-time?
    This is listed as a Full time position. It is posted as a Staff InfoSec Engineer – Endpoint, Identity & AI Security role in the Palo Alto Networks Ltd department at paloaltonetworks.
    Which team or department does the Staff InfoSec Engineer – Endpoint, Identity & AI Security at paloaltonetworks belong to?
    This Staff InfoSec Engineer – Endpoint, Identity & AI Security position is part of the Palo Alto Networks Ltd department at paloaltonetworks. See the full job description for more information about the team structure and responsibilities.
    How do I apply for the Staff InfoSec Engineer – Endpoint, Identity & AI Security position at paloaltonetworks?
    Click the "Apply Now" button on this page. You will be redirected to paloaltonetworks's official application portal hosted on workday where you can submit your application directly.
    When was the Staff InfoSec Engineer – Endpoint, Identity & AI Security job at paloaltonetworks posted?
    This Staff InfoSec Engineer – Endpoint, Identity & AI Security position at paloaltonetworks was posted on Aug 9, 2026. Apply as soon as possible — early applications are often reviewed first.
    Staff InfoSec Engineer – Endpoint, Identity & AI Security
    paloaltonetworks
    Apply for this role ↗

    You'll be redirected to paloaltonetworks's official application page on Workday.