
Sr. Staff Enterprise Security Engineer (InfoSec)
- תל אביב
- משרה קבועה
- משרה מלאה
Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.Who We AreWe take our mission of protecting the digital way of life seriously. We are relentless in protecting our customers and we believe that the unique ideas of every member of our team contributes to our collective success. Our values were crowdsourced by employees and are brought to life through each of us everyday - from disruptive innovation and collaboration, to execution. From showing up for each other with integrity to creating an environment where we all feel included.As a member of our team, you will be shaping the future of cybersecurity. We work fast, value ongoing learning, and we respect each employee as a unique individual. Knowing we all have different needs, our development and personal wellbeing programs are designed to give you choice in how you are supported. This includes our FLEXBenefits wellbeing spending account with over 1,000 eligible items selected by employees, our mental and financial health resources, and our personalized learning opportunities - just to name a few!Job DescriptionYour CareerPalo Alto Networks is disrupting the Cyber Security industry! We are looking for a Senior Enterprise Information Security Engineer to join our Infosec team that owns, securing and delivering security for our Enterprise, SaaS, and Public Cloud security services. With your networking, firewall, cloud, and development skills, you’ll design, build automation and integrate along with our secure programs – scale and secure our infrastructure and application in a Google Cloud Platform environment as well as collaborate with other team members. In this role, you will provide technical leadership in the development of Security programs by helping to drive the disruptive vision, technology planning, and estimation. If you are a fast learner and passionate about Cyber Security, this is a great opportunity for youYour Impact
- Providing advanced operations and engineering support for critical systems and services, including application and security infrastructure on-prem and in the cloud.
- Responsible for assessing and reviewing the security and cloud infrastructure in both IT and production environments.
- Coordinates with various teams to ensure appliances and services are configured with the correct posture to support business requirements.
- In-depth knowledge of designing and implementing a Zero Trust Network Architecture, including network and identity segmentation.
- Continuous monitoring and improvement of IT support practices to enhance scalability, reliability, and performance in the product infrastructure.
- Assist in maintaining strong oversight of cloud computing solutions to safeguard against undue risks from third-party or external integrations.
- Develop automation using SOAR tools to streamline repetitive tasks and improve the overall efficiency of the security team.
- Collaborate with teams outside the Security Fusion Center, including Vulnerability Management, Network Engineering, OS Engineering, and product SRE.
- Prioritize and respond to critical vulnerabilities and data exposures with urgency and effective risk mitigation strategies.
- Develop and maintain security baselines for infrastructure components (e.g., VMs, containers, network devices) in alignment with CIS Benchmarks, NIST, and internal standards.
- Support incident response activities, including containment, forensic investigation, root cause analysis, and post-incident documentation.
- Perform regular policy and firewall rule reviews to ensure alignment with access requirements and enforcement of Zero Trust principles.
- Contribute to governance, risk, and compliance (GRC) efforts, including audit participation, third-party risk assessments, and evidence collection for SOC 2, ISO 27001, or FedRAMP certifications.
- 8-10 years of hands-on experience in the Network and Infrastructure security technologies.
- 5+ years of experience with firewall technologies, including deep expertise with Palo Alto Networks Next-Generation Firewalls (NGFW) and security rule evaluation.
- 5+ years of experience managing and securing cloud environments across AWS, GCP, and Microsoft Azure, with knowledge of native security tools and multi-cloud architectures.
- Proven ability to design, build, and maintain scalable cloud infrastructure and secure cloud-native applications, leveraging infrastructure-as-code (IaC) principles.
- Strong working knowledge of IP networking, including routing, switching, VPNs, DNS, NAT, load balancing, and wireless for both on-prem and cloud environments.
- Proficient in virtualization platforms such as VMware, with experience securing virtualized and hybrid workloads.
- Experience working with REST APIs, automation scripting using Python or Go, and integration of security workflows into infrastructure tools.
- Ability to evaluate and optimize firewall rules and access control policies across complex environments, aligning with Zero Trust and least privilege models.
- Solid foundation in certificate management and PKI, including experience issuing and renewing certificates, managing key lifecycles, and enforcing secure communication using TLS and mutual authentication.
- Strong experience with OS-level security hardening and configuration management across Linux (RHEL, Ubuntu) and Windows Server, including patching, log monitoring, enforcing CIS/NIST baselines, and secure user access controls.
- Proficient in managing and securing Microsoft Active Directory (AD) environments, including Group Policy, LDAP integrations, role-based access control (RBAC), and identity federation for hybrid cloud architectures.
- Self-motivated, strong troubleshooting skills, and capable of working independently in fast-paced environments with minimal supervision.
- Strong communication skills with the ability to collaborate effectively with cross-functional teams, including network operations, cloud infrastructure, IAM, and compliance.
- CISSP, AWS , GCP certifications preferred.
- PCNSE certification is a plus.