Principal Consultant, Offensive Security, Proactive Services

3 days ago


Sydney, New South Wales, Australia Palo Alto Networks Full time $120,000 - $250,000 per year

Our Mission
At Palo Alto Networks everything starts and ends with our mission:

Being the cybersecurity partner of choice, protecting our digital way of life.

Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we're looking for innovators who are as committed to shaping the future of cybersecurity as we are.

Who We Are
We believe collaboration thrives in person. That's why most of our teams work from the office full time, with flexibility when it's needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

Job Description
Your Career
The Principal Consultant on the Offensive Security team is focused on assessing and challenging the security posture across a comprehensive portfolio of clients. The individual will have experience leading Red & Purple team engagements. They will be the client's advocate for cybersecurity best practices related to offensive security and will provide strong recommendations in this domain.

Your Impact

  • Performs client penetration testing to find any vulnerabilities or weaknesses that might be exploited by a malicious party, using open-source, custom, and commercial testing tools - Red Team experience essential
  • Ability to assist in scoping engagements by clearly articulating various penetration approaches and methodologies to audiences ranging from highly technical to executive personnel
  • Report generation that clearly communicates testing and assessment details, results, and remediation recommendations to clients
  • Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements
  • Conducts periodic scans of networks to find and detect vulnerabilities
  • Conducts IT application testing, cybersecurity tool and systems analysis, system and network administration, and systems engineering support for the sustainment of information technology systems (mobile application testing, penetration testing, application, security, and hardware testing)
  • Conduct threat hunting and/or compromise assessment engagements to identify active or dormant indicators of compromise (IoCs) using Crypsis and Palo Alto Networks' threat hunting tools (and/or client owned hunting instrumentation where applicable)
  • Conduct cloud penetration testing engagements to assess specific workloads (i.e., AWS, GCP, Azure, containers, or other PaaS and SaaS instances) for vulnerabilities and subsequently attempt to exploit identified weakness after receiving permission from client stakeholders
  • Provide recommendations to clients on specific security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks including response and recovery of a data security breach
  • Ability to perform travel requirements as needed to meet business demands

Qualifications
Your Experience

  • 6+ years of professional experience leading Red & Purple team engagements, Advanced Attack Simulations, OSINT research, social engineering techniques, bespoke security assessments and exploit development
  • Experience testing a range of technologies (Active Directory, major OSs, cloud environments, IoT / OT) and using a range of security tools and technologies inc AI-enabled to automate and tailor engagements
  • Demonstrate a deep understanding of how malicious software works (i.e.-malware, trojans, rootkits, etc.)
  • Ability to modify known and/or craft custom exploits manually without dependence on consumer tools such as Metasploit
  • Strong knowledge of tools and techniques used to conduct network, wireless, and web application penetration testing
  • Familiarity with web application penetration testing and code auditing to find security gaps and vulnerabilities
  • Experience with penetration testing, administering, and troubleshooting major flavors of Linux, Windows, and major cloud IaaS, PaaS, and SaaS providers (i.e., AWS, GCP, and Azure)
  • Experience with scripting and editing existing code and programming using one or more of the following - Perl, Python, ruby, bash, C/C++, C#, or Java
  • Experience with security assessment tools, including Nessus, OpenVAS, MobSF Metasploit, Burp Suite Pro, Cobalt Strike, Bloodhound, and Empire
  • Knowledge of application, database, and web server design and implementation
  • Knowledge of network vulnerability assessments, web and cloud application security testing, network penetration testing, red teaming, security operations, or 'hunt'
  • Knowledge of open security testing standards and projects, including OWASP & MITRE ATT&CK
  • Ability to read and use the results of mobile code, malicious code, and anti-virus software
  • Knowledge of computer forensic tools, technologies, and methods
  • Assist in the development of internal infrastructure design for research, development, and testing focused on offensive security
  • Identified ability to grow into a valuable contributor to the practice and, specifically
  • Develop an external presence via public speaking, conferences, and/or publications
  • Have credibility, executive presence, and gravitas
  • Able to have a meaningful delivery contribution
  • Have the potential and capacity to understand all aspects of the business and an excellent understanding of PANW products
  • Collaborative and able to build relationships internally, externally, and across all PANW functions, including the account teams
  • Bachelor's Degree in Information Security, Computer Science, Digital Forensics, Cyber Security, or equivalent years of professional experience to meet job requirements and expectations or equivalent military experience required
  • Hold industry leading certifications from OffSec (OSCE / OSCP / OSWP etc), CREST, GIAC (SANS), and preferably published vulnerabilities, competition winners, conference talks, and published papers or thought leadership

Additional Information
The Team
Our Unit 42 organization is dynamic, high-energy, and highly collaborative. If you have an inner entrepreneurial spirit, are comfortable working in fast-paced environments, and yearn for hands-on impact, then this organization is the right one for you. As a member of the Unit 42 team, you will be one of the founding members of a newly formed team responsible for the successful adoption of purchased offerings and driving the increased up-sell of additional services/products. We are looking for experienced SaaS sales or customer success professionals, ideally with cybersecurity domain expertise, who want to make an impact in a fast-paced, high-growth environment.

Our Commitment
We're problem solvers that take risks and challenge cybersecurity's status quo. It's simple: we can't accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.



  • Sydney, New South Wales, Australia Decipher Bureau Full time $120,000 - $180,000 per year

    Offensive Security, Senior ManagerSydney | Remote-firstWe're partnering with one of Australia's top offensive security teams who are expanding their team. This is your chance to step into a senior leadership role within a high-performing cyber practice that delivers complex offensive security programs across enterprise and critical environments. You'll work...


  • Sydney, New South Wales, Australia Cyberlinx Full time $120,000 - $180,000 per year

    Cyberlinx | Full-Time | (Sydney)Cyberlinx is a fast-growing, pure-play cybersecurity consultancy delivering high-impact work across enterprise, government, and critical infrastructure. We're looking for a highly skilled Senior Security Consultant to be part of our Offensive Security team.About the RoleAs our Senior Security Consultant, you'll work on a...


  • Sydney, New South Wales, Australia Phronesis Security Full time $80,000 - $120,000 per year

    Phronesis Security is Australia's first B Corp certified cyber security company, committed to delivering world-class cyber security consulting with a tangible social and environmental impact. To do so, we have built sharing our profits with some of Australia's highest impact charities into our core operating model.We provide tailored, pragmatic advice,...


  • Sydney, New South Wales, Australia Microsoft Full time $120,000 - $180,000 per year

    Senior Security Researcher and penetration tester to help evaluate and perform offensive security operations against our M365 Copilot suite of products. You will perform research with your team to identify and validate vulnerabilities from external research as well as proactive engagements. AI agent security as well as M365 chat security will be in areas of...


  • Sydney, New South Wales, Australia Cybertify Full time $120,000 - $180,000 per year

    About CybertifyCybertify is Australia's premier compliance-first cybersecurity consulting firm, proudly Australian owned, fully independent, and sovereign in every respect. We specialise in protecting and enabling organisations in the country's most heavily regulated sectors: financial services, superannuation, legal, aged care, healthcare, banking,...


  • Sydney, New South Wales, Australia Microsoft Full time $120,000 - $180,000 per year

    We are a team in M365 Core called Substrate; we have the massive responsibility and charter to help ensure the security and trustworthiness of M365 product suite. We want to reshape and modernize security to empower every user, customer, and developer with a secure cloud that protects them with end-to-end via our solutions. The M365 Substrate organization...


  • Sydney, New South Wales, Australia Preacta Full time $70,000 - $120,000 per year

    Senior or Principal Cyber Security Recruitment ConsultantLocation:Sydney CBDHybrid:3 days in the office, 2 days WFHAbout Preacta:Preacta; derived from the ability to pre-empt and act, ahead of the game.Passionate about digital, technology and sales, we have been partnering with some of the world's fastest growing and most innovative technology businesses...


  • Sydney, New South Wales, Australia Nexon Asia Pacific Pty Ltd Full time $120,000 - $180,000 per year

    Nexon is looking to for a highly experienced Principal Cyber Security Consultant. You will play a crucial role in driving our cybersecurity practice initiatives. You will leverage your deep knowledge and experience in designing and implementing security technologies, including F5, Palo Alto, Fortinet, Cisco, Checkpoint, and others, to engage with our...

  • Security Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Canva Full time $120,000 - $200,000 per year

    Company DescriptionJoin the team redefining how the world experiences design.Hey, g'day, mabuhay, kia ora, 你好, hallo, vítejteThanks for stopping by. We know job hunting can be a little time-consuming, and you're probably keen to find out what's on offer, so we'll get straight to the point.Where And How You Can WorkOur flagship campus is in Sydney. We...

  • Security Consultant

    1 week ago


    Sydney, New South Wales, Australia IPP Consulting Pty LTD Full time $60,000 - $120,000 per year

    Security Consultant - Entry Level - SydneyTo apply, please forward your resume to About IPPAt IPP, we specialise in delivering intelligent, integrated security solutions for some of the most prestigious clients across government, defence, critical infrastructure, and commercial sectors. Our work spans high-security environments where discretion, precision,...