RecentlyPostedJobs

Sr. Staff Software Engineer (Fedramp)

Palo Alto Networks · On-site · Full-time · Office - USA - CA - Headquarters · United States

Posted

Apply on Palo Alto Networks’s site

Job description

Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place. Who We Are In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us! We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes. Job Summary As an Sr. Staff Software Engineer (FedRAMP) , you will be a critical part of our Engineering team, serving as the technical backbone for our web applications and platform services across strictly governed public sector boundaries. You will be responsible for designing, building, and maintaining secure, scalable full-stack applications—from intuitive, modern frontend interfaces to resilient backend APIs and microservices—while strengthening our security posture across FedRAMP environments. Working closely with Information Security, R&D, DevOps, and internal Support teams, you will combine hands-on full-stack development with rigorous compliance standards to ensure high availability, auditability, and performance across our platform. Key Responsibilities Full-Stack Application Development: Design, develop, test, and maintain secure, responsive frontend interfaces and high-performance backend microservices across governed cloud boundaries. Secure Coding & Enclave Governance: Author clean, maintainable code adhering to OWASP, NIST SP 800-53, and Secure Software Development Framework (SSDF) standards to enforce zero-trust architecture across FedRAMP enclaves. API & Cloud-Native Architecture: Architect, build, and optimize RESTful and gRPC APIs and containerized microservices hosted on Google Cloud Platform (GCP) and Google Kubernetes Engine (GKE). Data & State Management: Design, query, and optimize relational and non-relational database schemas and caching layers utilizing GCP database services (e.g., Cloud SQL, Cloud Spanner, BigQuery) with strict data isolation and auditing. AI-Augmented SDLC & Velocity: Strategically leverage modern AI developer tools and LLM-assisted workflows (e.g., code synthesis, test scaffolding, automated refactoring, and documentation generation) to accelerate delivery cycles and engineering productivity, while ensuring strict adherence to boundary data security and code governance policies. CI/CD Pipeline Security Integration: Collaborate with DevOps teams to secure the software supply chain, integrating automated static and dynamic security scanning (SAST/DAST), dependency checking, and container image signing into CI pipelines. Observability & Telemetry: Instrument applications with structured logging, distributed tracing, and real-time metric tracking using Google Cloud Operations Suite (Cloud Logging/Monitoring) to ensure operational health and continuous audit readiness. Security & Compliance Remediation: Partner directly with the Information Security team to remediate vulnerability scan findings, implement security controls within the application tier, and execute rapid Plan of Action and Milestones (POA&M) resolutions. Internal Support & Escalation Triage: Resolve complex, escalated application-tier production issues routed from internal operations and customer support engineering teams via our Service Management platform, conducting root-cause analysis within secure boundaries. Continuous Improvement & Mentorship: Drive engineering best practices, conduct rigorous code reviews, champion automated testing (unit, integration, and end-to-end), and mentor teammates on modern full-stack development. On-Call Operations & Incident Response: Participate in an on-call rotation to support critical FedRAMP services, responding to high-priority operational incidents, system alerts, and security escalations to maintain SLA availability across regulated environments. TBD Qualifications 8+ years of professional experience building full-stack enterprise web applications in complex, highly regulated cloud environments. Backend Engineering: Proficiency in server-side languages such as Python, Java, or Node.js for architecting resilient RESTful APIs, asynchronous event processing, and microservices. Frontend Engineering: Demonstrated hands-on experience building modern, responsive, and accessible web user interfaces using frameworks like React, Vue.js, or Angular, with solid state-management fundamentals. Cloud Ecosystem (GCP): Solid experience deploying, debugging, and running cloud-native applications on Google Cloud Platform (GCP) and containerized orchestration platforms like Google Kubernetes Engine (GKE). Data Architecture: Practical experience designing, querying, and tuning relational and non-relational databases (e.g., PostgreSQL, MySQL, BigQuery). AI-Assisted Engineering: Practical experience leveraging AI-assisted developer productivity tools (e.g., GitHub Copilot, Gemini Code Assist, Cursor) or LLM-driven workflows to accelerate prototyping, test generation, and code review within enterprise compliance and security boundaries. CI/CD & Supply Chain Security: Experience authoring and securing automated pipelines using GitLab CI or GitHub Actions, Docker container builds, and basic Infrastructure as Code (Terraform). Security & Compliance Foundations: Working familiarity with software security practices required to meet FedRAMP baselines. Clearance & Eligibility: U.S. Citizenship with the ability to successfully pass background investigations required for DoD IL5 and federal boundary access. Preferred Qualifications GCP Certifications: Google Cloud Certified Professional Cloud Developer or Professional Cloud Security Engineer. ITSM & Operational Workflows: Experience investigating application escalations and documenting changes using ServiceNow or similar ITSM platforms. Identity & Zero-Trust: Experience integrating enterprise authentication/authorization protocols (OAuth2, OIDC, SAML, mTLS) and GCP Identity-Aware Proxy (IAP). Compensation Disclosure The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here . $153,700.00 - $248,600.00/yr Our Commitment We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together. We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at [email protected] . Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics. All your information will be kept confidential according to EEO guidelines. Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

Apply on Palo Alto Networks’s site

More from Palo Alto Networks

We are not Palo Alto Networks. The hiring company owns this listing. Reposts of the same requisition id are not shown as new.

All new jobs · Companies we watch · How dates work · Report an error