Sr Staff Researcher (Agentic AI Systems Security - Prisma AIRS)

$139K - $225K Seattle, WA, US Senior AI/ML Engineer

Interested in this AI/ML Engineer role at Palo Alto Networks?

Apply Now →

Skills & Technologies

Drift AiRag

About This Role

AI job market dashboard showing open roles by category

Santa Clara, California, United States of America

Seattle, Washington, United States of America Product Engineering Ref ID: JR\-020654

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real\-world problems with cutting\-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real\-world problems and ideating beside the best and the brightest, we invite you to join us!

We believe collaboration thrives in person. That’s why most of our teams work from the office full time, with flexibility when it’s needed. This model supports real\-time problem\-solving, stronger relationships, and the kind of precision that drives great outcomes.

Job Summary

About the Team

------------------

Prisma AIRS AI Supply Chain Security owns the full supply\-chain security posture for agentic\-AI systems at Palo Alto Networks, covering the models, artifacts, tools, and extensions that enterprise AI applications are built on. We turn threat research into the scanning and detection capabilities that let customers adopt agentic AI without inheriting its supply\-chain risk.

About the Role

------------------

We are looking for a security engineer to lead threat research and detection strategy for agentic AI systems, in a hands\-on role split across research and engineering. You will model the threat surface across the full agentic stack — agents, skills, MCP servers, and traditional model artifacts, including their configurations and deployment architecture — for both proprietary hosted models and in\-house custom deployments, then build that research into production scanning capabilities and own the services that ship them.

Core Technical Focus \& Ownership

-------------------------------------

You bring systemic fluency in the agentic threat landscape: direct and indirect (cross\-domain) prompt injection, jailbreak and guardrail bypass, instruction\-hierarchy violations, and the agent\-loop failures they enable — excessive agency, goal drift, and memory or RAG poisoning. That extends into the tool and extension layer: MCP tool poisoning, tool shadowing, server rug pulls, OAuth scope and token\-passthrough abuse, and supply\-chain risk in third\-party skills and plugins. Deployment posture matters equally — exposed inference endpoints, least\-privilege tool scoping and ephemeral credentials, insecure output handling, and egress control over the channels that turn a single injection into data loss. In production, you run the pipeline itself: service health, latency and availability targets, release quality, and false\-positive/false\-negative regression gates, with on\-call response and observability as day\-to\-day work.

Qualifications

Impact

----------

  • Shape detection and scanning strategy by identifying the vulnerability, exploit, and attack\-technique areas in the agentic\-AI domain where new or improved protections are needed.
  • Drive innovative detection ideas from concept to production, delivering measurable improvements in coverage, quality, speed, or scalability.
  • Expand the team's ability to deliver protections at scale through practical automation, detection pipeline improvements, and AI\-assisted research workflows.
  • Provide hands\-on technical leadership to researchers and developers through direction, review, problem decomposition, and execution guidance.
  • Influence cross\-functional decisions with product, QA, engineering, and research partners to ensure detections are technically sound, customer\-relevant, and production\-ready.
  • Support the operational excellence of the detection pipeline and other common infrastructure owned by the team.

Qualifications

------------------

  • Deep hands\-on experience in vulnerability research, exploit analysis, offensive security, or closely related threat prevention work.
  • Deep and proven expertise using agentic\-AI systems with an eye for finding loopholes, across both proprietary hosted models and in\-house custom model deployments. Using agentic\-AI practices as tooling and automation to improve security analysis, detection development, validation, or response workflows is highly desirable.
  • Proven ability to identify important technical problems, propose detection ideas, drive execution, and deliver measurable product or customer impact, specifically in the agentic\-AI threat research domain.
  • Deep understanding of common vulnerability classes and exploit techniques \- including memory corruption, injection, authentication bypass, path traversal, SSRF, RCE, XSS, SQL injection, CSRF, MITM, and DoS \- and how these classes resurface through agent tool wrappers, tool parameters, and insecurely handled model output.
  • Strong ability to analyze vulnerability root cause, exploitability, PoC behavior, network traffic, protocol behavior, application\-layer attack patterns, and detection tradeoffs.
  • Experience translating vulnerability or exploit understanding into production\-quality scanning capabilities or other customer\-facing protections.
  • Strong programming or scripting skills for research automation, tooling, test generation, detection development, or pipeline improvements.
  • Ability to lead complex technical work under ambiguity, guide other researchers or developers, and make sound technical decisions under time pressure.
  • Strong communication skills with the ability to influence technical direction across research, product, QA, and engineering partners.
  • BS/MS in Computer Science, Computer Engineering, Cybersecurity, or related field, or equivalent professional experience.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non\-sales roles) or base salary \+ commission target (for sales/com\-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus.

$139,600\.00 \- $225,775\.00/yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at [email protected].

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

Salary Context

This $139K-$225K range is above the median for AI/ML Engineer roles in our dataset (median: $175K across 2162 roles with salary data).

View full AI/ML Engineer salary data →

Role Details

Title Sr Staff Researcher (Agentic AI Systems Security - Prisma AIRS)
Location Seattle, WA, US
Category AI/ML Engineer
Experience Senior
Salary $139K - $225K
Remote No

About This Role

AI/ML Engineers build and deploy machine learning models in production. They work across the full ML lifecycle: data pipelines, model training, evaluation, and serving infrastructure. The role has evolved significantly over the past two years. Where ML Engineers once spent most of their time on model architecture, the job now tilts heavily toward inference optimization, cost management, and integrating LLM capabilities into existing systems. Companies want engineers who can ship production systems, and the experimenter-only role is fading fast.

Day-to-day, you're writing training pipelines, debugging data quality issues, setting up evaluation frameworks, and figuring out why your model performs differently in staging than it did on your dev set. The best ML engineers are obsessive about reproducibility and measurement. They instrument everything. They know that a model is only as good as the data feeding it and the infrastructure serving it.

Across the 4,317 AI roles we're tracking, AI/ML Engineer positions make up 70% of the market. At Palo Alto Networks, this role fits into their broader AI and engineering organization.

Demand for AI/ML Engineers has been strong and consistent. Unlike some AI roles that spike with hype cycles, ML engineering is a foundational need. Every company deploying AI models needs people who can keep them running, and the gap between research prototypes and production systems keeps growing.

What the Work Looks Like

A typical week might include: debugging a data pipeline that's silently dropping 3% of training examples, running A/B tests on a new model version, writing documentation for a feature flag system that lets you roll back model deployments, and reviewing a junior engineer's PR for a new evaluation metric. Meetings tend to be cross-functional since ML touches product, engineering, and data teams.

Demand for AI/ML Engineers has been strong and consistent. Unlike some AI roles that spike with hype cycles, ML engineering is a foundational need. Every company deploying AI models needs people who can keep them running, and the gap between research prototypes and production systems keeps growing.

Skills Required

Drift Ai (2% of roles) Rag (21% of roles)

Python and PyTorch dominate the requirements. Most roles expect experience with cloud platforms (AWS, GCP, or Azure) and familiarity with ML frameworks like TensorFlow or JAX. RAG (Retrieval-Augmented Generation) has become a top-3 skill requirement as companies integrate LLMs into their products. Docker and Kubernetes show up in about a third of postings, reflecting the production focus of the role.

Beyond the core stack, employers increasingly want experience with experiment tracking tools (MLflow, Weights & Biases), feature stores, and vector databases. Fine-tuning experience is valuable but less common than you'd think from reading Twitter. Most production LLM work is RAG and prompt engineering, not fine-tuning. If you have both, you're in a strong position.

Companies that are serious about AI/ML hiring tend to post specific infrastructure details in the job description: the frameworks they use, their model serving stack, their data pipeline tools. Vague postings that just say 'ML experience required' without specifics are often companies that haven't figured out what they need yet.

Compensation Benchmarks

AI/ML Engineer roles pay a median of $214,900 based on 6,420 positions with disclosed compensation. Senior-level AI roles across all categories have a median of $227,400. This role's midpoint ($182K) sits 15% below the category median. Disclosed range: $139K to $225K.

Across all AI roles, the market median is $215,000. Top-quartile compensation starts at $266,300. The 90th percentile reaches $320,790. For comparison, the highest-paying categories include AI Safety ($287,500) and Research Engineer ($272,100). By seniority level: Entry: $110,000; Mid: $194,400; Senior: $227,400; Director: $274,554; VP: $241,000.

Palo Alto Networks AI Hiring

Palo Alto Networks has 7 open AI roles right now. They're hiring across AI/ML Engineer. Positions span Santa Clara, CA, US, Washington, DC, US, Seattle, WA, US. Compensation range: $225K - $308K.

Location Context

AI roles in Seattle pay a median of $228,700 across 516 tracked positions. That's 6% above the national median.

Career Path

Common paths into AI/ML Engineer roles include Data Scientist, Software Engineer, Research Engineer.

From here, career progression typically leads toward ML Architect, AI Engineering Manager, Principal ML Engineer.

The fastest path into ML engineering is through software engineering with a self-directed ML education. A CS degree helps, but production engineering skills matter more than academic credentials. Build something that works, deploy it, and measure it. That portfolio project is worth more than a Coursera certificate. For career growth, the fork comes around the senior level: go deep on technical complexity (staff/principal track) or move into managing ML teams.

What to Expect in Interviews

Expect system design questions around ML pipelines: how you'd build a training pipeline for a specific use case, handle data drift, or design A/B testing infrastructure for model deployments. Coding rounds typically involve Python, with emphasis on data manipulation (pandas, numpy) and algorithm implementation. Take-home assignments often ask you to build an end-to-end ML pipeline from raw data to deployed model.

When evaluating opportunities: Companies that are serious about AI/ML hiring tend to post specific infrastructure details in the job description: the frameworks they use, their model serving stack, their data pipeline tools. Vague postings that just say 'ML experience required' without specifics are often companies that haven't figured out what they need yet.

AI Hiring Overview

The AI job market has 4,317 open positions tracked in our dataset. By seniority: 138 entry-level, 2,071 mid-level, 1,655 senior, and 453 leadership roles (Director, VP, C-Level). Remote roles make up 15% of the market (635 positions). The remaining 3,657 roles require on-site or hybrid attendance.

The market median for AI roles is $215,000. Top-quartile compensation starts at $266,300. The 90th percentile reaches $320,790. Highest-paying categories: AI Safety ($287,500 median, 34 roles); Research Engineer ($272,100 median, 227 roles); AI Engineering Manager ($244,000 median, 23 roles).

Demand for AI/ML Engineers has been strong and consistent. Unlike some AI roles that spike with hype cycles, ML engineering is a foundational need. Every company deploying AI models needs people who can keep them running, and the gap between research prototypes and production systems keeps growing.

The AI Job Market Today

The AI job market spans 4,317 open positions across 15 role categories. The largest categories by volume: AI/ML Engineer (3,004), Data Scientist (345), AI Software Engineer (309). These three account for the majority of open positions, though smaller categories often have higher per-role compensation because of specialized skill requirements.

The seniority mix tells a story about where AI teams are in their maturity. Entry-level roles (138) are outnumbered by mid-level (2,071) and senior (1,655) positions, reflecting that most companies are past the 'build a team from scratch' phase and need experienced engineers who can ship production systems. Leadership roles (Director, VP, C-Level) total 453 positions, representing the bottleneck between technical execution and organizational strategy.

Remote work availability sits at 15% of all AI roles (635 positions), with 3,657 requiring on-site or hybrid attendance. The remote share has stabilized after the post-pandemic correction. Senior and specialized roles (Research Scientist, ML Architect) are more likely to be remote-eligible than entry-level positions, partly because experienced hires have more negotiating power and partly because these roles require less hands-on mentorship.

AI compensation is structured in clear tiers. The market median sits at $215,000. Top-quartile roles start at $266,300, and the 90th percentile reaches $320,790. These figures include base salary with disclosed compensation. Total compensation (including equity, bonuses, and sign-on) runs 20-40% higher at companies that offer those components.

Category matters for compensation. AI Safety roles lead at $287,500 median, while Prompt Engineer roles sit at $145,000. The spread between highest and lowest-paying categories reflects the premium on specialized technical skills versus broader analytical roles.

The most in-demand skills across all AI postings: Python (2,249 postings), Aws (1,224 postings), Azure (938 postings), Rag (915 postings), Gcp (660 postings), Pytorch (640 postings), Prompt Engineering (624 postings), Kubernetes (559 postings). Python dominates, appearing in the vast majority of role descriptions regardless of category. Cloud platform experience (AWS, GCP, Azure) is the second most common requirement. The newer entrants to the top skills list (RAG, vector databases, LLM APIs) reflect the shift from traditional ML toward generative AI applications.

Frequently Asked Questions

Based on 6,420 roles with disclosed compensation, the median salary for AI/ML Engineer positions is $214,900. Actual compensation varies by seniority, location, and company stage.
Python and PyTorch dominate the requirements. Most roles expect experience with cloud platforms (AWS, GCP, or Azure) and familiarity with ML frameworks like TensorFlow or JAX. RAG (Retrieval-Augmented Generation) has become a top-3 skill requirement as companies integrate LLMs into their products. Docker and Kubernetes show up in about a third of postings, reflecting the production focus of the role.
About 15% of the 4,317 AI roles we track offer remote work. Remote availability varies by company and seniority level, with senior and leadership roles more likely to offer location flexibility.
Palo Alto Networks is among the companies actively hiring for AI and ML talent. Check our company profiles for detailed breakdowns of open roles, salary ranges, and hiring trends.
Common next steps from AI/ML Engineer positions include ML Architect, AI Engineering Manager, Principal ML Engineer. Progression depends on whether you lean toward technical depth, people management, or product strategy.

Get Weekly AI Career Intelligence

Salary data, skills demand, and market signals from 16,000+ AI job postings. Every Monday.