Summary
Palo Alto Networks is a cybersecurity company focused on protecting digital environments and helping organizations stay ahead of cyber threats. The Threat Hunter Researcher will investigate sophisticated threats, develop and execute threat-hunting methodologies, conduct forensic analysis, collaborate with customers and research teams, and communicate findings through reports and technical content.
Responsibilities
- Help multinational organizations stay one step ahead of adversaries and cyber threats
- Collaborate and guide our customers on the best ways to enhance their protection and readiness for future events
- Improve Palo Alto Networks' solutions by identifying and analyzing new threats and tactics
- Influence the industry by sharing knowledge and findings
- Collaborate with multiple research and development groups
- Contribute to making the world a safer and better place
- Perform threat hunting activities on any data source every day
- Deal with the latest cybersecurity research projects and attacks on a daily basis
- Build hypotheses, execute manual hunting techniques, gather and analyze results, perform forensic activities, and deliver reports
- Join a global team of experts who handle threats and adversaries on a global scale daily
- Enhance your knowledge and experience in all domains of cybersecurity: Network, Endpoint, Cloud, IoT, Mobile devices, and 3rd-party vendor data sources
- Develop, create, and execute new hunting hypothesis methodologies to uncover threats, understand their root causes, and attribute them
- We believe in automation and scaling
- Leverage big data to discover threats and multiple threat intelligence
Skills
- Understanding the threat landscape, including attack tools, tactics, and techniques, as well as networking and security fundamentals
- Experience investigating targeted, sophisticated, or hidden threats in both endpoints and networks
- 3+ years of relevant experience with a proven track record in cybersecurity research, specializing in either APTs or cybercrime, but with the ability to address the broader threat landscape
- Background in forensic analysis and incident response tools (both Dynamic and Static, such as IDA Pro, Ollydbg, and Wireshark) to identify threats and assess the extent and scope of compromises
- Understanding of APT operations, including attack vectors, propagation, data exfiltration, lateral movement, persistence mechanisms, and more
- Familiarity with organizational cybersecurity measures, including protective tools and remediation techniques
- Excellent written and oral communication skills in English
- Strong attention to detail
- Knowledge of advanced threat hunting methodologies and the ability to develop novel techniques
- Ability to simplify and clarify complex ideas
- Experience in writing technical blog posts and analysis reports
- Ability to analyze and understand the infrastructure of malicious campaigns
- Self-starter who can work independently and adapt to changing priorities
- Please note that we will not sponsor applicants for work visas for this position
- Experience in an Incident Response environment is a plus
- Proficiency in Python and SQL is beneficial
- Familiarity with reverse engineering is advantageous
Qualifications
Must Haves
- Understanding the threat landscape, including attack tools, tactics, and techniques, as well as networking and security fundamentals
- Experience investigating targeted, sophisticated, or hidden threats in both endpoints and networks
- 3+ years of relevant experience with a proven track record in cybersecurity research, specializing in either APTs or cybercrime, but with the ability to address the broader threat landscape
- Background in forensic analysis and incident response tools (both Dynamic and Static, such as IDA Pro, Ollydbg, and Wireshark) to identify threats and assess the extent and scope of compromises
- Understanding of APT operations, including attack vectors, propagation, data exfiltration, lateral movement, persistence mechanisms, and more
- Familiarity with organizational cybersecurity measures, including protective tools and remediation techniques
- Excellent written and oral communication skills in English
- Strong attention to detail
- Knowledge of advanced threat hunting methodologies and the ability to develop novel techniques
- Ability to simplify and clarify complex ideas
- Experience in writing technical blog posts and analysis reports
- Ability to analyze and understand the infrastructure of malicious campaigns
- Self-starter who can work independently and adapt to changing priorities
- Please note that we will not sponsor applicants for work visas for this position
Nice to Haves
- Experience in an Incident Response environment is a plus
- Proficiency in Python and SQL is beneficial
- Familiarity with reverse engineering is advantageous
Benefits
- This role is remote
- The offered compensation may also include restricted stock units and a bonus