Summary
Palo Alto Networks is a cybersecurity company focused on protecting organizations from digital threats. The Threat Hunter Researcher will investigate sophisticated cyber threats, develop and execute threat-hunting methodologies, perform forensic analysis, and deliver research and analysis reports. The role also involves guiding customers, collaborating with research and development teams, and contributing to cybersecurity solutions and industry knowledge.
Responsibilities
- Help multinational organizations stay one step ahead of adversaries and cyber threats
- Collaborate and guide our customers on the best ways to enhance their protection and readiness for future events
- Improve Palo Alto Networks' solutions by identifying and analyzing new threats and tactics
- Influence the industry by sharing knowledge and findings
- Collaborate with multiple research and development groups
- Contribute to making the world a safer and better place
- Perform threat hunting activities on any data source every day
- Deal with the latest cybersecurity research projects and attacks on a daily basis
- Build hypotheses, execute manual hunting techniques, gather and analyze results, perform forensic activities, and deliver reports
- Join a global team of experts who handle threats and adversaries on a global scale daily
- Enhance your knowledge and experience in all domains of cybersecurity: Network, Endpoint, Cloud, IoT, Mobile devices, and 3rd-party vendor data sources
- Develop, create, and execute new hunting hypothesis methodologies to uncover threats, understand their root causes, and attribute them
- We believe in automation and scaling
- Leverage big data to discover threats and multiple threat intelligence
Skills
- Understanding the threat landscape, including attack tools, tactics, and techniques, as well as networking and security fundamentals
- Experience investigating targeted, sophisticated, or hidden threats in both endpoints and networks
- 3+ years of relevant experience with a proven track record in cybersecurity research, specializing in either APTs or cybercrime, but with the ability to address the broader threat landscape
- Background in forensic analysis and incident response tools (both Dynamic and Static, such as IDA Pro, Ollydbg, and Wireshark) to identify threats and assess the extent and scope of compromises
- Understanding of APT operations, including attack vectors, propagation, data exfiltration, lateral movement, persistence mechanisms, and more
- Familiarity with organizational cybersecurity measures, including protective tools and remediation techniques
- Excellent written and oral communication skills in English
- Strong attention to detail
- Knowledge of advanced threat hunting methodologies and the ability to develop novel techniques
- Ability to simplify and clarify complex ideas
- Experience in writing technical blog posts and analysis reports
- Ability to analyze and understand the infrastructure of malicious campaigns
- Self-starter who can work independently and adapt to changing priorities
- Please note that we will not sponsor applicants for work visas for this position
- Experience in an Incident Response environment is a plus
- Proficiency in Python and SQL is beneficial
- Familiarity with reverse engineering is advantageous
Qualifications
Must Haves
- Understanding the threat landscape, including attack tools, tactics, and techniques, as well as networking and security fundamentals
- Experience investigating targeted, sophisticated, or hidden threats in both endpoints and networks
- 3+ years of relevant experience with a proven track record in cybersecurity research, specializing in either APTs or cybercrime, but with the ability to address the broader threat landscape
- Background in forensic analysis and incident response tools (both Dynamic and Static, such as IDA Pro, Ollydbg, and Wireshark) to identify threats and assess the extent and scope of compromises
- Understanding of APT operations, including attack vectors, propagation, data exfiltration, lateral movement, persistence mechanisms, and more
- Familiarity with organizational cybersecurity measures, including protective tools and remediation techniques
- Excellent written and oral communication skills in English
- Strong attention to detail
- Knowledge of advanced threat hunting methodologies and the ability to develop novel techniques
- Ability to simplify and clarify complex ideas
- Experience in writing technical blog posts and analysis reports
- Ability to analyze and understand the infrastructure of malicious campaigns
- Self-starter who can work independently and adapt to changing priorities
- Please note that we will not sponsor applicants for work visas for this position
Nice to Haves
- Experience in an Incident Response environment is a plus
- Proficiency in Python and SQL is beneficial
- Familiarity with reverse engineering is advantageous
Benefits
- This role is remote
- The offered compensation may also include restricted stock units and a bonus.