Palo Alto Networks logo
Palo Alto Networks
Posted 11 days agoVerified live 2d ago

Threat Hunting Researcher (Unit 42)

Brief overview

Remote
UndergradOr in progress
$117k–$189k/yrStated range
3+ yrsMinimum
1,547 H-1B approvalsDept. of Labor
577 green cardsCertified filings
Threat HuntingIncident InvestigationCybersecurity Threat IntelligenceDetection EngineeringDigital Forensics and Incident Response (DFIR)Security Operations Center (SOC) AnalysisThreat Detection and Hunting QueriesLog-Based InvestigationPythonSQLMalware Analysis

About the company

Palo Alto Networks logo
Palo Alto Networkspaloaltonetworks.com

Palo Alto Networks is a cybersecurity company that offers cybersecurity solutions for organizations.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
1,547H-1B approved
98%approval rate
211new H-1B hires
577PERM certified
$184,662median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
2023371
2024464
2025582
2026130
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
2023115
2024117
202597
202679
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
2023126
2024121
2025325
20265
Top sponsored roles
Principal Engineer SoftwarePrincipal Software EngineerSenior Staff Software EngineerSenior Staff Engineer SoftwareSenior Technical Support Engineer, Focused Services
Sponsored employees from
IndiaChinaPakistanAustraliaVietnam

Job description

Summary

Palo Alto Networks is a cybersecurity company focused on protecting digital life and helping organizations address evolving cyber threats. The Threat Hunting Researcher will investigate threat-hunting leads, suspicious activity, and security incidents using indicators of compromise, threat intelligence, and internal detections, while supporting customers and the Managed Detection and Response team. The role also includes monitoring emerging campaigns, escalating high-impact events, and improving hunting reports, queries, and workflows.

Responsibilities

  • Serve as a critical line of defense by providing coverage for core threat hunting activities
  • Collaborate with and guide customers by responding to urgent hunting-related requests and suspected security incidents
  • Execute threat hunting reports and workflows, investigate results, and support timely customer reporting
  • Investigate hunting leads based on IOCs, threat intelligence, and internal detections
  • Monitor the threat landscape and prepare initial context for emerging campaigns to enable deeper investigations
  • Ensure timely and appropriate escalation of major or high-impact security events to leadership
  • Provide support and assistance to the Managed Detection and Response (MDR) team for hunting-related activities
  • Provide ongoing feedback on findings, reports, queries, and workflows to support continuous improvement

Skills

  • • 3+ years of relevant cybersecurity experience in threat hunting, incident investigation, SOC analysis, detection engineering, DFIR, or MDR
  • • Strong understanding of the evolving threat landscape, attack tools, tactics, techniques, and networking/security fundamentals
  • • Experience investigating suspicious activity, security incidents, or targeted threats across endpoints, networks, identity, and cloud
  • • Ability to work independently, make sound investigative decisions, and escalate findings requiring additional review
  • • Experience handling customer-facing security requests, including clear written communication, investigation summaries, and recommendations
  • • Understanding of attacker behaviors, including attack vectors, execution, persistence, privilege escalation, lateral movement, and exfiltration
  • • Background in writing, modifying, or executing detections, hunting queries, or log-based investigations
  • • Familiarity with organizational cybersecurity measures, including protective tools, response actions, and remediation techniques
  • • Excellent written and oral communication skills in English, with strong attention to detail for documenting investigation logic
  • • Experience in an Incident Response environment
  • • Proficiency in Python and SQL
  • • Familiarity with malware analysis
  • • Experience writing technical reports, investigation summaries, or customer-facing security analysis
  • • Ability to analyze and understand the infrastructure, behaviors, and objectives of malicious campaigns

Qualifications

Must Haves

  • • 3+ years of relevant cybersecurity experience in threat hunting, incident investigation, SOC analysis, detection engineering, DFIR, or MDR
  • • Strong understanding of the evolving threat landscape, attack tools, tactics, techniques, and networking/security fundamentals
  • • Experience investigating suspicious activity, security incidents, or targeted threats across endpoints, networks, identity, and cloud
  • • Ability to work independently, make sound investigative decisions, and escalate findings requiring additional review
  • • Experience handling customer-facing security requests, including clear written communication, investigation summaries, and recommendations
  • • Understanding of attacker behaviors, including attack vectors, execution, persistence, privilege escalation, lateral movement, and exfiltration
  • • Background in writing, modifying, or executing detections, hunting queries, or log-based investigations
  • • Familiarity with organizational cybersecurity measures, including protective tools, response actions, and remediation techniques
  • • Excellent written and oral communication skills in English, with strong attention to detail for documenting investigation logic

Nice to Haves

  • • Experience in an Incident Response environment
  • • Proficiency in Python and SQL
  • • Familiarity with malware analysis
  • • Experience writing technical reports, investigation summaries, or customer-facing security analysis
  • • Ability to analyze and understand the infrastructure, behaviors, and objectives of malicious campaigns

Benefits

  • This role is remote.
  • The offered compensation may also include restricted stock units and a bonus.

More jobs like this