Summary
Palo Alto Networks is a cybersecurity company focused on protecting digital life and helping organizations address evolving cyber threats. The Threat Hunting Researcher will investigate threat-hunting leads, suspicious activity, and security incidents using indicators of compromise, threat intelligence, and internal detections, while supporting customers and the Managed Detection and Response team. The role also includes monitoring emerging campaigns, escalating high-impact events, and improving hunting reports, queries, and workflows.
Responsibilities
- Serve as a critical line of defense by providing coverage for core threat hunting activities
- Collaborate with and guide customers by responding to urgent hunting-related requests and suspected security incidents
- Execute threat hunting reports and workflows, investigate results, and support timely customer reporting
- Investigate hunting leads based on IOCs, threat intelligence, and internal detections
- Monitor the threat landscape and prepare initial context for emerging campaigns to enable deeper investigations
- Ensure timely and appropriate escalation of major or high-impact security events to leadership
- Provide support and assistance to the Managed Detection and Response (MDR) team for hunting-related activities
- Provide ongoing feedback on findings, reports, queries, and workflows to support continuous improvement
Skills
- • 3+ years of relevant cybersecurity experience in threat hunting, incident investigation, SOC analysis, detection engineering, DFIR, or MDR
- • Strong understanding of the evolving threat landscape, attack tools, tactics, techniques, and networking/security fundamentals
- • Experience investigating suspicious activity, security incidents, or targeted threats across endpoints, networks, identity, and cloud
- • Ability to work independently, make sound investigative decisions, and escalate findings requiring additional review
- • Experience handling customer-facing security requests, including clear written communication, investigation summaries, and recommendations
- • Understanding of attacker behaviors, including attack vectors, execution, persistence, privilege escalation, lateral movement, and exfiltration
- • Background in writing, modifying, or executing detections, hunting queries, or log-based investigations
- • Familiarity with organizational cybersecurity measures, including protective tools, response actions, and remediation techniques
- • Excellent written and oral communication skills in English, with strong attention to detail for documenting investigation logic
- • Experience in an Incident Response environment
- • Proficiency in Python and SQL
- • Familiarity with malware analysis
- • Experience writing technical reports, investigation summaries, or customer-facing security analysis
- • Ability to analyze and understand the infrastructure, behaviors, and objectives of malicious campaigns
Qualifications
Must Haves
- • 3+ years of relevant cybersecurity experience in threat hunting, incident investigation, SOC analysis, detection engineering, DFIR, or MDR
- • Strong understanding of the evolving threat landscape, attack tools, tactics, techniques, and networking/security fundamentals
- • Experience investigating suspicious activity, security incidents, or targeted threats across endpoints, networks, identity, and cloud
- • Ability to work independently, make sound investigative decisions, and escalate findings requiring additional review
- • Experience handling customer-facing security requests, including clear written communication, investigation summaries, and recommendations
- • Understanding of attacker behaviors, including attack vectors, execution, persistence, privilege escalation, lateral movement, and exfiltration
- • Background in writing, modifying, or executing detections, hunting queries, or log-based investigations
- • Familiarity with organizational cybersecurity measures, including protective tools, response actions, and remediation techniques
- • Excellent written and oral communication skills in English, with strong attention to detail for documenting investigation logic
Nice to Haves
- • Experience in an Incident Response environment
- • Proficiency in Python and SQL
- • Familiarity with malware analysis
- • Experience writing technical reports, investigation summaries, or customer-facing security analysis
- • Ability to analyze and understand the infrastructure, behaviors, and objectives of malicious campaigns
Benefits
- This role is remote.
- The offered compensation may also include restricted stock units and a bonus.