Palo Alto Networks Unit 42 logo
Palo Alto Networks Unit 42
Posted 12 days agoVerified live 2d ago

Threat Hunting Researcher (Unit 42)

Brief overview

Remote
UndergradOr in progress
$117k–$189k/yrStated range
3+ yrsMinimum
Threat HuntingIncident InvestigationThreat IntelligenceDetection EngineeringHunting Query DevelopmentLog AnalysisAttacker Behavior AnalysisIncident ResponseMalware AnalysisPythonSQL

About the company

Palo Alto Networks Unit 42 logo
Palo Alto Networks Unit 42crypsisgroup.com

Palo Alto Networks Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization passionate about helping customers more proactively manage cyber risk.

Job description

Summary

Palo Alto Networks is a cybersecurity company focused on protecting digital systems and helping organizations address evolving cyber threats. The Threat Hunting Researcher will conduct threat hunting, investigate indicators of compromise and security incidents, respond to customer requests, monitor emerging campaigns, and escalate high-impact events. The role also supports the Managed Detection and Response team and contributes to improving hunting reports, queries, and workflows.

Responsibilities

  • Serve as a critical line of defense by providing coverage for core threat hunting activities
  • Collaborate with and guide customers by responding to urgent hunting-related requests and suspected security incidents
  • Execute threat hunting reports and workflows, investigate results, and support timely customer reporting
  • Investigate hunting leads based on IOCs, threat intelligence, and internal detections
  • Monitor the threat landscape and prepare initial context for emerging campaigns to enable deeper investigations
  • Ensure timely and appropriate escalation of major or high-impact security events to leadership
  • Provide support and assistance to the Managed Detection and Response (MDR) team for hunting-related activities
  • Provide ongoing feedback on findings, reports, queries, and workflows to support continuous improvement

Skills

  • 3+ years of relevant cybersecurity experience in threat hunting, incident investigation, SOC analysis, detection engineering, DFIR, or MDR
  • Strong understanding of the evolving threat landscape, attack tools, tactics, techniques, and networking/security fundamentals
  • Experience investigating suspicious activity, security incidents, or targeted threats across endpoints, networks, identity, and cloud
  • Ability to work independently, make sound investigative decisions, and escalate findings requiring additional review
  • Experience handling customer-facing security requests, including clear written communication, investigation summaries, and recommendations
  • Understanding of attacker behaviors, including attack vectors, execution, persistence, privilege escalation, lateral movement, and exfiltration
  • Background in writing, modifying, or executing detections, hunting queries, or log-based investigations
  • Familiarity with organizational cybersecurity measures, including protective tools, response actions, and remediation techniques
  • Excellent written and oral communication skills in English, with strong attention to detail for documenting investigation logic
  • Proficiency in Python and SQL
  • Experience in an Incident Response environment
  • Familiarity with malware analysis
  • Experience writing technical reports, investigation summaries, or customer-facing security analysis
  • Ability to analyze and understand the infrastructure, behaviors, and objectives of malicious campaigns

Qualifications

Must Haves

  • 3+ years of relevant cybersecurity experience in threat hunting, incident investigation, SOC analysis, detection engineering, DFIR, or MDR
  • Strong understanding of the evolving threat landscape, attack tools, tactics, techniques, and networking/security fundamentals
  • Experience investigating suspicious activity, security incidents, or targeted threats across endpoints, networks, identity, and cloud
  • Ability to work independently, make sound investigative decisions, and escalate findings requiring additional review
  • Experience handling customer-facing security requests, including clear written communication, investigation summaries, and recommendations
  • Understanding of attacker behaviors, including attack vectors, execution, persistence, privilege escalation, lateral movement, and exfiltration
  • Background in writing, modifying, or executing detections, hunting queries, or log-based investigations
  • Familiarity with organizational cybersecurity measures, including protective tools, response actions, and remediation techniques
  • Excellent written and oral communication skills in English, with strong attention to detail for documenting investigation logic
  • Proficiency in Python and SQL

Nice to Haves

  • Experience in an Incident Response environment
  • Familiarity with malware analysis
  • Experience writing technical reports, investigation summaries, or customer-facing security analysis
  • Ability to analyze and understand the infrastructure, behaviors, and objectives of malicious campaigns

Benefits

  • This role is remote
  • The offered compensation may also include restricted stock units and a bonus

More jobs like this