Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
P

Principal Threat Hunter (Unit 42)

Paloaltonetworks
🇺🇸 United States
Remote
Staff / Principal
18 hours ago
  • Palo Alto Networks
  • AI
  • Fabric
  • Threat Intelligence
  • triage
  • Incident Response
  • GCP
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.

Job Summary

ThePrincipal Threat Intelligence Hunter will sit withinUnit 42 Managed Threat Hunting and drive proactive, intelligence-led hunting across customer environments.


This role combines hands-on threat hunting with cyber threat intelligence analysis, helping multinational organizations stay one step ahead of adversaries and cyber threats.


The Principal Cyber Threat Intelligence Hunter will analyze public and private threat intelligence,  track adversary activity & capabilities, engage in rapid response efforts, model frontline incident data, then translate that intelligence into actionable hunting hypotheses, investigation workflows, behavioural profiles, and ultimately targeted customer notifications designed to empower our customers’ response and disrupt adversary activity. 


This role will work across customer telemetry to investigate suspicious activity, validate emerging threats, and contribute to timely, professional reporting. The role will also collaborate closely with threat hunters, detection engineers, incident responders, MDR teams, and Unit 42 intelligence and security researchers to operationalize intelligence quickly and improve hunting outcomes across the service.


Ultimately, this is a proactive, research-driven hunting role for an expert who can connect intelligence with real-world telemetry, maintain ongoing threat tracking while responding to emerging threats, fingerprint attacker behavior, investigate security incidents, mentor peers, and clearly communicate findings.


Your Impact

Help multinational organizations stay one step ahead of adversaries and cyber threats by delivering timely, actionable frontline intelligence.

Help drive the strategic direction of Unit 42 Managed Threat Hunting, combining hands-on threat hunting execution with cyber threat intelligence. 

Assist leadership with triage and evaluation of ongoing campaigns and telemetry findings to inform team priorities.

Keep the Unit 42 Managed Services intelligence flywheel spinning by capturing, modeling, and analyzing frontline incident data within our threat intelligence knowledge base. 

Analyze public and private threat intelligence, Unit 42 research, adversary campaigns, malware activity, infrastructure, indicators, and TTPs.

Translate threat intelligence into actionable hunting hypotheses, investigation workflows, hunting queries, and customer-facing findings.

Execute threat hunting workflows, investigate results, and support timely reporting for the most consequential threats to our Unit 42 Managed Service customers.


Investigate hunting leads based on IOCs, threat intelligence, internal detections, customer telemetry, and emerging adversary behaviors, acting as the primary Subject Matter Expert (SME) for specific threat actor clusters or capabilities.

Leverage and build cutting edge tooling to identify and track adversaries and their capabilities being deployed against our customers. 


Escalate major, unclear, or high-impact security events to the Threat Hunting leadership team and mentor junior hunters through complex, multi-tenant investigations.


Collaborate with other threat hunters, detection engineers, incident responders, MDR, and Unit 42 researchers to operationalize intelligence quickly and effectively.


Provide ongoing feedback on findings, hunting reports, queries, intelligence workflows, and operational processes to support continuous improvement.


Why Choose Us

Leverage a massive set of telemetry, turning frontline incident data into actionable intelligence that catches adversaries. 

Translate emerging threat intelligence into real hunting outcomes across customer environments.


Work across multiple cybersecurity domains, including endpoint, network, cloud, identity, and third-party vendor telemetry.


Shape the future of our operations: You will design our playbooks and processes in a highly collaborative, open minded, global team environment. 


Deliver immediate, tangible impact: Your findings don't just go into a PDF report or IOC feed. You sit at the direct intersection of intelligence and incident response for Unit 42 Managed Services, issuing tactical notifications that disrupt active adversary campaigns.


Own your domain: We carve out a runway for you to build and maintain long-term specialisations, allowing you to track specific infrastructure, threat groups, or capabilities in the background and serve as the Subject Matter Expert.

Join a global team of experts who handle threats and adversaries at scale every day.


Collaborate closely with Unit 42 researchers, incident responders, detection engineers, MDR teams, and experienced threat hunters.

Improve how threat intelligence is operationalized across a managed service operating at scale.


Publish your research: Share your findings under the globally recognized Unit 42 brand. 

Qualifications

  • 8+ years of experience in tactical threat hunting, cyber threat intelligence (CTI), DFIR, or advanced security operations with a proven track record of leading complex investigations and delivering change.
  • Strong background in tactical threat intelligence, specifically identifying the discrete traces, artifacts, and behavioral fingerprints left by adversaries across diverse telemetry sources (endpoint, network, cloud, and identity).
  • Experience capturing and modeling incident data in intelligence platforms/graphs to map out intrusions, understand attacker behaviors, and cluster isolated events into broader campaign tracking. 
  • Proven ability to develop & deliver verbal & written technical findings of attacker behaviour into clear, high-impact notifications for customers.
  • Experience translating threat intelligence into high-fidelity hunting hypotheses, detection logic, and log-based queries.
  • Bonus Points: Experience in an Incident Response Consulting or Managed Security Services environment, proficiency in building AI tooling, experience with GCP, analysis or modelling experience in Vertex Synapse, published security blogs or research that shows a deep understanding of a particular threat or proven adversary disruption. 

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be foundhere.

$163,900.00 - $265,100.00/yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at  accommodations@paloaltonetworks.com.

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

 

 

Principal Threat Hunter (Unit 42) · Paloaltonetworks

Auto apply with Likeremote