Principal Product Researcher
Lead Windows threat detection research and EDR sensor development for SMB customers. Requires deep Windows kernel expertise, reverse engineering, EDR bypass testing, and AI-augmented research to build innovative, automated defenses.
About the job
What You’ll Do
- Identify innovative ways to detect Windows OS threats
- Develop cross-platform features that leverage telemetry from common OS subsystems such as file system, memory, process, and network activity
- Research and development of sensor capabilities to provide visibility and detection support for attack techniques across supported Windows OS versions
- Work collaboratively with internal engineering and detection teams to implement detection logic
- Identify and evaluate new telemetry opportunities
- Identify and address gaps in product coverage
- Respond to product escalations
- Perform False Positive and False Negative investigations
- Lead product research initiatives to develop and evaluate security product strategies and technologies
- Coordinate with Product and Engineering teams to integrate and operationalize solutions developed by Threat Operations teams
- Applies AI as a practical part of day-to-day product research work to improve the speed, quality, and impact of research outputs
- Uses AI to support information gathering, analysis, prototyping, and production of clear, decision-useful work products while maintaining accountability for the final output
- Builds and reuses lightweight prompts, templates, or workflows for recurring research tasks rather than relying on one-off use
- Build internal and external technical documentation to educate customers and communicate research findings to adjacent teams about security risks and opportunities
- Mentor and teach technical expertise to advance the broader community
- Promote Huntress’ reputation through media interaction, public speaking, CFPs, CTFs, and blogs
Qualifications
- Expert in Windows OS internals, components, APIs, and design
- Prior experience with Windows OS kernel coding and device drivers
- Experience testing EDRs, bypasses, and evasion techniques
- Comfortable with reverse engineering and using debuggers
- Proficiency in multiple programming/scripting languages, such as C/C++/C#, PowerShell, and Python
- Applies AI to improve research quality, speed, and outputs in day-to-day work
- Commitment to clear documentation of research findings
- Experience with MITRE ATT&CK matrix, SIGMA, Yara, and Elasticsearch/Kibana
What We Offer
- 100% remote work environment
- Generous paid time off policy, including vacation, sick time, and paid holidays
- 12 weeks of paid parental leave
- Highly competitive and comprehensive medical, dental, and vision benefits plans
- 401(k) with a 5% contribution regardless of employee contribution
- Life and Disability insurance plans
- Stock options for all full-time employees
- One-time $500 reimbursement for building/upgrading home office
- Annual allowance for education and professional development assistance
- $75 USD/month digital reimbursement
- Access to the BetterUp platform for coaching, personal, and professional growth
Skills
Windows Os Internals, Kernel Coding, Device Drivers, Edr Testing, Reverse Engineering, Debuggers, C/C++, C#, PowerShell, Python, AI, Mitre Att&Ck, Sigma, Yara, Elasticsearch
Similar jobs
Security Engineering jobsLeads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.
Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.
Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.