Skip to content

Sr. Threat Researcher

Senior Threat Researcher analyzes large-scale security datasets to identify attacker TTPs, maps threats to MITRE ATT&CK, and collaborates with product teams to enhance detection, risk insights, and segmentation strategies at a cybersecurity firm. Requires 5+ years in threat research or related fields.

170k – 196kSunnyvale, CASecurity EngineeringOnsite5+ YOE

About the role

Responsibilities

Threat Research and Analysis

  • Analyze large-scale security datasets to identify attacker behaviors, patterns, TTPs, and emerging risks.
  • Map observed behaviors to the MITRE ATT&CK framework and real-world adversary tradecraft.
  • Leverage the security graph to model attack paths and uncover opportunities to reduce the risk of lateral movement.
  • Identify gaps in detection coverage, data enrichment, and segmentation effectiveness.
  • Develop and validate hypotheses about evolving threats using research and intelligence sources.

Product Impact and Innovation

  • Partner closely with Product and Engineering teams to translate research findings into concrete improvements: enhanced detection logic and analytics, improved data tagging, enrichment, and graph quality, more actionable customer-facing risk insights.
  • Recommend segmentation strategies and policy improvements to strengthen breach containment and limit lateral movement.
  • Contribute to internal threat models and risk frameworks that directly inform product roadmap decisions.

Strategic Guidance and Thought Leadership

  • Provide expert guidance on emerging threats observable in our platform and their implications for customers.
  • Support product, sales, and customer-facing teams with research-backed insights and threat context.
  • Contribute to internal research, patents, and future external publications as the function matures.
  • Track global adversary evolution to help shape long-term detection and risk strategies.

Requirements

  • 5+ years of experience in threat research, incident response, detection engineering, or adversary emulation.
  • Strong understanding of attacker tradecraft across enterprise, cloud, and hybrid environments.
  • Deep familiarity with the MITRE ATT&CK framework and real-world TTP mapping.
  • Hands-on experience working with security telemetry sources.
  • Excellent written and verbal communication skills, with the ability to translate complex findings into clear, actionable insights.
  • Comfort working in ambiguous environments and helping define new functions.
  • Experience writing detection rules, analytics queries, or conducting threat hunting.

Preferred Qualifications

  • 7–10+ years in threat intelligence or security research roles.
  • Experience analyzing security graphs or graph-based analytics for threat detection.
  • Background in network segmentation, zero-trust architecture, or micro-segmentation.
  • Proven ability to influence product development in a fast-paced environment.

Bonus Points:

  • Previous experience at a cybersecurity product company.
  • Track record of publishing threat research or speaking at industry conferences.
  • Experience integrating external threat intelligence feeds.
  • Relevant certifications (e.g., GCIH, GCFA, or similar).

Skills

Mitre Att&CkThreat IntelligenceDetection EngineeringSecurity TelemetryTtp MappingThreat HuntingDetection RulesSecurity GraphsNetwork SegmentationZero TrustAdversary EmulationThreat Research

Senior Offensive Security Engineer

Lead red and purple team engagements to test Huntress' defenses against advanced adversaries. Perform penetration testing, social engineering, and collaborate with security teams to improve detection and response.

170k – 185kUnited StatesSecurity EngineeringRemote3+ YOEAWSAzure

Senior Engineer, Container Security

Develops container security solutions for Zero Trust Segmentation in Kubernetes ecosystems, enhancing platforms like Istio and EKS. Requires 5+ years in distributed systems, proficiency in Go/Python/Java, and strong networking expertise; involves mentoring and customer collaboration.

170k – 196kSunnyvale, CASecurity EngineeringOn-site5+ YOEGoAks

Senior Engineer, Cloud Security

Develops containerized microservices in Go for cloud security platform, processing real-time telemetry from AWS/Azure/GCP to deliver insights and recommendations. Requires 4+ years distributed systems experience, Kubernetes, and cloud APIs; mentors juniors.

170k – 196kSunnyvale, CASecurity EngineeringOn-site4+ YOEGoSQL

Sr. Software Engineer, Cloud Security

Develops containerized microservices in Go for Illumio's cloud security platform, processing real-time cloud telemetry for threat insights and recommendations. Requires 4+ years in distributed systems, Kubernetes, major cloud providers (AWS/Azure/GCP), and mentors junior engineers. Onsite in Sunnyvale, CA.

170k – 196kSunnyvale, CASecurity EngineeringOn-site4+ YOEGoSQL

Software Engineer - Security Platform

Build and operate secure distributed systems for secrets/key management, PKI, and machine identity across Cloudflare's global network. Requires 8+ years experience in software development, distributed systems, and security implementation.

168k – 275kAustin, TX +5Security EngineeringHybrid8+ YOEGoPki