HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    PA

    Palo Alto Networks

    Cybersecurity

    Principal Threat Hunter (Unit 42)

    Remote - USA - WA, United StatesFull-time8+ yrs experiencePosted 1w ago
    All Palo Alto Networks jobs

    Job description

    Our Mission

    At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

    Who We Are

    In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

    This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.

    Job Summary

    The Principal Threat Intelligence Hunter will sit within Unit 42 Managed Threat Hunting and drive proactive, intelligence-led hunting across customer environments.

    This role combines hands-on threat hunting with cyber threat intelligence analysis, helping multinational organizations stay one step ahead of adversaries and cyber threats.

    The Principal Cyber Threat Intelligence Hunter will analyze public and private threat intelligence,  track adversary activity & capabilities, engage in rapid response efforts, model frontline incident data, then translate that intelligence into actionable hunting hypotheses, investigation workflows, behavioural profiles, and ultimately targeted customer notifications designed to empower our customers’ response and disrupt adversary activity. 

    This role will work across customer telemetry to investigate suspicious activity, validate emerging threats, and contribute to timely, professional reporting. The role will also collaborate closely with threat hunters, detection engineers, incident responders, MDR teams, and Unit 42 intelligence and security researchers to operationalize intelligence quickly and improve hunting outcomes across the service.

    Ultimately, this is a proactive, research-driven hunting role for an expert who can connect intelligence with real-world telemetry, maintain ongoing threat tracking while responding to emerging threats, fingerprint attacker behavior, investigate security incidents, mentor peers, and clearly communicate findings.

    Your Impact

    Help multinational organizations stay one step ahead of adversaries and cyber threats by delivering timely, actionable frontline intelligence.

    Help drive the strategic direction of Unit 42 Managed Threat Hunting, combining hands-on threat hunting execution with cyber threat intelligence. 

    Assist leadership with triage and evaluation of ongoing campaigns and telemetry findings to inform team priorities.

    Keep the Unit 42 Managed Services intelligence flywheel spinning by capturing, modeling, and analyzing frontline incident data within our threat intelligence knowledge base. 

    Analyze public and private threat intelligence, Unit 42 research, adversary campaigns, malware activity, infrastructure, indicators, and TTPs.

    Translate threat intelligence into actionable hunting hypotheses, investigation workflows, hunting queries, and customer-facing findings.

    Execute threat hunting workflows, investigate results, and support timely reporting for the most consequential threats to our Unit 42 Managed Service customers.

    Investigate hunting leads based on IOCs, threat intelligence, internal detections, customer telemetry, and emerging adversary behaviors, acting as the primary Subject Matter Expert (SME) for specific threat actor clusters or capabilities.

    Leverage and build cutting edge tooling to identify and track adversaries and their capabilities being deployed against our customers. 

    Escalate major, unclear, or high-impact security events to the Threat Hunting leadership team and mentor junior hunters through complex, multi-tenant investigations.

    Collaborate with other threat hunters, detection engineers, incident responders, MDR, and Unit 42 researchers to operationalize intelligence quickly and effectively.

    Provide ongoing feedback on findings, hunting reports, queries, intelligence workflows, and operational processes to support continuous improvement.

    Why Choose Us

    Leverage a massive set of telemetry, turning frontline incident data into actionable intelligence that catches adversaries. 

    Translate emerging threat intelligence into real hunting outcomes across customer environments.

    Work across multiple cybersecurity domains, including endpoint, network, cloud, identity, and third-party vendor telemetry.

    Shape the future of our operations: You will design our playbooks and processes in a highly collaborative, open minded, global team environment. 

    Deliver immediate, tangible impact: Your findings don't just go into a PDF report or IOC feed. You sit at the direct intersection of intelligence and incident response for Unit 42 Managed Services, issuing tactical notifications that disrupt active adversary campaigns.

    Own your domain: We carve out a runway for you to build and maintain long-term specialisations, allowing you to track specific infrastructure, threat groups, or capabilities in the background and serve as the Subject Matter Expert.

    Join a global team of experts who handle threats and adversaries at scale every day.

    Collaborate closely with Unit 42 researchers, incident responders, detection engineers, MDR teams, and experienced threat hunters.

    Improve how threat intelligence is operationalized across a managed service operating at scale.

    Publish your research: Share your findings under the globally recognized Unit 42 brand. 

    Qualifications

    • 8+ years of experience in tactical threat hunting, cyber threat intelligence (CTI), DFIR, or advanced security operations with a proven track record of leading complex investigations and delivering change.
    • Strong background in tactical threat intelligence, specifically identifying the discrete traces, artifacts, and behavioral fingerprints left by adversaries across diverse telemetry sources (endpoint, network, cloud, and identity).
    • Experience capturing and modeling incident data in intelligence platforms/graphs to map out intrusions, understand attacker behaviors, and cluster isolated events into broader campaign tracking. 
    • Proven ability to develop & deliver verbal & written technical findings of attacker behaviour into clear, high-impact notifications for customers.
    • Experience translating threat intelligence into high-fidelity hunting hypotheses, detection logic, and log-based queries.
    • Bonus Points: Experience in an Incident Response Consulting or Managed Security Services environment, proficiency in building AI tooling, experience with GCP, analysis or modelling experience in Vertex Synapse, published security blogs or research that shows a deep understanding of a particular threat or proven adversary disruption. 

    Compensation Disclosure

    The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

    $163,900.00 - $265,100.00/yr

    Our Commitment

    We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

    We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at  [email protected].

    Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

    All your information will be kept confidential according to EEO guidelines.

    Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.

    Job details are sourced from the employer's original posting.

    Open job posting
    PA

    About the company

    Palo Alto Networks

    Palo Alto Networks is a global cybersecurity leader dedicated to protecting our digital way of life. They provide cutting-edge technology and bold thinking to solve real-world problems in cybersecurity.

    View all Palo Alto Networks jobs
    Industry
    Cybersecurity
    Founded
    2005
    Open roles
    1180

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.