Principal Researcher; Unit
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Data Security
Location: California
Company Description
Our Mission At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
Who We Are This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.
Job DescriptionYour Career:
We are seeking a Principal Threat Intelligence Researcher for our Unit 42 Intelligence Response Unit’s CTI Services Delivery Team. This team plays a critical role in creating timely, relevant, and actionable threat insights to drive business and security outcomes for our customers. The incumbent will play a critical role in understanding our customers’ intelligence needs and developing tailored intelligence that augment their existing capabilities.
Impact
The incumbent will play a critical role in understanding our customers’ intelligence needs and developing tailored intelligence that augment their existing capabilities. As a Principal Threat Intelligence Researcher in the Intel Response Unit, your primary responsibilities will include:
- Client-facing Briefing:
Deliver fused intelligence insights on a recurring basis to clients across industry verticals focusing on relevant cyber threat activities, trends, and shifts in the cyber threat landscape. Custom tailored content should empower defensive actions for clients, providing their threat intelligence and security teams with key observations, insights, and perspective. Content creation will require performing independent research across internal data sets, commercial third‑party data, and open sources.
This will also include leveraging existing Unit 42 intelligence publications and working with partners from internal intelligence teams. - Client-facing RFI Support:
Provide tailored research and analysis for client‑based RFIs to drive business and security outcomes. Leverage the full weight of Palo Alto Network’s unique data holdings, ongoing research, cross‑company capabilities, and externally sourced information. Assist leadership in creating a scalable solution to service multiple industries and similar stakeholder types. Model research findings into Unit 42’s Threat Intelligence Knowledge Repository (TIKR). Provide recommendations and help implement improvements to service support quality and speed to enhance the effectiveness and differentiation of our threat intelligence services.
Some requests will require rapid turnaround time, which may include operating outside of normal business hours. - Threat Profile Production:
Create cyber threat profiles for clients to identify top cyber threat activities, groups, and trends relevant to a client’s unique business operations, then provide tailored defensive recommendations. Work with clients to understand their operational footprint, business objectives, technology and security stacks, and areas of risk exposure. Develop MITRE ATT&CK workflows and heatmaps for top threat groups. - Anticipatory Threat Knowledge Creation:
Develop structured intelligence insights tracking adversary trends, motivations, organizational priorities, and historical region and industry targeting patterns. This information will act as a backdrop to support intelligence production response for unfolding cyber events, exploitation trends, and threat actor campaigns. Collaborate with other Unit 42 CTI SMEs in fusion cells to expand research and existing collateral on threat groups. - Industry Voice & Expertise:
Must be willing to represent Unit 42 by delivering expert-level presentations at key conferences, public‑speaking engagements, podcasts or webinars, and authoring influential thought leadership materials. - Peer Empowerment:
Act as a resource for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).