Principal Threat Hunter (Unit 42)
Core
Proactive, intelligence-led threat hunting across customer environments to identify adversary behavior and validate emerging threats.
Role type
Principal Threat Intelligence Hunter (IC)
Builds
Actionable hunting hypotheses, investigation workflows, hunting queries, and customer-facing findings
Domain
Cybersecurity / Threat Intelligence / Managed Security Services
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
tactical threat hunting, cyber threat intelligence (CTI), DFIR, attacker behavior modeling, translating intelligence to hunting hypotheses, log-based query development, technical reporting
Preferred skills
incident response, managed services, Python, SQL, malware analysis, security research
Technologies
endpoint telemetry, network telemetry, cloud telemetry, identity telemetry, Unit 42 research data
Responsibilities
Analyze public/private threat intelligence and adversary campaigns to generate hunting hypotheses; Execute scheduled hunts and investigate suspicious activity in customer telemetry; Translate intelligence into actionable queries and customer reports; Collaborate with detection engineers, incident responders, and researchers to operationalize intelligence; Escalate high-impact security events; Provide feedback on hunting workflows and processes
Seniority
Principal, hands-on IC with strategic impact