Principal Threat Hunter (Unit 42)

Palo Alto NetworksSeattle, WashingtonOn-siteFull-timeSenior, 5–8 yearsListed 5 hours ago

Apply now

About this role

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.

Job Summary

Principal Threat Intelligence Hunter - Unit 42 Managed Threat Hunting

Job Description Summary

The Principal Threat Intelligence Hunter will sit within Unit 42 Managed Threat Hunting and support proactive, intelligence-led hunting across customer environments. This role combines hands-on threat hunting with cyber threat intelligence analysis, helping multinational organizations stay one step ahead of adversaries and cyber threats.

The Cyber Threat Intelligence Hunter will analyze public and private threat intelligence, Unit 42 research, adversary campaigns, malware activity, infrastructure, indicators, and TTPs, then translate that intelligence into actionable hunting hypotheses, investigation workflows, hunting queries, and customer-facing findings.

This role will work across large-scale customer telemetry to investigate suspicious activity, validate emerging threats, support scheduled hunts, and contribute to timely, professional reporting. The role will also collaborate closely with threat hunters, detection engineers, incident responders, MDR teams, and Unit 42 intelligence and security researchers to operationalize intelligence quickly and improve hunting outcomes across the service.

This is a proactive, research-driven hunting role for someone who can connect external intelligence with real-world telemetry, understand and fingerprint attacker behavior, investigate security data, and clearly communicate findings to both technical and non-technical audiences.

Your Impact

Help multinational organizations stay one step ahead of adversaries and cyber threats.

Serve as a key contributor within Unit 42 Managed Threat Hunting , combining hands-on threat hunting execution with cyber threat intelligence analysis.

Analyze public and private threat intelligence, Unit 42 research, adversary campaigns, malware activity, infrastructure, indicators, and TTPs.

Translate threat intelligence into actionable hunting hypotheses, investigation workflows, hunting queries, and customer-facing findings.

Execute existing threat hunting reports and hunting workflows, investigate results, and support timely customer reporting.

Investigate scheduled hunt detections and compose clear, professional reports when relevant.

Investigate hunting leads based on IOCs, threat intelligence, internal detections, customer telemetry, and emerging adversary behaviors.

Monitor the threat landscape and prepare initial context for emerging campaigns, enabling the global team to continue deeper investigation and hunting.

Collaborate with threat hunters, detection engineers, incident responders, MDR, and Unit 42 researchers to operationalize intelligence quickly and effectively.

Escalate major, unclear, or high-impact security events to the Threat Hunting leadership team when necessary.

Provide ongoing feedback on findings, hunting reports, queries, intelligence workflows, and operational processes to support continuous improvement.

Contribute to making the world a safer and better place.

Why Choose Us

Perform meaningful, intelligence-led threat hunting across a wide variety of data sources.

Gain hands-on experience translating emerging threat intelligence into real hunting outcomes across customer environments.

Work across multiple cybersecurity domains, including endpoint, network, cloud, identity, and third-party vendor telemetry.

Learn how threat intelligence is converted into hypotheses, queries, investigations, validations, and customer-facing reports.

Join a global team of experts who handle threats and adversaries at scale every day.

Collaborate closely with Unit 42 researchers, incident responders, detection engineers, MDR teams, and experienced threat hunters.

Help improve how threat intelligence is operationalized across a managed service.

Take part in the continuous improvement of hunting reports, queries, workflows, automation, AI-driven hunting capabilities, and operational processes.

We believe in automation, AI, intelligence-led hunting, and scalable security outcomes.

Qualifications

Your Experience

- 6+ years of experience in tactical threat hunting, cyber threat intelligence (CTI), DFIR, or advanced security operations.
- Strong background in tactical threat intelligence, specifically identifying the discrete traces, artifacts, and behavioral fingerprints left by adversaries across diverse telemetry sources (endpoint, network, cloud, and identity).
- Experience capturing and modelling incident data to map out intrusions and understand attacker behaviours.
- Proven ability to develop & deliver verbal & written technical findings of attacker behaviour into clear, high-impact notifications for customers.
- Experience translating threat intelligence into high-fidelity hunting hypotheses, detection logic, and log-based queries.
- Bonus Points: Experience in an Incident Response or Managed Services environment, proficiency in Python and SQL, or familiarity with malware analysis, published security blogs or research that shows a deep understanding of a particular threat.

##

##

The Team

We’re not your ordinary Threat Hunting team. We’re a diverse and global group of security professionals who deal with big data, emerging threats, adversary behavior, threat intelligence, and customer telemetry in order to remain one step ahead of attackers.

Being a Cyber Threat Intelligence Hunter within Unit 42 Managed Threat Hunting is an opportunity to sit at the intersection of threat intelligence, proactive hunting, detection logic, incident response insights, and customer-facing security outcomes. You’ll work with some of the brightest minds in cybersecurity and help turn intelligence into action at global scale.

Qualifications

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here .

- /yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at   [email protected] .

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.