Principal Threat Intelligence Researcher

2 weeks ago


Washington, Washington, D.C., United States Palo Alto Networks Full time

Position Overview

Eligibility Requirements

To comply with U.S. federal government requirements, U.S. citizenship is required for this position.

Clearance: (TS/SCI) w/Polygraph is also required.

About Us

At Palo Alto Networks, our mission is clear:

To be the trusted cybersecurity partner, safeguarding our digital lives.

We envision a world where each day is more secure than the last. Achieving these ambitious goals is no small feat – but we are not here for the easy path. We are here to innovate and redefine the cybersecurity landscape. We seek forward-thinkers who are dedicated to shaping the future of security.

We are transforming the work experience. Palo Alto Networks is adapting to meet the evolving needs of our workforce through FLEXWORK, our innovative approach to work. From benefits to learning opportunities, location flexibility to leadership development, we have reimagined every facet of the employee experience. FLEXWORK empowers our employees to explore new possibilities and grow together.

Job Responsibilities

As a vital member of the Unit 42, National Security Team (NATSEC), you will collaborate with a globally distributed team of vulnerability researchers, reverse engineers, and threat intelligence analysts. You will be integrated into a client environment where you will monitor cybercriminals, ransomware collectives, and advanced persistent threats to fulfill sensitive intelligence requirements.

Your Contributions

  • Deliver timely and actionable intelligence to meet customer intelligence needs.
  • Utilize global datasets (netflow, malware, passive DNS, etc.) to track malicious cyber actors, their infrastructure, and operations.
  • Conduct malware reverse engineering using both static and dynamic techniques, and interpret Assembly through disassembly or debugging tools.
  • Collaborate with a global team of threat intelligence analysts to assess and develop coverage for emerging threats.
  • Create strategic threat assessments tailored to customer requirements.
  • Engage with product engineering teams to enhance detection capabilities across our product ecosystem.

Qualifications

Your Background

  • Top Secret Clearance (TS/SCI) with Polygraph.
  • BS/MS in Computer Science, Computer Engineering, or 5+ years of experience as a cleared cyber threat intelligence analyst.
  • Familiarity with BigQuery.
  • Proficient in Python, C, and/or C++.
  • Experience with static and dynamic malware analysis and industry-standard tools.
  • Knowledge of common tactics, techniques, and procedures employed by cyber threat actors, including familiarity with the MITRE ATT&CK Matrix.
  • Strong understanding of cybersecurity threat actors, including their tactics, techniques, procedures, tools, and notable attacks.
  • Experience leveraging netflow, passive DNS, IP registration, malware telemetry, and other datasets to create comprehensive threat assessments.
  • Experience collaborating with information security teams such as fusion centers, security operations centers, vulnerability threat management, security incident management, threat hunting, and data analytics.
  • Excellent time management skills, capable of working under tight deadlines and managing multiple assignments.
  • Exceptional verbal and written communication skills.
  • Comfortable creating and delivering presentations in various settings, from industry conferences to client briefings.
  • Fluent in English; proficiency in additional languages is a plus.

Team Overview

Unit 42 unites our world-class threat researchers with an elite team of security consultants to form an intelligence-driven, response-ready organization. The Unit 42 Threat Intelligence team provides critical threat research that empowers security teams to understand adversary intent and attribution, while enhancing the protections offered by our products and services against advanced attacks. As threats evolve, Unit 42 stands ready to advise clients on the latest risks, assess their preparedness, and assist in recovery efforts.

Our Commitment

We are innovators who dream big, take calculated risks, and challenge the status quo in cybersecurity. We recognize that our mission cannot be achieved without diverse teams working collaboratively.

We are dedicated to providing reasonable accommodations for all qualified individuals with disabilities. If you require assistance or accommodation due to a disability or special need, please reach out to us.

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All information will be kept confidential according to EEO guidelines.

The compensation for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $125,100/yr to $202,400. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found on our website.

Immigration Sponsorship Eligibility: No. Please note that we will not sponsor applicants for work visas for this position.



  • Washington, Washington, D.C., United States Facebook Full time

    The Integrity, Investigations, and Intelligence (i3) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including: criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security analysts to investigate sophisticated...


  • Washington, Washington, D.C., United States Jacobs Full time

    About the RoleWe are seeking a highly skilled Intelligence Analyst SME to join our team at Jacobs. As a key member of our national security team, you will play a critical role in identifying and analyzing threats to transportation and national security.Key ResponsibilitiesConduct In-Depth Threat Analysis: Utilize various classified and unclassified databases...


  • Washington, Washington, D.C., United States Treasury, Departmental Offices Full time

    Pursuant to 50 USC 3024 (v), and with concurrence and consultation with the Director of National Intelligence and the Director of the Office of Personnel Management, this position is being established in the excepted service as an element of the Intelligence Community within the Department of the Treasury.The following are the duties of this position at the...


  • Washington, Washington, D.C., United States Jacobs Full time

    About the RoleWe are seeking a highly skilled Intelligence Analyst SME to join our team at Jacobs. As a key member of our national security team, you will play a critical role in identifying and analyzing threats to transportation and national security.Key ResponsibilitiesConduct In-Depth Threat Analysis: Utilize various classified and unclassified databases...


  • Washington, Washington, D.C., United States Treasury, Departmental Offices Full time

    Pursuant to 50 USC 3024 (v), and with concurrence and consultation with the Director of National Intelligence and the Director of the Office of Personnel Management, this position is being established in the excepted service as an element of the Intelligence Community within the Department of the Treasury.The following are the duties of this position at the...


  • Washington, Washington, D.C., United States Department Of Energy - Agency Wide Full time

    This is an Excepted Service position. This appointment will not confer Competitive Service career-conditional or career tenure status. This means that if you are selected, you would have to compete with other applicants in open competition to meet requirements for another Federal position, unless you meet the requirements for reinstatement. Applicants who...


  • Washington, Washington, D.C., United States Advantage SCI Full time

    Position Title: Intelligence Research Support Specialist IIDescription:Advantage SCI is seeking a proficient Intelligence Research Support Specialist II to enhance our operations. This role is essential in fortifying our clients' security initiatives through meticulous intelligence research and evaluation. The ideal candidate should be ready for possible...


  • Washington, Washington, D.C., United States Advantage SCI Full time

    Position Title: Intelligence Research Support Specialist IIDescription:Advantage SCI is seeking a dedicated Intelligence Research Support Specialist II to enhance our operational capabilities. This role is vital in fortifying our clients' security initiatives through comprehensive intelligence research and evaluation. The ideal candidate should be ready for...


  • Washington, Washington, D.C., United States Advantage SCI Full time

    Position Title: Intelligence Research Support Specialist IIDescription:Advantage SCI is seeking a proficient Intelligence Research Support Specialist II to enhance our operational capabilities. This role is essential in bolstering our clients' security initiatives through comprehensive intelligence analysis and research. The ideal candidate must be ready for...


  • Washington, Washington, D.C., United States Advantage SCI Full time

    Position Title: Intelligence Research Support Specialist IIDescription:Advantage SCI is seeking a dedicated Intelligence Research Support Specialist II to enhance our operational capabilities. This role is vital in fortifying our clients' security initiatives through comprehensive intelligence analysis and research. The ideal candidate must be ready for...


  • Washington, Washington, D.C., United States Department Of Energy - Agency Wide Full time

    This is an Excepted Service position. This appointment will not confer Competitive Service career-conditional or career tenure status. This means that if you are selected, you would have to compete with other applicants in open competition to meet requirements for another Federal position, unless you meet the requirements for reinstatement. Applicants who...

  • Cyber Threat Analyst

    2 weeks ago


    Washington, Washington, D.C., United States Axxum Technologies Full time

    Job OverviewAs a Cyber Threat Analyst at Axxum Technologies, you will play a pivotal role in conducting investigations focused on threat actors, developing innovative detection strategies, and providing specialized support to incident response and monitoring teams.Key Responsibilities:Engage in comprehensive SIEM monitoring, analysis, and content...


  • Washington, Washington, D.C., United States SGI Global, LLC Full time

    Job OverviewSGI Global, LLC is looking for a Mid-Level Identity Intelligence Specialist to support our Counterintelligence and Counterterrorism Vetting (CCV) operations. This role is essential in analyzing potential threats to U.S. interests and ensuring the safety of personnel and facilities.Key Responsibilities:Data Analysis: Leverage diverse datasets and...


  • Washington, Washington, D.C., United States Chenega MIOS SBU Full time

    Req ID: 32134Position OverviewIntermediate Threat Hunt AnalystWork Arrangement: Hybrid schedule with in-person attendance required at the Washington, DC office bi-weekly.Are you eager to refine your expertise and advance your career in a dynamic industry? Are you seeking a workplace that prioritizes professional growth as a fundamental aspect of its culture?...


  • Washington, Washington, D.C., United States Chenega MIOS SBU Full time

    Req ID: 32194Position OverviewIntelligence Operations SpecialistAs a part of the Chenega MIOS SBU, we are dedicated to delivering exceptional Engineering and Technical Support Services to our federal clientele.Are you eager to advance your expertise and develop your career in a dynamic environment? Do you seek a workplace that prioritizes professional...


  • Washington, Washington, D.C., United States U.S. Secret Service Full time

    The selectee will serve as a Clinical Research Psychologist in the National Threat Assessment CenterTypical work assignments include:Serving as a subject matter expert in the areas of clinical and forensic psychology, mental health law, threat assessment, and the behavioral sciences in support of the Protective Intelligence Clinical Assessment Program....


  • Washington, Washington, D.C., United States Chenega MIOS SBU Full time

    Position ID: 32194OverviewIntelligence Operations SpecialistLocation: Pentagon, Washington, DCChenega Defense & Aerospace Solutions (CDAS) is a newly established entity dedicated to delivering specialized Engineering and Technical Support Services to federal clients.Are you eager to advance your expertise and grow your career in a dynamic industry? Do you...


  • Washington, Washington, D.C., United States SGI Global, LLC Full time

    Job OverviewSGI Global, LLC is looking for a Mid-Level Identity Intelligence Specialist to enhance our Counterintelligence and Counterterrorism Vetting (CCV) operations. This role is pivotal in analyzing potential threats to U.S. interests and ensuring the safety of personnel.Key Responsibilities:Leverage diverse datasets and advanced analytical methods to...


  • Washington, Washington, D.C., United States Constellis Full time

    Job SummaryConstellis is seeking a highly skilled Intelligence and Security Professional to join our team as a Watch Officer. In this role, you will play a critical part in detecting and preventing acts of violence against the Legislative Branch of the United States Government.Key ResponsibilitiesProvide all-source intelligence support, reporting, and...


  • Washington, Washington, D.C., United States SGI Global, LLC Full time

    Job OverviewSGI Global, LLC is in search of a Mid-Level Identity Intelligence Specialist to contribute to our Counterintelligence and Counterterrorism Vetting (CCV) operations. This role is essential in analyzing and identifying potential threats to U.S. interests.Key Responsibilities:Employ a variety of datasets and advanced analytical techniques to assess...