Source Job

$171,500–$245,000/yr
US

  • Dissect and outmaneuver sophisticated cyber attack techniques across endpoint and cloud environments.
  • Translate complex threat research into scalable detection recommendations and engineer attack code.
  • Collaborate with detection engineers, intelligence analysts, and threat hunters to prioritize and refine deliverables.

Security Research Endpoint Security Cloud Security Python AI/ML

20 jobs similar to Principal Threat Researcher

Jobs ranked by similarity.

US

  • Monitor and analyze sophisticated cyber threats targeting Anduril's products, infrastructure, and personnel.
  • Research and anticipate emerging technical trends in the threat landscape, collaborating with detection and response teams.
  • Enhance tooling for threat actor tracking and intelligence data integration, engaging with external partners.

Anduril Industries is a defense technology company focused on transforming military capabilities with advanced technology, including AI-powered systems and autonomy. The company is known for its fast-paced, innovative culture and its commitment to bringing cutting-edge solutions to the defense industry.

$96,600–$138,000/yr
US

  • Analyze EDR telemetry, alerts, and log sources across Endpoint, Identity, Network, and Cloud/SaaS.
  • Publish threats for customers with concise written communication conveying key indicators and remediation context.
  • Improve Detection Operations workflow through orchestration and automation to manage high volumes of telemetry.

Zscaler accelerates digital transformation with a cloud security platform that protects customers from cyberattacks. With 160+ public exchanges globally, they are the world's largest in-line cloud security platform, fostering a culture of ownership, collaboration, and continuous feedback.

$245,000–$307,000/yr
US

  • Lead the Sysdig Threat Research Team, owning adversary research and detection engineering end-to-end.
  • Drive AI security research into threats on models, agents, and infrastructure, plus AI-driven research methods.
  • Publish original research, ship detection content to customers and the Falco community, and partner with marketing and product teams.

Sysdig is a cloud security company that created Falco, the open standard for cloud threat detection, trusted by over 60% of the Fortune 500. With a culture recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for 5 years, they emphasize diversity and open dialogue.

India

  • Monitor security alerts and events to identify potential threats and vulnerabilities.
  • Detect and analyze security incidents using multiple security tools like SIEM, EDR, and IDS/IPS.
  • Respond to security incidents promptly following established procedures and perform phishing analysis.

Zscaler accelerates digital transformation so customers can be more agile, efficient, resilient, and secure with its Zero Trust Exchange platform. The company employs thousands globally and fosters a culture of ownership, collaboration, and continuous feedback.

$157,675–$238,500/yr
US

  • Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry with clear false-positive thresholds.
  • Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement.
  • Advance the detection-as-code platform with version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.

Samsara is the pioneer of the Connected Operations™ Cloud, helping organizations that depend on physical operations to harness IoT data for actionable insights. They are a recently public company with a high-caliber team, embracing a flexible working model that supports remote and hybrid work.

$168,000–$238,000/yr
Canada Israel UK United States Unlimited PTO

  • Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
  • Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
  • Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.

UK

  • Co-own day-to-day operation, triage, and tuning of the enterprise endpoint security environment.
  • Evolve zero trust systems and write clear runbooks in partnership with Security Operations.
  • Mentor engineers to grow security knowledge and act as a technical subject matter expert.

Samsara is the pioneer of the Connected Operations Cloud, enabling physical-operations industries to harness IoT data for actionable insights. A recently public company, it offers autonomy and support with a collaborative, long-term-focused culture.

$143,500–$205,000/yr
US

  • Lead and develop a high-performing customer-facing team of threat hunters and MDR specialists.
  • Serve as senior escalation point for customer security teams during active intrusions and complex investigations.
  • Manage recurring customer engagements translating threat intelligence into actionable guidance.

Zscaler is a cloud security company that accelerates digital transformation with its Zero Trust Exchange platform, protecting customers from cyberattacks. With thousands of customers globally, Zscaler fosters a culture of ownership, collaboration, and innovation.

$175,000–$240,000/yr
US

  • Serve as the primary technical advisor for enterprise customers throughout the evaluation, adoption, and expansion of the cybersecurity platform.
  • Lead impactful demos, presentations, and technical storytelling for technical and executive audiences.
  • Partner with internal teams and partners to accelerate revenue, drive product feedback, and support Proof of Concepts.

TrendAI is the global AI security leader and enterprise business unit of Trend Micro, securing identities, infrastructure, and data. Trusted by large enterprises and governments in 185 countries, it fosters a diverse, multicultural workforce.

$144,300–$216,500/yr
US

  • Proactively hunt for advanced threats and dissect complex fraud vectors using hypothesis-driven threat hunting operations.
  • Apply and enrich the FT3 taxonomy to standardize threat intelligence across kill chain phases and API endpoints.
  • Collaborate cross-functionally to integrate threat intelligence, build agentic simulation workflows, and eliminate product vulnerabilities.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments and grow revenue. They are a large, global company with a mission to increase the GDP of the internet and a culture of innovation and collaboration.

US Unlimited PTO

  • Hunt for emerging exploitation activity and attacker infrastructure across VulnCheck's data.
  • Turn discoveries into durable detections including rules, queries, and tooling.
  • Investigate payloads and post-exploitation activity and produce threat intelligence.

VulnCheck provides structured exploit intelligence on actively weaponized vulnerabilities, built for automation and AI workflows. Founded in 2021, the company has a collaborative and supportive culture with a team of cybersecurity experts.

Global

  • Execute end-to-end platform deployments across Google SecOps and Microsoft Sentinel for new customers.
  • Onboard log sources, configure data connectors, and validate ingestion pipelines.
  • Train customers on their deployed platform and document handoff notes for ongoing support.

TENEX is an AI-native, automation-first Managed Detection and Response (MDR) provider that combines cutting-edge AI with human expertise to deliver security operations. It is a fast-growing startup backed by top-tier investors, with a mission-driven and customer-obsessed culture.

$115,500–$165,000/yr
US

  • Build LLM-powered agents and production ML systems to automate security analysis.
  • Collaborate with threat-research and data engineering to turn risk identification into scalable solutions.
  • Own deployment, monitoring, and quality of solutions in CI/CD frameworks.

Zscaler accelerates digital transformation with its Zero Trust Exchange platform, protecting customers from cyberattacks and data loss. The company is the world's largest in-line cloud security platform, distributed across 160+ exchanges, with an AI-native culture focused on ownership, collaboration, and trust.

Europe

  • Monitor, triage, and investigate security alerts across SIEM, EDR, and cloud environments.
  • Analyze logs from Windows, Linux, databases, and network systems to identify and remediate threats.
  • Work with Incident Response teams to contain threats and improve detection quality.

Talan is a global consulting group specializing in innovation and business transformation through technology. With over 7,200 consultants across 21 countries and an €850M turnover, we deliver future-ready solutions in a multicultural, growth-oriented environment.

$172,279–$249,640/yr
United States Canada

  • Build and maintain SIEM infrastructure and detection systems to identify malicious behavior across corporate and production environments.
  • Investigate security incidents end-to-end, including malware analysis and timeline reconstruction, and develop runbooks for scalable response.
  • Partner with IT to enforce security standards on employee devices and drive implementation of Zero-Trust VPN and other corporate security controls.

Quora operates two platforms: Quora, a global knowledge sharing platform, and Poe, a platform for chatting with AI language models. The company fosters a culture of transparency, idea-sharing, and collaboration among its global teams.

US

  • Design and implement scalable detection logic to identify insider threats and data exfiltration across corporate and production environments.
  • Conduct proactive threat hunting and incident response, collaborating with HR, Legal, and engineering teams during complex investigations.
  • Develop automation and detection models using Python and SQL to strengthen security response capabilities and reduce risk exposure.

The company is a technology organization specializing in security and threat detection. They operate in a fast-paced, collaborative environment with a focus on insider threat prevention and response.

$143,500–$205,000/yr
US

  • Manage premium customer support relationships and drive deep product adoption for top-tier customers.
  • Partner with Field Sales, serve as trusted advisor for web and email security implementations, and manage escalations.
  • Deliver high-impact training, monitor customer environments, and translate insights into product requirements.

Zscaler accelerates digital transformation with the Zero Trust Exchange platform, a cloud security solution protecting thousands of customers from cyberattacks. The company is AI-native and values ownership, collaboration, and a challenge culture.

$133,000–$209,000/yr
US

  • Design and continuously improve detection and alerting controls to reduce noise and enable rapid response.
  • Build, test, and automate incident response playbooks to increase efficiency across the incident lifecycle.
  • Drive prioritization of alerts using a data-driven triage framework aligned with business impact and threat context.

Sword builds AI to heal billions, pioneering AI Care for healthcare delivery across physical therapy, women’s health, and more. With over 700,000 members and 1,000+ enterprise clients, they have raised $500 million and emphasize a culture of proactive security and AI proficiency.

Philippines

  • Monitor security tools and investigate alerts to maintain situational awareness.
  • Manage vulnerability management platform and coordinate remediation of security vulnerabilities.
  • Conduct security awareness training and assist with incident response and reporting.

The organization is committed to maintaining robust information security practices. With a team of skilled professionals, it promotes a culture of continuous learning and adherence to high ethical standards.

$108,000–$140,000/yr
US

  • Design, implement, and maintain internal tooling for acquiring and parsing recaptured underground data.
  • Build and deploy cloud infrastructure using Infrastructure as Code technologies.
  • Collaborate with the research team to support targeting and collection of new data sources.

SpyCloud transforms recaptured darknet data to disrupt cybercrime. They have over 250 cybersecurity experts and foster a collaborative, innovative culture.