Jobs and Careers
PA

Principal Researcher (Unit 42)

Palo Alto Networks
United Statesfull_timeVerifiedPosted 26 Mar 2026
💰 $225,775/yr($139,600/yr$225,775/yr)

About the role

Our Mission

At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.

Job Summary

As a Senior Designated CTI Analyst (DCA) on the Unit 42 CTI Services Delivery Team, you will play a critical role in helping evolve the client’s cyber threat intelligence operations. Key to this role is understanding customer intelligence and business priorities  and developing tailored cyber threat intelligence findings and capabilities to drive their security outcomes. This will be done through: 

  • Developing automation and orchestration pipelines to surface relevant threats based on multiple feeds; 

  • Creating timely, relevant, and actionable threat insights based on customers priority intelligence requirements; 

  • Upskilling the customers use of cyber threat intelligence through sharing threat intelligence best practices 

Key Responsibilities

  • Integrate intelligence use cases into security tooling, including data feed collation, deduplication, and the creation of threat dashboards.

  • Correlate raw network and host-based indicators to attribute activity to specific threat actor groups, intrusion clusters, and malware families.

  • Utilize Palo Alto Networks telemetry, commercial tools, and open-source data to identify and track threat activities of interest, pivoting between the customers findings and Palo Alto Networks telemetry.

  • Leverage intelligence discoveries to perform threat hunts within the client’s Cortex security console.

  • Provide tailored research and analysis for client-based Requests for Information (RFIs) to include relevant cyber threat activities, trends, or shifts in the threat landscape.

  • Create a cyber threat profile that identifies top threats and provides tailored defensive recommendations based on their unique operational footprint.

  • Assist in upskilling customer team capacity through mentorship sessions, and other micro-learning initiatives on best practices in CTI.

  • Provide monthly briefings to customer leadership highlighting relevant threats, trends, and support provided.

Qualifications

Required Qualifications

  • Minimum of 7 years of experience in the cyber threat intelligence (CTI) field with a specialized focus on intelligence engineering and threat research.

  • Strong understanding of security tooling, including the underlying data structures and complex data flows required for modern defense.

  • Strong ability to architect scalable solutions to process, deduplicate, and enrich threat data, ensuring all intelligence is accurately tagged and discoverable by analytic end users.

  • Knowledge of cyber threat actors, noteworthy attacks, and the ability to quickly recognize shifts or deviations from threat activity baselines. Ability to provide tailored defensive recommendations based on identified activity.

  • A proven track record of proactive threat hunting within enterprise security consoles with a strong preference for experience using Palo Alto Networks’ Cortex product.

  • Experience communicating complex threat intelligence to diverse audiences, including C-suite executives.

  • Proven ability to operate under short-fuse deadlines, manage concurrent tasks, and thrive in complex and sometimes ambiguous situations

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Palo Alto Networks

View company profile →