Principal Researcher

Palo Alto NetworksReston, VA
Remote

About The Position

Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place. Who We Are In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us! This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters. Job Summary We are seeking a Principal Threat Intelligence Researcher for Unit 42’s Threat Intelligence Delivery Execution (TIDE) Team. This team plays a critical role in creating timely, relevant, and actionable threat insights to drive business and security outcomes for our customers. We are looking for a high performing, experienced CTI analyst with a strong track record in understanding CTI stakeholder intelligence needs and developing tailored intelligence in line with their security use cases.

Requirements

  • 7 years minimum in the CTI field with experience in threat research, analytic production, and client-facing delivery.
  • Strong knowledge of cyber threat actors, noteworthy attacks, and ability to quickly recognize inflection points, signalling shifts, evolution, or deviation from threat activity baselines or industry norms.
  • Ability to contextualize cyber events, identify how the events fit into a current or historical pattern, the impact on an industry or organization, and tailored defensive recommendations.
  • Experience operating under short fuse deadlines, managing concurrent tasks, and thriving in complex and sometimes ambiguous situations.
  • Strong writing and presentation skills with the ability to communicate threat intelligence effectively to diverse audiences, including C-suite level customers.
  • Deep experience with cyber threat intelligence frameworks and analytical techniques preferred.
  • Demonstrated ability to coordinate with cross-organizational threat analysts, facilitating collaboration, and aligning efforts to achieve common goals.
  • Experience with prompt engineering and leveraging Google’s AI capabilities to support development of intelligence products.
  • Comfortable adapting to change as every part of a growing team.
  • Must be a self-starter and creative thinker.

Nice To Haves

  • History of triaging and modeling open source data, telemetry, and other intelligence sources to quickly respond to requests for information.
  • Previous experience in Synapse or other hypergraphs.
  • Experience serving as a CTI analyst supporting customers in vendor space.

Responsibilities

  • Deliver fused intelligence insights on a recurring basis to clients across industry verticals focusing on relevant cyber threat activities, trends, and shifts in the cyber threat landscape trends.
  • Perform independent research across internal data sets, commercial third party data, and open sources.
  • Leverage existing Unit 42 intelligence publications and work with partners from internal intelligence teams.
  • Provide tailored research and analysis for client-based RFIs to drive business and security outcomes.
  • Leverage the full weight of Palo Alto Network's unique data holdings, on-going research, cross-company capabilities, and externally sourced information.
  • Assist leadership in creating a scalable solution to service multiple industries and similar stakeholder types.
  • Model research findings into Unit 42’s Threat Intelligence Knowledge Repository (TIKR).
  • Provide recommendations and help implement improvements to service support quality and speed to enhance the effectiveness and differentiation of our threat intelligence services.
  • Create cyber threat profiles for clients to identify top cyber threat activities, groups, and trends relevant to a client’s unique business operations then provide tailored defensive recommendations.
  • Work with clients to understand their operational footprint, business objectives, technology and security stacks, and areas of risk exposure.
  • Develop MITRE ATT&CK workflows and heatmaps for top threat groups.
  • Develop structured intelligence insights tracking adversary trends, motivations, organizational priorities, and historical region and industry targeting patterns.
  • Collaborate with other Unit 42 CTI SMEs in fusion cells to expand research and existing collateral on threat groups.
  • Act as a resource for colleagues, sharing expertise and best practices to enhance team capabilities.
  • Provide guidance to grow technical and strategic research acumen through personalized or group brown bag sessions.
  • Integrate Generative AI, NotebookLM, and other artificial intelligence and machine learning solutions across all phases of the intelligence lifecycle to improve analytic workflows.
  • Use and develop new AI solutions to reduce research toil, query existing intelligence holdings, and accelerate report and presentation creation.

Benefits

  • Restricted stock units
  • Bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service