Principal Security Researcher
Lead technical strategy and multi-quarter research initiatives for identity threat detection and response. Investigate attacker tradecraft, develop resilient detections, guide AI-assisted research workflows, mentor researchers, and influence security product strategy.
Responsibilities
- Set technical direction and multi-quarter strategy for identity protection research
- Lead concurrent end-to-end investigations and resolve complex technical questions
- Analyze identity and related data to identify novel threats, attacker tradecraft, and detection opportunities
- Design resilient detection logic across the attack kill chain
- Partner with product management, engineering, data science, and research teams on product strategy and roadmaps
- Mentor researchers through technical reviews, coaching, and complex investigations
- Define and evaluate generative AI patterns and workflows for triage, hypothesis generation, coding, and detection synthesis
- Represent the security research team through publications, conference talks, blogs, and industry engagement
Requirements
- At least 10 years of cybersecurity experience, including at least 4 years focused on identity-based attacks through research, hunting, or detection engineering
- Deep knowledge of the modern attacker kill chain and MITRE ATT&CK
- Track record of owning defensive research from threat hypothesis through shipped detection and customer impact
- Knowledge of Windows internals and identity protocols including Kerberos, NTLM, LDAP, OAuth 2.0, and SAML
- Fluency with generative AI tools, including prompt design, output validation, and integration into investigation, coding, and detection authoring
- Strong cross-group leadership, communication, and influencing skills
Nice to have
- B.Sc. or M.Sc. in Computer Science or a related technical discipline
- Experience with C#, Python, or C++ and a query language such as KQL, SQL, or Cypher
- Windows or cloud forensics experience involving credential theft and lateral movement
- Published security research, conference talks, blogs, CVEs, or open-source contributions
- Experience applying AI or LLM-assisted workflows to security research, detection engineering, or threat intelligence
- Established external thought leadership in the security research community