Principal Threat Researcher
Job description
About the role
You will spearhead the definition and execution of Identity Threat Detection and Response research for Saviynt's flagship platform. This role demands that you anticipate the evolving tactics of identity-focused adversaries and translate offensive insights into world-class defensive capabilities. You will own the strategic direction of advanced identity threat research initiatives, ensuring they align with the highest standards of innovation and impact. By bridging the gap between raw threat intelligence and product engineering, you will directly shape the future of identity security for Fortune 500 customers and government entities. You will establish thought leadership by articulating complex threat landscapes through authoritative publications and public speaking. Ultimately, you will be responsible for ensuring Saviynt remains at the forefront of defending against the most sophisticated identity-centric attacks in the AI era.
Key facts
What you'll do
Spearhead Identity Threat Research: Lead advanced research initiatives focused on uncovering and understanding novel identity-centric vulnerabilities (Human Identity(HI), Non Human Identity(NHI), Agentic Identity) based attack vectors, and exploit chains across hybrid and multi-cloud environments.
Data-Driven Behavioral Modeling: Leverage vast telemetry from multi-cloud environments, disparate data sources, and user activity logs to conduct deep behavioral analysis. You will be a domain expert and work with an extended team to develop and refine sophisticated behavioral models to detect anomalies, uncovering stealthy, suspicious identity threat patterns that bypass traditional signature-based detection.
Drive Product Innovation: Partner closely with Product Managers and Engineering teams to translate complex threat research into actionable product features, robust detection algorithms, and high-fidelity telemetry for our next-generation ITDR platform.
Execute Advanced Threat Hunting & Intelligence: Conduct proactive threat intelligence gathering and sophisticated threat hunting specifically targeting Identity vulnerabilities (e.g., Active Directory, Entra ID, Okta, PAM, and Cloud IAM misconfigurations).
Operationalize Security Frameworks: Extensively utilize and map research to industry-standard frameworks, including MITRE ATT&CK, MITRE ATLAS, and MAESTRO, ensuring our detection strategies comprehensively cover modern adversary Tactics, Techniques, and Procedures (TTPs).
Pioneer Detection Engineering: Architect and develop advanced detection strategies, behavioral baselines, and correlation rules to identify anomalous identity behaviors, privilege escalation, and lateral movement.
Establish Thought Leadership: Serve as a highly visible ambassador for Saviynt's research capabilities. You will regularly author and publish high-quality blogs, and technical reports on emerging threats.
Drive Patentable Innovation: Foster a culture of exemplary, bleeding-edge innovation within the team, actively pursuing research that leads to industry publications, CVE discoveries, and patents for Saviynt.
Mentor and Guide: Act as a senior technical authority, mentoring junior researchers and elevating the technical acumen of the Threat Research and Engineering organizations.
Champion Adversary Emulation: Lead red team exercises specifically designed to test identity infrastructure resilience, validating detection capabilities against realistic attacker playbooks.
Champion Data Integrity: Ensure the fidelity and quality of telemetry data used for modeling, establishing rigorous methodologies for data collection and normalization across heterogeneous environments.
Collaborate with Incident Response: Work hand-in-hand with the Incident Response team to analyze real-world breaches, extracting learnings to enhance the predictive accuracy of threat models.
Champion Toolchain Innovation: Evaluate, prototype, and integrate cutting-edge open-source and commercial tools for intelligence collection, analysis, and visualization specific to identity ecosystems.
Define Research Roadmap: Own the quarterly and annual research agenda, prioritizing initiatives based on emerging threats, customer impact, and strategic alignment with product vision.
Requirements
Extensive Industry Experience: 12+ years of progressive experience in cybersecurity, with a minimum of 5+ years dedicated specifically to Threat Research, Threat Intelligence, or advanced Detection Engineering at a senior/lead level.
Threat Intelligence Pivoting: Tracing connections between seemingly unrelated data points (e.g., IPs, domain names, hashes) to attribute attacks to specific threat actors or Advanced Persistent Threats (APTs).
Security Frameworks: Applying industry models to classify and map adversary behavior, such as the MITRE ATT&CK framework, ATLAS, and MAESTRO.
Attack Vectors: Knowledge of Identity based attacks such as Pass-the-Hash/Ticket, Golden/Silver Tickets, MFA Fatigue (Prompt Bombing), Token Theft, Kerberosting and Credential Stuffing.
Adversary Tradecraft: Familiarity with tools threat actors use to map and exploit identity environments, such as Mimikatz, BloodHound, Rubeus.
Vulnerability & Exploit Research: Assessing zero-day flaws, evaluating proof-of-concept (PoC) exploits, and testing patching strategies.
Programming & Scripting: Familiarity with scripting and programming languages (e.g., Python, Go, Bash) to help rapidly engineer complex detection algorithms and prototype innovative feature proof-of-concepts (POCs).
Data Mining & OSINT: Gathering threat intelligence from various sources like Open Source Intelligence (OSINT), dark web forums, threat feeds, and internal telemetry to build comprehensive threat pictures.
Cloud Identity Platforms: Deep understanding of major Identity Providers (IdPs) like Azure AD, Okta, and AWS, including their internals, configuration nuances, and security limitations.
Nice to have
Experience with published research in top-tier security conferences or publications.
Demonstrated ability to drive security automation through AI/ML technologies.
Practical notes
Hours: Full-time (standard business hours).
Location: Bengaluru.
Travel: None specified.