Staff Threat Researcher
Job description
About the role
Zscaler is looking for a Staff Threat Researcher to join our Threat Hunting department. You will analyze adversarial tactics and emerging threats to strengthen our security detection capabilities across our global infrastructure. In this capacity, you will own the investigation of complex threat scenarios and translate ambiguous indicators into robust detection logic. The role requires you to act as a technical authority who bridges the gap between raw telemetry and actionable defensive insights. You will be responsible for maintaining a deep understanding of the threat landscape to anticipate and counter sophisticated adversaries. Your work will directly influence the security posture of the company by refining our detection logic against real-world attacks. You will leverage your expertise to ensure that our security operations remain resilient and proactive. This position is critical for driving continuous improvement in our threat hunting methodologies and security outcomes.
Key facts
What you'll do
- Investigate emerging threats, adversarial behaviors, and TTPs to refine detection logic using advanced analytical techniques.
- Perform proactive and retroactive threat hunting using Zscaler telemetry and behavioral methodologies to uncover hidden risks.
- Validate, document, and analyze all findings from hunting activities to ensure clarity and reproducibility of results.
- Manage flexible operational schedules, including weekend and night shifts, to provide on-call support and customer response as required.
- Convert observed adversary behavior into actionable hunt hypotheses that can be tested and integrated into detection strategies.
- Collaborate with cross-functional teams to correlate findings and enhance the overall effectiveness of security controls.
- Evaluate new tools and techniques to improve the efficiency and accuracy of threat identification and response processes.
- Contribute to the development of best practices and playbooks that standardize threat hunting operations across the organization.
- Analyze complex security incidents to determine root cause and potential impact on the infrastructure.
- Mentor junior analysts by providing guidance on methodologies, tool usage, and analytical thinking.
- Participate in red team exercises to test detection capabilities and improve defensive mechanisms.
- Monitor industry trends and threat intelligence feeds to stay ahead of evolving adversarial tactics.
- Translate technical findings into clear reports that communicate risk and recommendations to both technical and executive audiences.
- Ensure all hunting activities align with organizational policies, compliance requirements, and security frameworks.
Requirements
- Foundational knowledge of AI/ML technologies and experience securing or positioning AI-driven solutions is mandatory for this role.
- Practical background in threat hunting, incident response, security operations, malware analysis, or network defense is required.
- Experience using SIEM platforms such as Splunk, Microsoft Sentinel, or ElasticSearch is essential for performing core job functions.
- Proficiency with the MITRE ATT&CK framework and modern TTPs must be demonstrated through prior experience or documented work.
- Ability to analyze malware campaigns and adversary behavior to create detection logic is a non-negotiable skill.
- Bachelor's or graduate degree in Computer Science, Engineering, or equivalent security experience is required for consideration.
- Candidates must be able to show evidence of hands-on work with security tools and technologies relevant to the position.
- Strong understanding of network protocols, system architectures, and attack vectors is necessary to perform thorough investigations.
- Excellent problem-solving skills and the ability to work independently with minimal supervision are expected.
- Willingness to adhere to all security and privacy policies established by the organization is mandatory for all staff.
- Capability to communicate effectively in a hybrid work environment with team members and stakeholders.
- Commitment to continuous learning and staying updated on the latest developments in cybersecurity threats and defenses.
Nice to have
- Experience using AI/ML models, LLMs, or NLP to automate threat intelligence synthesis or analyze large telemetry datasets is preferred but not required.
- Background as a Senior Threat Hunter leading investigations and mentoring team members will be considered an advantage.
- Advanced scripting skills in Python and expertise in writing YARA and IDS/IPS signatures are desirable for this position.
Practical notes
This is a hybrid role. Zscaler provides comprehensive benefits including health plans, vacation and sick time, parental leave, retirement options, and education reimbursement. Candidates must adhere to all security and privacy policies. Zscaler is an equal opportunity employer. The role operates within a hybrid schedule, allowing for a combination of remote and on-site work from the Pune location. Travel requirements are not specified beyond standard operational needs for team collaboration and on-call duties. Employment is contingent upon successful completion of any required background checks and verification of credentials. The position is subject to the terms and conditions of employment outlined by Zscaler for staff roles.