Senior Security Researcher - Identity - Security Automation (Cortex)

12 Minutes ago • All levels • Cyber Security

Job Summary

Job Description

As a Senior Security Researcher, you will advance automation in identity security by designing autonomous response strategies for identity-based threats, misconfigurations, and abuse scenarios. Your research will directly shape the Cortex platform's ability to remediate identity-driven attacks, ensuring effective, safe, and scalable automation. You will collaborate with world-class researchers and engineers to deliver on the vision of the Autonomous SOC, focusing on innovation and large-scale impact.
Must have:
  • Lead the design and implementation of robust, testable, and safe remediation playbooks for identity-related threats.
  • Conduct deep research on adversary TTPs targeting identity systems and translate insights into automated detection and response mechanisms.
  • Drive innovation in identity security automation by applying data analysis, modeling, and programming.
  • Serve as a subject-matter expert and mentor within the research group.
  • Stay ahead of evolving identity-based attack vectors, cloud-native identity risks, and advanced adversary tradecraft.
  • Extensive background in identity security, including Active Directory, Azure AD, SSO, and federation protocols.
  • Proven expertise in incident response, red teaming, advanced detection research, or identity threat hunting.
  • Hands-on experience with cloud identity platforms and services like AWS IAM, Azure AD, GCP IAM.
  • Proficiency in Python for building security automations, detection rules, or SOAR playbooks.
  • Experience using SQL or other query languages for large-scale data analysis.
  • Strong analytical mindset, independent thinking, and proven ability to lead cross-functional collaboration.
Good to have:
  • Experience with big data platforms (e.g., GCP BigQuery, AWS Athena, Snowflake) to analyze large-scale identity telemetry.
  • Familiarity with Cortex XSIAM, XDR, SOAR, or similar platforms that integrate detection and response.
  • Deep knowledge of identity-focused adversary techniques, including pass-the-hash, Golden/Silver tickets, SAML manipulation, and cloud identity abuse.
  • Experience with machine learning or AI-driven approaches to identity analytics and anomaly detection.
  • Demonstrated leadership in publishing, mentoring, or community contributions in the identity security research domain.
Perks:
  • FLEXBenefits wellbeing spending account with over 1,000 eligible items.
  • Mental and financial health resources.
  • Personalized learning opportunities.

Job Details

Your Career

Are you passionate about advancing automation in identity security? Do you thrive at the intersection of research, innovation, and large-scale impact? As a Senior Security Researcher, you will drive the design of autonomous response strategies to counter identity-based threats, misconfigurations, and abuse scenarios. Your research will directly shape the Cortex platform’s ability to remediate identity-driven attacks, ensuring effective, safe, and scalable automation for our customers. You will collaborate with world-class researchers and engineers to deliver on the vision of the Autonomous SOC.

Your Impact

  • Lead the design and implementation of robust, testable, and safe remediation playbooks for identity-related threats (e.g., privilege escalation, credential abuse, lateral movement, IAM misconfigurations).
  • Conduct deep research on adversary TTPs targeting identity systems and translate insights into automated detection and response mechanisms.
  • Drive innovation in identity security automation by applying data analysis, modeling, and programming to refine remediation strategies.
  • Serve as a subject-matter expert and mentor within the research group, elevating the team’s overall expertise in identity security.
  • Stay ahead of evolving identity-based attack vectors, cloud-native identity risks, and advanced adversary tradecraft to ensure our automation keeps pace with threats.

Your Experience

  • Extensive background in identity security, including areas such as Active Directory, Azure AD, SSO, federation protocols, and identity lifecycle management.
  • Proven expertise in at least one of the following: incident response, red teaming, advanced detection research, or identity threat hunting.
  • Hands-on experience with cloud identity platforms and services (e.g., AWS IAM, Azure AD, GCP IAM) and their security controls.
  • Proficiency in Python, with practical experience building security automations, detection rules, or SOAR playbooks.
  • Experience using SQL or other query languages for large-scale data analysis to support research and validation of remediation approaches.
  • Strong analytical mindset, independent thinking, and proven ability to lead cross-functional collaboration.

Advantages

  • Experience with big data platforms (e.g., GCP BigQuery, AWS Athena, Snowflake) to analyze large-scale identity telemetry.
  • Familiarity with Cortex XSIAM, XDR, SOAR, or similar platforms that integrate detection and response.
  • Deep knowledge of identity-focused adversary techniques, including pass-the-hash, Golden/Silver tickets, SAML manipulation, and cloud identity abuse.
  • Experience with machine learning or AI-driven approaches to identity analytics and anomaly detection.
  • Demonstrated leadership in publishing, mentoring, or community contributions in the identity security research domain.

The Team

Our research team is at the core of our products and connected directly to the mission of preventing cyberattacks. We are constantly innovating - challenging the way we, and the industry, think about cybersecurity. Our researchers don’t shy away from building products to solve problems no one has pursued before.

We define the industry instead of waiting for directions. We need individuals who feel comfortable in ambiguity, excited by the prospect of a challenge, and empowered by the unknown risks facing our everyday lives that are only enabled by a secure digital environment.

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Tel Aviv, Israel

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Cyber Security Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Our enterprise security platform detects and prevents known and unknown threats while safely enabling an increasingly complex and rapidly growing number of applications. Come be part of the team that redefined the firewall industry and is now the fastest-growing security company in history. Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest security challenges with continuous innovation that seizes the latest breakthroughs in artificial intelligence, analytics, automation, and orchestration. By delivering an integrated platform and empowering a growing ecosystem of partners, we are at the forefront of protecting tens of thousands of organizations across clouds, networks, and mobile devices. Our vision is a world where each day is safer and more secure than the one before.

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

Seattle, Washington, United States (On-Site)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)

Santa Clara, California, United States (On-Site)

Santa Clara, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Palo Alto Networks

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug
Contact Us
hello@outscal.com
Made in INDIA 💛💙