SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Saviynt is seeking an Associate Principal Engineer - Threat Researcher to lead advanced identity threat research initiatives. This is a senior technical role focused on uncovering novel identity-centric vulnerabilities and attack vectors across hybrid and multi-cloud environments, including Human Identity (HI), Non-Human Identity (NHI), and Agentic Identity threats.
Key responsibilities include:
• Spearhead identity threat research to uncover vulnerabilities and exploit chains in hybrid and multi-cloud environments
• Conduct deep behavioral analysis using telemetry from multi-cloud environments and user activity logs to develop sophisticated behavioral models for detecting anomalies and stealthy identity threat patterns
• Partner with Product Managers and Engineering teams to translate threat research into actionable product features, detection algorithms, and telemetry for the next-generation ITDR platform
• Execute advanced threat hunting and intelligence gathering targeting identity vulnerabilities (Active Directory, Entra ID, Okta, PAM, Cloud IAM misconfigurations)
• Map research to industry-standard frameworks including MITRE ATT&CK, MITRE ATLAS, and MAESTRO to ensure comprehensive coverage of adversary TTPs
• Architect and develop advanced detection strategies, behavioral baselines, and correlation rules to identify anomalous identity behaviors, privilege escalation, and lateral movement
• Serve as a thought leader, authoring and publishing high-quality blogs and technical reports on emerging threats
• Foster innovation within the team, pursuing research that leads to industry publications, CVE discoveries, and patents
• Mentor junior researchers and elevate the technical acumen of the Threat Research and Engineering organizations
The role is hybrid based in Bengaluru with willingness to travel globally for business requirements, industry conferences, and strategic team syncs.
REQUIREMENTS:
• 12+ years of progressive experience in cybersecurity, with a minimum of 5+ years dedicated specifically to Threat Research, Threat Intelligence, or advanced Detection Engineering at a senior/lead level
• Expertise in threat intelligence pivoting, tracing connections between data points to attribute attacks to specific threat actors or APTs
• Strong knowledge of security frameworks: MITRE ATT&CK, ATLAS, MAESTRO
• Deep understanding of identity-based attacks: Pass-the-Hash/Ticket, Golden/Silver Tickets, MFA Fatigue (Prompt Bombing), Token Theft, Kerberoasting, Credential Stuffing
• Familiarity with adversary tools: Mimikatz, BloodHound, Rubeus
• Experience in vulnerability and exploit research, assessing zero-day flaws, evaluating PoC exploits
• Proficiency in scripting and programming languages (Python, Go, Bash) for detection algorithm engineering and PoC development
• Experience with data mining and OSINT from threat feeds, dark web forums, and internal telemetry
• Demonstrated expertise in rule/signature development: YARA, Snort rules, SIEM query languages (Splunk SPL, KQL), Sigma
• Working knowledge of AI/ML in threat research, threat hunting, and detection mechanisms; understanding of Agentic AI and emerging Agentic AI threats
• Proven track record of thought leadership: published white papers, cybersecurity blogs, conference speaking, patents, or acknowledged CVEs
• Exceptional cross-functional communication skills to translate complex technical research into actionable requirements
• Good-to-have: algorithmic prototyping and advanced query language skills
• Strong understanding of Identity and Access Management (IAM), Privileged Access Management (PAM), and cloud identity architectures (AWS IAM, Azure AD/Entra ID, GCP Cloud Identity, Active Directory)