SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 171,500 - 245,000 / annual
Zscaler is seeking a Principal Threat Researcher to join the Threat Research Team as a subject matter expert on adversary behavior across Endpoint and Cloud environments. You will dissect, replicate, and analyze sophisticated cyber attack techniques to understand how they operate and develop defenses against them. Your research will directly inform engineering efforts, shape product strategy, and ensure industry-leading protection for Zscaler's customer base.
Key Responsibilities:
- Scope and refine research initiatives analyzing emerging attack techniques across Windows, macOS, Linux, and major cloud providers (AWS, Microsoft 365, Okta)
- Conduct deep technical analysis of threat components and detection methods to understand how adversaries manipulate attack variations
- Engineer automated attack code, write validation test code, and develop proofs of concept for new detections
- Collaborate across Zscaler with detection engineers, intelligence analysts, and threat hunters to develop detection methodologies and prioritize deliverables
- Document and present research findings to internal and external audiences; mentor junior team members and colleagues pursuing research
- Leverage an adversarial mindset to translate complex threat research into concrete, scalable detection recommendations
You thrive in ambiguity, act as an owner with passion for the mission, and seamlessly navigate between high-level strategy and hands-on technical execution. You are an energized problem-solver who actively seeks complex security challenges, a high-trust collaborator in a challenge culture, and a continuous learner with a growth mindset.
Requirements:
- 12+ years of experience conducting security research with actionable outcomes
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions
- Extensive security expertise in at least one operating system (Windows, macOS, or Linux)
- Experience with commercial Endpoint Detection & Response (EDR) platforms
- Security experience in at least one cloud service provider (AWS, GCP, Azure) and cloud-based detection platforms
- Software development experience in at least one scripting language (PowerShell, Python) and one compiled/assembled language (C, C++, Rust, Go)
- Experience managing code with version control systems (git/GitHub)
Preferred Qualifications:
- Proven ability to leverage AI technologies and workflows to drive measurable operational efficiency
- Established record of public community engagement (conference talks, technical blog posts, webinars)
- Prior experience developing relationships with security vendors or building attack technique automation frameworks