Enable job alerts via email!

Principal Security Researcher, Google

Huntress

United States

Remote

USD 200,000 - 220,000

Full time

20 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Huntress, a leading cybersecurity firm, is seeking a Security Product Researcher who will play a crucial role in leading security capabilities and conducting research to combat cyber threats. This fully remote position offers a competitive salary and the chance to work within a collaborative team focused on innovative security solutions for SMBs.

Benefits

Generous paid time off
401(k) with 5% contribution
Comprehensive medical, dental, and vision benefits
Stock options for all full-time employees
Annual allowance for education assistance

Qualifications

  • Expertise in Google security tools and APIs.
  • Strong understanding of incident response and threat detection.
  • Experience with managing security in multi-tenant environments.

Responsibilities

  • Lead the security capabilities and layered defense strategy.
  • Conduct research on identity security and threat detection.
  • Collaborate with cross-departmental teams for product delivery.

Skills

Technical expertise in Google ecosystem
Incident response
Threat detection
Research and development
Security solutions

Education

Google Workspace Administrator Certification
Experience in security product management

Tools

Elastic
Kibana
Google Identity Premium
Chrome Enterprise

Job description

Reports to: Director, Product Research

Location: Remote US

Compensation Range: $200,000 to $220,000 base plus bonus and equity

What We Do:

Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference.

Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC) in mind and is never separated from our service.

We protect 3M+ endpoints and 1M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do. As long as hackers keep hacking, Huntress keeps hunting.

What You’ll Do:

Do you like getting into the weeds on all things technical, psychological, and educational and have a desire to know how things work? Then this is the position for you. We are looking for that jack of all trades who brings broad experience to each challenge presented. The Huntress Security team has the unique honor of waking up every morning knowing we’re going to make hackers regret targeting our partners and customers. As a Security Product Researcher, we’re looking for someone who wants to pour all of their creativity into building and implementing simple solutions that are disproportionately effective at countering these constantly evolving threats. Competitive candidates have experience managing, deploying, and securing SMB environments utilizing a wide variety of security software, best practices, and automation tools. Familiarity with product management, incident response, social engineering, psychology, education, and managed service provider tools are additional ways to differentiate yourself.

As you can imagine, success doesn’t happen in a vacuum. An effective Security Researcher fosters highly collaborative environments between the Product, Engineering, and Security teams to accelerate our mission and secure the 99% of businesses that fall below the enterprise poverty line. This collaboration is needed to produce and prioritize a unified technical vision that ultimately delivers our most impactful features and capabilities.

We defend over 2.5M endpoints across 33,000+ mid-sized and small business customers, and that number continues to grow each month. Considering this market’s tighter budget, it’s not financially possible to dedicate human analysts to each client. The Security Operations team addresses this challenge head-on by building and scaling highly automated efficiencies—often lightly augmented by our SOC — that make intruders earn every inch of their access while maintaining affordability and healthy gross margins.

Responsibilities:

  • Lead the security Capabilities we bring to market, owning the layered defense strategy gained by combining multiple log sources.
  • Conduct research and development efforts to further threat detection and identity security posture.
  • Investigate identity compromise, initial access + authentication logins, and subsequent access to understand, document & combat attacker behavior.
  • Hunt threat actors in Google Workspace, AuthN, AuthZ, OAuth, & token authentication audit logs to determine Google environment initial access, abuse and persistence.
  • Test attack paths. Hunt and solve for identity hijacking via discovering exploitation of vulnerabilities and misconfigurations.
  • Hack to FIX things. Know how to break in and devise innovative fixes. Discover how to protect against attacks.
  • Test exploitation of vulnerabilities, misconfigurations, and attack paths that results in developing reliable and weaponized Proof-of-Concept (PoC) exploits for identified vulnerabilities.
  • Identify and prototype telemetry data that can be leveraged within Huntress to expand current prevention, hardening, and detection capabilities.
  • Analyze and reverse engineer software to discover security weaknesses and undocumented features.
  • Distinguish between suspicious and malicious login events to reach the highest accuracy true positive rate.
  • Elevate and nurture the cross-department relationships critical for successful product delivery & launch. Coordinate with Security, Product, and Engineering teams to integrate and operationalize security solutions. Build high-trust, high-value relationships with product leads.
  • Document research findings through technical write-ups, advisories, internal reports, and blogs.
  • Identify improvement opportunities in existing product features and explore new ones based on feedback from partners, prospects, peers, and industry publications.
  • Coordinate with Product and Engineering teams to integrate and operationalize solutions developed by you + the research team.
  • Partner with Support, Detection Engineering, SOC, Hunt & Adversary Tactics teams.
  • Own & nurture the cross-department relationships critical to successful product delivery & launch.
  • Proven organizational and program management skills, with keen attention to detail and sense of urgency to deliver an exceptional product under tight deadline pressures.
  • Eagerness to engage, report, and be accountable to executive stakeholders.
  • Passion to translate your expertise in nontechnical ways to deliver impactful security outcomes that protect the 99%.
  • Promote Huntress’ reputation through media interaction, public speaking, and blogs.
  • Educate the public on how to be security savvy in novel and fun ways.

What You Bring To The Team:

  • Expert knowledge and technical expertise in Google ecosystem including: logs, APIs, multi-tenant environments, especially supporting MSPs, Google Workspace editions, and business plans with the ability to maximize value across business plan levels, GCP; security products such as: Chrome Enterprise, BeyondCorp, Google Identity Premium, and Google Vault
  • Google security stack expertise: chrome enterprise/beyond corp, google identity premium
  • Expert knowledge of Google multi tenant environments especially supporting MSPs
  • Expert knowledge of Google Workspace editions and business plans with the ability to maximize value across business plan levels
  • Proof of Concept (POC) development
  • Comfortable reading API documentation for SaaS applications and programming languages
  • Understanding of how MSPs utilize IT automation tools such as PSAs and RMMs preferred
  • Experience with conducting searches and creating visualizations in Elastic and Kibana a plus
  • Innovator builder mindset – you are not afraid to build in the open and share the ugly early versions of your work using feedback to iterate your research & learning
  • Expert knowledge and experience configuring and leveraging Google Workspace organizational units (OUs), group permissions, settings & APIs including Gmail, Drive, Calendar, Takeout, & Docs scripting engine.
  • Expert knowledge and experience configuring and leveraging Google Workspace security policies including SSO, two-factor authentication, password policies, and data loss prevention (DLP) to protect sensitive information.
  • Expert knowledge and experience managing security settings like configuring email security, spam filtering, malware detection, and phishing protection.
  • Security conference presenters and community educators preferred.

Desired:

  • Identity Access Management (IAM) Engineer
  • Experience with identity and access management (IAM) concepts and tools
  • Google Workspace Administrator Certification
  • Google SIEM (Chronicle) experience
  • Expertise in implementing, managing, and bypassing SSO, MFA, and identity governance across a complex organizational structure
  • Experienced Cyber Network Operator, Computer Network Operator, Cyber Technical Operator Targeter or other similar career fields
  • Red team experience, coursework, training, certifications
  • Google certifications
  • Administrator for Google Workspace at multi-tenant MSP
  • Incident responder in Google environment incidents
  • Passion for MSP community
  • Security conference presenter
  • Security community educator & advocate

What We Offer:

  • 100% remote work environment - since our founding in 2015
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth

Huntress is committed to creating a culture of inclusivity where every single member of our team is valued, has a voice, and is empowered to come to work every day just as they are.

We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, disability, veteran status, genetic information, marital status, or any other legally protected status.

We do discriminate against hackers who try to exploit small businesses.

Accommodations:

If you require reasonable accommodation to complete this application, interview, or pre-employment testing or participate in the employee selection process, please direct your inquiries to accommodations@huntresslabs.com . Please note that non-accommodation requests to this inbox will not receive a response.

If you have questions about your personal data privacy at Huntress, please visit our privacy page .

#BI-Remote

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Lead Data Scientist

Alkymi Inc

New York

Remote

USD 170,000 - 210,000

3 days ago
Be an early applicant

Principal Applied Scientist, Experimentation

ZMEX Zillow Mexico, S. de R.L. de C.V.

Remote

USD 173,000 - 277,000

3 days ago
Be an early applicant

Lead Data Scientist

Grow Therapy

Remote

USD 200,000 - 250,000

5 days ago
Be an early applicant

Principal Scientist, Integrative Computational Biology

Scorpion Therapeutics

Remote

USD 140,000 - 222,000

-1 days ago
Be an early applicant

Sr Industry Expert - Corporate Accounts - Professional Services

Moody's Corporation

Remote

USD 143,000 - 209,000

3 days ago
Be an early applicant

Director, US Marketing, Product Portfolio | Remote US

Johnson & Johnson MedTech

Kansas City

Remote

USD 146,000 - 252,000

5 days ago
Be an early applicant

Field Clinical Manager (Remote)

Kardium Inc.

Remote

USD 180,000 - 220,000

5 days ago
Be an early applicant

Controller - Remote

Community Health Systems

Remote

USD 110,000 - 296,000

2 days ago
Be an early applicant

Senior Data Analyst - Treasury

Kraken Digital Asset Exchange

Remote

USD 127,000 - 203,000

2 days ago
Be an early applicant