Principal Security Researcher, Google Job at Huntress, Columbia, MD

V1FWUzRDQkVxTWtEcG5qdlUveGVXaVFUTlE9PQ==
  • Huntress
  • Columbia, MD

Job Description

Job Description

Job Description

Reports to: Director, Product Research

Location: Remote US

Compensation Range: $210,000 to $240,000 base plus bonus and equity

What We Do:

Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference.

Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC) in mind and is never separated from our service.

We protect 3M+ endpoints and 1M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do. As long as hackers keep hacking, Huntress keeps hunting.

What You'll Do:

Do you like getting into the weeds on all things technical, psychological, and educational, and have a desire to know how things work? Then this is the position for you. We are looking for that jack of all trades who brings broad experience to each challenge presented. The Huntress Security team has the unique honor of waking up every morning knowing we're going to make hackers regret targeting our partners and customers. As a Security Product Researcher, we're looking for someone who wants to pour all of their creativity into building and implementing simple solutions that are disproportionately effective at countering these constantly evolving threats. Competitive candidates have experience managing, deploying, and securing SMB environments utilizing a wide variety of security software, best practices, and automation tools. Familiarity with product management, incident response, social engineering, psychology, education, and managed service provider tools are additional ways to differentiate yourself.

As you can imagine, success doesn't happen in a vacuum. An effective Security Researcher fosters highly collaborative environments between the Product, Engineering, and Security teams to accelerate our mission and secure the 99% of businesses that fall below the enterprise poverty line. This collaboration is needed to produce and prioritize a unified technical vision that ultimately delivers our most impactful features and capabilities.

We defend over 2.5M endpoints across 33,000+ mid-sized and small business customers, and that number continues to grow each month. Considering this market's tighter budget, it's not financially possible to dedicate human analysts to each client. The Security Operations team addresses this challenge head-on by building and scaling highly automated efficiencies—often lightly augmented by our SOC — that make intruders earn every inch of their access while maintaining affordability and healthy gross margins.

Responsibilities:

  • Lead the security Capabilities we bring to market, owning the layered defense strategy gained by combining multiple data sources
  • Investigate identity compromises such as account takeover, session hijacking, and credential theft, to convert attacker behavior into threat detection and identity security product capabilities
  • Hunt threat actors in Google environments to discover attacker initial access, abuse, and persistence
  • Test attack paths. Go beyond disclosing vulnerabilities and misconfigurations to developing requirements for security products that shut out attackers
  • Safely & ethically test exploitation of vulnerabilities, misconfigurations, and attack paths that result in developing reliable and weaponized Proof-of-Concept (PoC) exploits for identified vulnerabilities
  • Identify telemetry that confirms malicious activity with high confidence, even when little or no environment baselines exist
  • Analyze and reverse engineer technology to discover security weaknesses and undocumented features
  • Distinguish between suspicious and malicious login events to reach the highest accuracy true positive rate
  • Conduct research and development efforts to further threat detection and security posture
  • Document research findings through technical write-ups, advisories, internal reports, and blogs
  • Identify improvement opportunities in existing product features and explore new ones based on feedback from partners, prospects, peers, and industry publications
  • Elevate and nurture the cross-department relationships critical for successful product delivery & launch
  • Build high-trust, high-value relationships with product leads
  • Proven organizational and program management skills, with keen attention to detail and a sense of urgency to deliver an exceptional product under tight deadline pressures
  • Eagerness to engage, report, and be accountable to executive stakeholders
  • Passion to translate your expertise in nontechnical ways to deliver impactful security outcomes that protect the 99%
  • Promote Huntress' reputation through media interaction, public speaking, and blogs
  • Educate the public on how to be security savvy in novel and fun ways

What You Bring To The Team:

  • Expert skills in accessing & testing Google data without console or native Google tools
  • Expert knowledge of Google logs & APIs
  • Experience bypassing Google security controls, performing account takeover, bypassing MFA & attacking Google tech stack
  • Experience building exploit proofs of concept (POC)
  • Expert knowledge of Google vulnerabilities & threats with the ability to emulate attacks in a test lab created by you
  • Innovator builder mindset – you are not afraid to build in the open and share the ugly early versions of your work using feedback to iterate your research & learning
  • Can toggle between red team, systems administration & defender roles
  • Expert skills operating across multi-tenant environments, especially supporting MSPs, Google Workspace editions, and business plans, with the ability to maximize value across business plan levels
  • Can translate between GCP, Google Workspace & Google security products
  • Understanding of how MSPs utilize IT automation tools such as PSAs and RMMs preferred
  • Experience with conducting searches and creating visualizations in Elastic and Kibana is preferred
  • Security conference presenters and community educators preferred

What We Offer:

  • 100% remote work environment - since our founding in 2015
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth

Huntress is committed to creating a culture of inclusivity where every single member of our team is valued, has a voice, and is empowered to come to work every day just as they are.

We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, disability, veteran status, genetic information, marital status, or any other legally protected status.

We do discriminate against hackers who try to exploit businesses of all sizes.

Accommodations:

If you require reasonable accommodation to complete this application, interview, or pre-employment testing or participate in the employee selection process, please direct your inquiries to accommodations@huntresslabs.com . Please note that non-accommodation requests to this inbox will not receive a response.

If you have questions about your personal data privacy at Huntress, please visit our privacy page .

#BI-Remote

Job Tags

Full time, Remote work, Worldwide, Home office, Day shift,

Similar Jobs

ManTech

Security Engineer Job at ManTech

 ...ManTech seeks a motivated, career and customer-oriented Security Engineer to join our team in Herndon, VA. The Security Engineer will design, implement, and maintain secure environments that align with compliance standards in support of a high priority mission... 

Green Way Shuttles

Part-Time Shuttle Bus Driver (Class A or B CDL) Job at Green Way Shuttles

 ...experience. Class A or B CDL with passenger endorsement is required.** Green Way Shuttles is a professional student transportation company. We are currently hiring Part-Time Shuttle Bus Drivers in the Morgantown, WV area! Drive local! Responsibilities: Transporting... 

Teksky

Food Quality Assurance Manager Job at Teksky

 ...Qualifications Experience in Quality Assurance, Quality Control, and conducting inspections and audits Knowledge of regulatory...  ...work on-site in Pine Bluff, Arkansas Bachelor's degree in Food Science, Chemistry, Microbiology, or a related field... 

NLP Dominos

Loudon - Domino's Pizza Maker Job at NLP Dominos

 ...TN Job Summary Are you looking for a fun, flexible job where you can interact with people? Domino's is seeking enthusiastic individuals to join our team as a Pizza Maker. Whether you're looking for a main gig, a hobby, or a supplemental job, we have... 

Fenco Solutions

Marketing and Digital Content Specialist Job at Fenco Solutions

 ...Job Description Job description: Now Hiring: Marketing & Digital Content Specialist Drive engagement. Build content. Boost visibility. We...  ...with lead generation strategies, marketing automation, and email marketing campaigns You Might Be a Great Fit If You...