
Principal Threat Researcher/ Associate Principal Threat Researcher
Saviynt
Posted 2026-06-01
Tech & Engg
Job Description
Ovii's Interpretation of the Role
The Principal Threat Researcher will lead identity‑centric threat research, design detection algorithms, and mentor junior researchers. This senior individual contributor partners with product and engineering to turn advanced threat insights into Saviynt’s next‑generation ITDR platform.
Role Snapshot
- Lead identity threat research
- Design and prototype detection algorithms
- Mentor junior researchers
- Collaborate with product & engineering
- Publish research and drive patents
Must-Have Requirements
- 12+ years cybersecurity experience
- 5+ years threat research/intelligence/detection engineering
- Threat intelligence pivoting
- MITRE ATT&CK / ATLAS / MAESTRO framework expertise
- Identity attack technique knowledge
- Python, Go, Bash scripting
- Data mining & OSINT
- YARA / Snort / Sigma rule development
- SIEM query language proficiency (Splunk SPL, KQL)
- AI/ML working knowledge for threat research
- cybersecurity
- threat research
Nice-to-Have Signals
- Algorithmic prototyping of detection algorithms
- Advanced query languages for data analysis
- Deep cloud IAM expertise (AWS IAM, Azure AD/Entra ID, GCP Cloud Identity)
- Familiarity with Mimikatz, BloodHound, Rubeus
- algorithmic prototyping
- AI/ML
Work Setup
- Location: Bengaluru, India
- Work mode: HYBRID
- Remote scope: UNSPECIFIED
- Travel: global travel for conferences and syncs
- Employment type: Full-Time
Eligibility Gates
- Visa sponsorship: unknown
Application Requirements
- Portfolio required
Not Specified in JD
- Salary range
- Visa sponsorship
- Equity
- Bonus
- Remote eligibility
What You'll Likely Work On
- Spearhead advanced research on novel identity‑centric vulnerabilities across hybrid and multi‑cloud environments
- Build and refine behavioral models using telemetry and user activity logs to detect stealthy identity threats
- Translate research findings into high‑fidelity detection features and telemetry for the ITDR platform
- Conduct proactive threat hunting on identity infrastructures such as Active Directory, Entra ID, Okta, and PAM
- Map detection strategies to MITRE ATT&CK, ATLAS, and MAESTRO frameworks
- Architect detection rules, baselines, and correlation logic to surface anomalous identity behavior
- Publish blogs, technical reports, and represent Saviynt at conferences while pursuing patents and CVEs
- Mentor junior researchers and raise the technical bar of the Threat Research team
Good Fit If You Have
- Strong communication skills for translating technical research into product requirements
- Proven track record of thought leadership (blogs, papers, patents, CVEs)
- Ability to work collaboratively across product and engineering functions
Skills
- Threat intelligence analysis
- MITRE ATT&CK / ATLAS / MAESTRO frameworks
- Identity attack techniques
- Python, Go, Bash scripting
- Data mining & OSINT
- YARA / Snort / Sigma rule creation
- SIEM query languages (Splunk SPL, KQL)
- AI/ML for threat research
- Cloud IAM (AWS, Azure, GCP) knowledge