Skip to content

Open nowPosted 3 days ago

Associate Principal Engineer - Threat Researcher

Saviynt75 open roles

Where
Bengaluru
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAssociate Principal Engineer - Threat ResearcherSaviynt · Bengaluru
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Saviynt's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

The posting

Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust Saviynt to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, Saviynt is today helping organizations safely accelerate their deployment and usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the world’s leading brands, Fortune 500 companies and government institutions. For more information, please visit www.saviynt.com.

Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust Saviynt to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, Saviynt is today helping organizations safely accelerate their deployment and usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the world’s leading brands, Fortune 500 companies and government institutions. For more information, please visit www.saviynt.com.

Saviynt is seeking a visionary and highly technical Senior Principal Threat Researcher to pioneer the future of Identity Threat Detection and Response (ITDR). In this senior-level role, you will be a cornerstone of our broader Threat Research Team, working in lockstep with Product Management and Engineering to architect and deliver Saviynt’s next-generation ITDR product.

You will lead from the front, anticipating how threat actors exploit infrastructure, and translating those insights into industry-leading detection capabilities and thought leadership.

What will you be doing?

  • Spearhead Identity Threat Research: Lead advanced research initiatives focused on uncovering and understanding novel identity-centric vulnerabilities (Human Identity(HI), Non Human Identity(NHI), Agentic Identity) based attack vectors, and exploit chains across hybrid and multi-cloud environments.
  • Data-Driven Behavioral Modeling: Leverage vast telemetry from multi-cloud environments, disparate data sources, and user activity logs to conduct deep behavioral analysis. You will be a domain expert and work with an extended team to develop and refine sophisticated behavioral models to detect anomalies, uncovering stealthy, suspicious identity threat patterns that bypass traditional signature-based detection.
  • Drive Product Innovation: Partner closely with Product Managers and Engineering teams to translate complex threat research into actionable product features, robust detection algorithms, and high-fidelity telemetry for our next-generation ITDR platform.
  • Execute Advanced Threat Hunting & Intelligence: Conduct proactive threat intelligence gathering and sophisticated threat hunting specifically targeting Identity vulnerabilities (e.g., Active Directory, Entra ID, Okta, PAM, and Cloud IAM misconfigurations).
  • Operationalize Security Frameworks: Extensively utilize and map research to industry-standard frameworks, including MITRE ATT&CK, MITRE ATLAS, and MAESTRO, ensuring our detection strategies comprehensively cover modern adversary Tactics, Techniques, and Procedures (TTPs).
  • Pioneer Detection Engineering: Architect and develop advanced detection strategies, behavioral baselines, and correlation rules to identify anomalous identity behaviors, privilege escalation, and lateral movement.
  • Establish Thought Leadership: Serve as a highly visible ambassador for Saviynt’s research capabilities. You will regularly author and publish high-quality blogs, and technical reports on emerging threats.
  • Drive Patentable Innovation: Foster a culture of exemplary, bleeding-edge innovation within the team, actively pursuing research that leads to industry publications, CVE discoveries, and patents for Saviynt.
  • Mentor and Guide: Act as a senior technical authority, mentoring junior researchers and elevating the overall technical acumen of the Threat Research and Engineering organizations.

What you will bring?

  • Extensive Industry Experience: 12+ years of progressive experience in cybersecurity, with a minimum of 5+ years dedicated specifically to Threat Research, Threat Intelligence, or advanced Detection Engineering at a senior/lead level.
  • Technical & Analytical Skills:
  • Threat Intelligence Pivoting: Tracing connections between seemingly unrelated data points (e.g., IPs, domain names, hashes) to attribute attacks to specific threat actors or Advanced Persistent Threats (APTs).
  • Security Frameworks: Applying industry models to classify and map adversary behavior, such as the MITRE ATT&CK framework, ATLAS, and MAESTRO.
  • Attack Vectors: Knowledge of Identity based attacks such as Pass-the-Hash/Ticket, Golden/Silver Tickets, MFA Fatigue (Prompt Bombing), Token Theft, Kerberosting and Credential Stuffing.
  • Adversary Tradecraft: Familiarity with tools threat actors use to map and exploit identity environments, such as Mimikatz, BloodHound, Rubeus
  • Vulnerability & Exploit Research: Assessing zero-day flaws, evaluating proof-of-concept (PoC) exploits, and testing patching strategies.
  • Programming & Scripting: Familiarity with scripting and programming languages (e.g., Python, Go, Bash) to help rapidly engineer complex detection algorithms and prototype innovative feature proof-of-concepts (POCs).
  • Data Mining & OSINT: Gathering threat intelligence from various sources like Open Source Intelligence (OSINT), dark web forums, threat feeds, and internal telemetry.
  • Rule/Signature Development: Creating custom detection logic for monitoring platforms (e.g., building YARA or Snort rules), experience writing detection logic using SIEM query languages (Splunk SPL, KQL) or universal formats like Sigma.
  • AI/ML in Threat Research: Working knowledge of leveraging Artificial Intelligence and Machine Learning technologies to aid in threat research, scale threat hunting capabilities, or improve the fidelity of detection mechanisms, Agentic AI usage and understanding of the upcoming Agentic AI threats.
  • A Portfolio of Excellence: A demonstrated track record of thought leadership, including published white papers, popular cybersecurity blogs, conference speaking engagements, patents, or acknowledged CVEs.
  • Cross-Functional Leadership Skills: Exceptional communication skills with the proven ability to distill complex, highly technical research into clear, actionable requirements for Product Management and Engineering teams.
  • Algorithmic Prototyping: Good-to-have skills in developing and prototyping complex detection algorithms, familiarity with advanced query languages used in data analysis.
  • Identity Security Expertise: Understanding of Identity and Access Management (IAM), Privileged Access Management (PAM), and cloud identity architectures (AWS IAM, Azure AD/Entra ID, GCP Cloud Identity, Active Directory). Understanding how identity works in AWS (IAM Roles, Policies), GCP (Cloud Identity), and Azure
  • Logistical Flexibility:
  • Willing to work in a Hybrid model from our Bengaluru office.
  • Willingness to undertake some travel globally based on business requirements, industry conferences, and strategic team syncs.

Saviynt is an amazing place to work. We are a high-growth, Platform as a Service company focused on Identity Authority to power and protect the world at work. You will experience tremendous growth and learning opportunities through challenging yet rewarding work which directly impacts our customers, all within a welcoming and positive work environment. If you're resilient and enjoy working in a dynamic environment you belong with us!

Security & Compliance This role requires adherence to Saviynt’s information security and privacy policies and procedures, including annual security training.

Saviynt is an equal opportunity employer and we welcome everyone to our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Saviynt's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Saviynt's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Saviynt's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.