Cyber Threat Investigator

2 weeks ago


Bengaluru Karnataka India, Karnataka Mashreq Full time

Description :


Manage security event monitoring and incident response using SIEM platforms, with preference for Azure Sentinel and ArcSight. Analyze and respond to security events from diverse sources such as firewalls, IDS/IPS, antivirus solutions, DAM systems, web servers, proxies, and banking applications. Develop and maintain alert rules and logic within SIEM to ensure accurate detection of security events. Assist senior personnel in managing complex security incidents and improving incident response times.


Job Purpose :


Administration:

Responsible for threat-hunting by proactively identifying and mitigating advanced threats within an organization’s network


This role involves working closely with the security operations team to enhance organization’s cybersecurity posture by proactively identifying and mitigating advanced threats


Key Result Areas :

  • Proactive Threat Hunting: Conduct proactive threat hunting activities to identify and isolate advanced threats that may bypass traditional security measures over network, endpoints, and cloud environments, searching for indicators of compromise (IOCs), advanced persistent threats (APTs), and other hidden adversary activity
  • Utilize advanced analytical techniques such as behavioral analysis, anomaly detection, and machine learning to identify emerging threats and patterns
  • Leveraging threat intelligence (both internal and external) to correlate and enhance hunting activities and adapt to new attack tactics, techniques, and procedures (TTPs).
  • Develop and apply hunting frameworks and methodologies to continuously improve detection capabilities. This includes leveraging frameworks like MITRE ATT&CK for understanding adversary tactics and behaviors.
  • Data Analysis: Analyze large datasets, network traffic, and user behavior to detect anomalies and potential security breaches
  • Hypothesis Development: Develop and test hypotheses about potential malicious activities within the organization’s environment.
  • Incident Response: Collaborate with the incident response team to investigate and respond to identified threats.
  • Threat Intelligence Integration: Utilize threat intelligence to inform and enhance threat hunting activities.
  • Reporting and Documentation: Document findings, create detailed reports, and communicate results to stakeholders.
  • Continuous Improvement: Stay updated with the latest threat landscapes, attack techniques, and security technologies to continuously improve threat hunting methodologies.

Key Principles :


  • Alignment with Business Priorities: Provide strategic direction and oversight of threat-hunting process, ensuring alignment with organizational goals and objectives
  • Ownership and Accountability: The threat hunting manager takes full responsibility for activities and the holding self and team accountable for their outcomes.
  • Driving Threat hunting Maturity Enhancement: This role proactively drives initiatives that enhance incident response and resilient cyber posture.
  • Focus on Outputs and Impact: Focus on delivering outputs that create meaningful impact such as enhanced security culture and protection posture of the bank.
  • Innovation and Automation: Continuously seek innovative solutions and automated processes for efficiency.

Continuous Learning and Improvement: Committed to learning from experiences and continuously improving the processes and outcomes.


Key skills :

Essential knowledge

  • Have over 10+ years of rich experience in information security domain and at least 4-6 years of dedicated experience in Threat-hunting.
  • Proficiency in using threat intel platforms such as CybelAngel, ThreatConnect, Recorded Future, DarkTrace etc.
  • Proficiency in using SIEM and SOAR solutions.
  • Strong understanding of network protocols and security technologies.
  • Strong understanding of endpoint detection and response (EDR) tools.
  • Excellent analytical and problem-solving skills
  • Preferably worked in BFSI domain with proven experience in SOC function.
  • Knowledge of key security standards and regulations such as NIST 800-61, CERT/CC, ISO 27035 etc.


Skills and Application

  • Maintaining up-to-date knowledge of security landscape, threats, attack patterns and counter measures
  • Assess and design threat-hunting processes through solutions, tools and methodologies
  • Reviewing use cases/playbooks for integrating threat-intel
  • Continuously monitor security hygiene and performance using tools and processes
  • Collaborate with other IS teams, Ops and tech teams on enhancing security incident response resilience


Other

  • Knowledge of evolving advanced tech stacks and related control and risk universe from a threat-hunting perspective.
  • The ideal candidate will have a technical or computer science degree.
  • Professional certifications : GCIH, CISSP, CEH,etc.



  • Bengaluru, Karnataka, India ColorTokens Inc. Full time

    About ColorTokensAt ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by preventing the lateral spread of ransomware and advanced malware. We enable organizations to...


  • Bengaluru, Karnataka, India CloudSEK Full time

    Are you a cybersecurity enthusiast who enjoys detective work and applying it to real-world threat tracking? Do you thrive on correlating rapidly evolving cybersecurity incidents and tech innovations, aspiring to build an AI-proof career? I just wanted to let you know that this position is for you.What are your Day-to-Day Responsibilities?You will be pivotal...


  • Bengaluru, Karnataka, India dentsu Full time ₹ 4,00,000 - ₹ 12,00,000 per year

    The purpose of this role is to work as part of a team to implement an organised approach to addressing and managing security requests,breaches or cyberattacks. Performing investigations, providing reports with recommendations and root cause analysis.Job Description:Key responsibilities:Performs response analytics during and after an incident, determine root...


  • Bengaluru, Karnataka, India, Karnataka CloudSEK Full time

    WHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal! We believe that work and the workplace should be joyful and always buzzing with energy!CloudSEK, one of India’s most trusted Cyber security product companies, is on a mission to build the world’s fastest and most reliable AI technology...


  • Bengaluru, Karnataka, India CloudSek Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    WHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal We believe that work and the workplace should be joyful and always buzzing with energyCloudSEK, one of India's most trusted Cyber security product companies, is on a mission to build the world's fastest and most reliable AI technology that...


  • Bengaluru, Karnataka, India, Karnataka Embitel Technologies Full time

    We are seeking a highly skilled and detail-oriented Cyber Security Specialist to protect our organization's digital assets and infrastructure from cyber threats. The ideal candidate will have a strong background in network and information security, threat detection, incident response, and risk management. You will be responsible for implementing security...


  • Bengaluru, Karnataka, India thehivecareers Full time

    About the job Cyber Security AnalystThe Cyber Security Analyst will be responsible for protecting all of the company's hardware, software, and networks from cybercriminals. The analyst's primary role will be to understand the company IT infrastructure in detail in order to detect, evaluate and respond to threats that could potentially breach the network. The...


  • Bengaluru, Karnataka, India Commonwealth Bank of Australia Full time

    Organization: At CommBank, we never lose sight of the role we play in other people's financial wellbeing. Our focus is to help people and businesses move forward to progress. To make the right financial decisions and achieve their dreams, targets, and aspirations. Regardless of where you work within our organisation, your initiative, talent, ideas, and...


  • Bengaluru, Karnataka, India Cyble Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    About Cyble:Cyble is revolutionizing the landscape of cybersecurity intelligence. Founded in 2019, Cyble began as a visionary college project and has quickly transformed into a leading force in proactive cyber threat detection and mitigation, that is now globally significant, with people in 20 countries - Headquartered in Alpharetta, Georgia, and with...


  • Bengaluru, Karnataka, India CloudSEK Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    WHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal We believe that work and the workplace should be joyful and always buzzing with energyCloudSEK, one of India's most trusted Cyber security product companies, is on a mission to build the world's fastest and most reliable AI technology that...