Threat Hunter and Incident Response Expert

2 weeks ago


Gurgaon, India Coralogix Full time

Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Towards this end, Snowbit, built off years of Israeli cybersecurity experience, offers the broadest managed detection and response offering available today.

Snowbit is part of the Coralogix group. Coralogix is rebuilding the path to log observability by offloading the burden of indexing and providing deep insights into accumulated data, at an infinite scale, for less than half the cost.

This is a team of experts with vast cybersecurity experience focused on research on cloud and enterprise systems to identify emerging threat trends/vectors as well as gaps and opportunities within existing enterprise cybersecurity frameworks.

**What Will you do?**
- **Threat hunt** inside our customer logs and environments to discover existing malware or threat actors that compromised their network.
- Treat **incident response** cases from start to finish, including identifying the threats, machine/network/cloud forensics, creating timelines, and consulting customers on IR and mitigation steps.
- Producing reports for customers on your threat hunting / Incident response cases.
- Research emerging attacks, technologies, threats, and vulnerabilities in SaaS and enterprise products and create actionable alerting scenarios to catch them through Coralogix/Snowbit system.
- Investigate logs from security systems to detect intrusions or misconfigurations and create detections based on your findings.
- Write detection rules documentation with actionable recommendations for mitigations.
- Publish your findings internally for customers and externally for blog/marketing needs.
- Work with our customers to investigate anomalies and incidents and create custom detections and next step recommendations.

**Responsibilities will include**:

- **On-demand Incident response** treatment for serious incidents raised by our Security resource center or customers.
- **Research new attack vectors**, including identification, with respect to novel attack vectors including their iteration/evolution and related mitigations across the enterprise IT landscape.
- Collaborate with Product and Engineering to leverage research findings to evolve Snowbit product and knowledge base.
- Be a knowledge source for new and emerging threats, incident response processes, and threat-hunting activities including mentoring the team on your findings and methods.
- Evaluate & recommend new security technologies and help shape the product with your insights and expertise.
- Regular updates to internal teams and customers on research findings.
- Active participation in public cybersecurity media/forums/events.

**Requirements**:

- 5+ years of experience in **hands-on** **threat hunting and incident response** in large, complex, security organizations and a proven track record in cybersecurity research, specializing in either APTs or cybercrime.
- Hands-on experience in threat hunting and incident response on **cloud environments** (AWS, Azure, GCP) and SaaS products (Okta, Google workspaces, Github etc).
- Experience in securing on-prem, cloud and SaaS environments and how organizations protect themselves from attacks (including hands-on experience with common tools and products - FW, IDS/IPS, WAF, EDRs, SIEM etc). familiarity with common **cloud and SaaS attack vectors **and misconfigurations.
- Hands-on experience with **machine forensics **including analyzing disk, memory, and network artifacts on **Windows and Linux machines**.
- Hands-on experience with **malware analysis / DFIR** in a custom-built sandbox environment (Dynamic & Static, including tools like - IDA Pro, Ollydbg, Wireshark),

**Reverse engineering** experience - **a plus**.
- Solid understanding of the** cyber security kill chain** (MITRE ATT&CK/D3FEND), identifying security vulnerabilities, typical attacker exploit techniques, and related mitigations and remediations.
- Experience in **working closely with customers** from the alert phase, through treat hunting, raising, and treating an incident (including machine forensics as needed) including the removal of the threat and producing a concluding report for the customer.
- Great communication skills - Fluent in english, spoken and written with a positive and helpful attitude.
- Hands-on experience with **query languages** (Kibana/KQL/Lucene, Splunk), working with JSON files and writing complex queries and rules.
- Development of threat hunting automation (threat hunting scripts, IOC gathering scripts) - **a big plus.**
- **An innovative mind with keen attention to detail and the ability to set his own goals and parameters for success, investigate and implement solutions and recommendations for the customer benefit.



  • Gurugram, Gurgaon / Gurugram, India SBI Card Full time

    A- Define and Manage processes around insider threat management - Manage Insider Threat Monitoring program by ensuring processing security alerts generated by the various monitoring tools and technologies operated by the team in order to identify potential instances of data loss / exfiltration and other activity which may pose a potential Insider Threat...


  • Gurgaon, India Boston Scientific Full time

    Additional Locations: India-Haryana, Gurgaon Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most important health industry challenges....

  • Security Expert

    6 days ago


    Gurgaon, India Orange Business Services Full time

    **About the role**: 1) Primary responsibility is to provide Tier 2 network security support of Firewall environments supporting multiple customers. 2) This position interfaces with external clients and is highly visible. 3) Responsible for general architecture, initial configurations and subsequent management of one or more Firewall/VPN based/IPS/Proxy...

  • Security Analyst

    3 weeks ago


    Gurgaon,Gurugram, India Sampoorna Consultants Pvt. Ltd Full time

    Role and responsibilities:- Perform investigations, threat hunting and work cases as needed- Act as an escalation point for Tier 1- Communicate with customers regarding security related incidents- Assist in threat signature implementation and tuning- Define and mature 'playbooks' for response to cyber threats- Provide teaching/mentoring to junior...

  • Security Analyst

    5 days ago


    Gurgaon/Gurugram, India Sampoorna Consultants Pvt. Ltd Full time

    Role and responsibilities:- Perform investigations, threat hunting and work cases as needed- Act as an escalation point for Tier 1- Communicate with customers regarding security related incidents- Assist in threat signature implementation and tuning- Define and mature 'playbooks' for response to cyber threats- Provide teaching/mentoring to junior...

  • Security Analyst

    2 weeks ago


    Gurgaon/Gurugram, IN Sampoorna Consultants Pvt. Ltd Full time

    Role and responsibilities:- Perform investigations, threat hunting and work cases as needed- Act as an escalation point for Tier 1- Communicate with customers regarding security related incidents- Assist in threat signature implementation and tuning- Define and mature 'playbooks' for response to cyber threats- Provide teaching/mentoring to junior...


  • Gurgaon, India Coralogix Full time

    **About The Position** Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Towards this end, Snowbit, built off years of Israeli cybersecurity experience, offers the broadest managed detection and response...


  • Gurgaon, India V-Konnect Associates Full time

    **Job Opening Details** **back to list** - Reference Code: - VK22936 - Job Title: **Fraud Process Monitoring** - Category: - Job Description: - Role Summary/Purpose - Wing to wing review and closure of the identified decision gaps and observations while auditing/monitoring fraud prevention processes. Ensuring rectification of the errors highlighted...


  • Gurgaon,Gurugram, India Right Advisors Pvt. Ltd. Full time

    Experience : 6 - 8 yearsLocation : GurugramQualification : Any Graduation Degree in ITMandatory Skills Required : Cyber Security, Incident Response, EDR, SIEM, Mail Analysis & Security, Cloud Security ( Azure/ AWS), Threat IntelligenceGood to have : CEH (Certified Ethical Hacking)Job Description : - Computer Science or Information Systems major related field...


  • Gurgaon, India ixigo Full time

    We are seeking a seasoned Senior Security Expert with a strong focus on cybersecurity compliance and management. The ideal candidate will have over 5 years of experience in the field of cybersecurity, with a proven track record of managing complex security systems. The candidate will also have a deep understanding of security testing methodologies, as well...

  • SOC L2

    3 days ago


    Gurgaon, India NMS Consultant Full time

    From 2 to 6 year(s) of experience ₹ Not Disclosed by Recruiter - Gurgaon/Gurugram **JOB TITLE**: Cyber Security Analyst **LOCATION**: Gurugram, India **ROLES & RESPONSIBILITIES**: Provide incident response as part of the 24x7 Security Operations Centre Monitoring of events & alerts from a multitude of technologies to detect malicious...


  • Gurgaon,Gurugram, India Sampoorna Consultants Pvt. Ltd Full time

    Responsibilities :- Primarily responsible for directing security event monitoring, management and response and cyber intelligence- Responsible for the SOC as part of the overall IT Security strategy- Responsible for team & vendor management, overall use of resources and initiation of corrective action where required for Security Operations Center- Ensuring...


  • Gurgaon/Gurugram, India Sampoorna Consultants Pvt. Ltd Full time

    Responsibilities :- Primarily responsible for directing security event monitoring, management and response and cyber intelligence- Responsible for the SOC as part of the overall IT Security strategy- Responsible for team & vendor management, overall use of resources and initiation of corrective action where required for Security Operations Center- Ensuring...


  • Gurgaon/Gurugram, IN Sampoorna Consultants Pvt. Ltd Full time

    Responsibilities :- Primarily responsible for directing security event monitoring, management and response and cyber intelligence- Responsible for the SOC as part of the overall IT Security strategy- Responsible for team & vendor management, overall use of resources and initiation of corrective action where required for Security Operations Center- Ensuring...

  • Subject Matter Expert

    3 hours ago


    Gurgaon, India Orange Business Full time

    **About the role**: Act as Technical/Solution Expert for Paloalto Prisma SDWAN Understand complex design of SDWAN setup & also solution suggested as per customer requirement. Plan, Transition, Transformation, Green field/organic growth deployment and support - SDWAN Products -Prisma SDWAN Prepare Site Requirements, High Level, and Low Level Design &...

  • Gds Travel Expert

    3 days ago


    Gurgaon, India Fly Business Class Full time

    Overview of Role: Fly Business Class is looking for a gds travel expert to find an build exceptional airline tickets in the marketplace to deliver excellent products to our clients. The GDS experts are expected to provide a deep insight of the available products to Travel Consultants Experts are expected to provide new methods of finding prices below market...


  • Gurgaon, India Expert Staffing Solutions Full time

    From 2 to 7 year(s) of experience - ₹ 3,50,000 - 8,50,000 P.A. - Gurgaon/Gurugram, Delhi / NCR**Roles and Responsibilities** Hiring for Collections/ Customer Service with US MNC based in Gurgaon (Hybrid). US Process Salary upto 10 LPA + Lucrative Incentives. 5 days working.. Voice Process. Both way Cabs!! ASAP Joining!! Graduate/ Under graduate with...


  • Gurgaon, India OAC Full time

    **F5 WAF Security L3 + TrendMicro** **Location - Gurugram** **Services Window: 9*5 willing to work 24/7 support.** **Education -Graduate in any stream** **Skills/Experience required** minimum 10 years of experience on F5 WAF solution experience on threat hunting model and Mitre framework He should have experience on ITIL process experience Trend...


  • Gurgaon,Gurugram, India Fresher Mart. Full time

    RESPONSIBILITIES : - Manage and support Network security team, implementation of Network Security projects like ZTNA, Virtual & perimeter firewalls.- Collaborate with other security and IT teams including IT infrastructure, OT Engineering, Application teams to implement and enforce Network security policies.- Proactively monitor network traffic for anomalies...


  • Gurgaon/Gurugram, IN Fresher Mart. Full time

    RESPONSIBILITIES : - Manage and support Network security team, implementation of Network Security projects like ZTNA, Virtual & perimeter firewalls.- Collaborate with other security and IT teams including IT infrastructure, OT Engineering, Application teams to implement and enforce Network security policies.- Proactively monitor network traffic for anomalies...