Cyber Threat Investigator
4 days ago
Description :Manage security event monitoring and incident response using SIEM platforms, with preference for Azure Sentinel and ArcSight. Analyze and respond to security events from diverse sources such as firewalls, IDS/IPS, antivirus solutions, DAM systems, web servers, proxies, and banking applications. Develop and maintain alert rules and logic within SIEM to ensure accurate detection of security events. Assist senior personnel in managing complex security incidents and improving incident response times.Job Purpose :Administration:Responsible for threat-hunting by proactively identifying and mitigating advanced threats within an organization’s networkThis role involves working closely with the security operations team to enhance organization’s cybersecurity posture by proactively identifying and mitigating advanced threatsKey Result Areas :Proactive Threat Hunting: Conduct proactive threat hunting activities to identify and isolate advanced threats that may bypass traditional security measures over network, endpoints, and cloud environments, searching for indicators of compromise (IOCs), advanced persistent threats (APTs), and other hidden adversary activityUtilize advanced analytical techniques such as behavioral analysis, anomaly detection, and machine learning to identify emerging threats and patternsLeveraging threat intelligence (both internal and external) to correlate and enhance hunting activities and adapt to new attack tactics, techniques, and procedures (TTPs).Develop and apply hunting frameworks and methodologies to continuously improve detection capabilities. This includes leveraging frameworks like MITRE ATT&CK for understanding adversary tactics and behaviors.Data Analysis: Analyze large datasets, network traffic, and user behavior to detect anomalies and potential security breachesHypothesis Development: Develop and test hypotheses about potential malicious activities within the organization’s environment.Incident Response: Collaborate with the incident response team to investigate and respond to identified threats.Threat Intelligence Integration: Utilize threat intelligence to inform and enhance threat hunting activities.Reporting and Documentation: Document findings, create detailed reports, and communicate results to stakeholders.Continuous Improvement: Stay updated with the latest threat landscapes, attack techniques, and security technologies to continuously improve threat hunting methodologies.Key Principles :Alignment with Business Priorities: Provide strategic direction and oversight of threat-hunting process, ensuring alignment with organizational goals and objectivesOwnership and Accountability: The threat hunting manager takes full responsibility for activities and the holding self and team accountable for their outcomes.Driving Threat hunting Maturity Enhancement: This role proactively drives initiatives that enhance incident response and resilient cyber posture.Focus on Outputs and Impact: Focus on delivering outputs that create meaningful impact such as enhanced security culture and protection posture of the bank.Innovation and Automation: Continuously seek innovative solutions and automated processes for efficiency.Continuous Learning and Improvement: Committed to learning from experiences and continuously improving the processes and outcomes.Key skills :Essential knowledgeHave over 10+ years of rich experience in information security domain and at least 4-6 years of dedicated experience in Threat-hunting.Proficiency in using threat intel platforms such as CybelAngel, ThreatConnect, Recorded Future, DarkTrace etc.Proficiency in using SIEM and SOAR solutions.Strong understanding of network protocols and security technologies.Strong understanding of endpoint detection and response (EDR) tools.Excellent analytical and problem-solving skillsPreferably worked in BFSI domain with proven experience in SOC function.Knowledge of key security standards and regulations such as NIST 800-61, CERT/CC, ISO 27035 etc.Skills and ApplicationMaintaining up-to-date knowledge of security landscape, threats, attack patterns and counter measuresAssess and design threat-hunting processes through solutions, tools and methodologiesReviewing use cases/playbooks for integrating threat-intelContinuously monitor security hygiene and performance using tools and processesCollaborate with other IS teams, Ops and tech teams on enhancing security incident response resilienceOtherKnowledge of evolving advanced tech stacks and related control and risk universe from a threat-hunting perspective.The ideal candidate will have a technical or computer science degree.Professional certifications : GCIH, CISSP, CEH,etc.
-
Cyber Threat Investigator
3 days ago
Bangalore, India Mashreq Full timeDescription : Manage security event monitoring and incident response using SIEM platforms, with preference for Azure Sentinel and ArcSight. Analyze and respond to security events from diverse sources such as firewalls, IDS/IPS, antivirus solutions, DAM systems, web servers, proxies, and banking applications. Develop and maintain alert rules and logic within...
-
Cyber Threat Investigator
3 days ago
Bangalore Division, India Mashreq Full timeDescription : Manage security event monitoring and incident response using SIEM platforms, with preference for Azure Sentinel and ArcSight. Analyze and respond to security events from diverse sources such as firewalls, IDS/IPS, antivirus solutions, DAM systems, web servers, proxies, and banking applications. Develop and maintain alert rules and logic within...
-
Cyber Threat Investigator
4 days ago
bangalore district, India Mashreq Full timeDescription : Manage security event monitoring and incident response using SIEM platforms, with preference for Azure Sentinel and ArcSight. Analyze and respond to security events from diverse sources such as firewalls, IDS/IPS, antivirus solutions, DAM systems, web servers, proxies, and banking applications. Develop and maintain alert rules and logic within...
-
Cyber Threat Intelligence Intern
14 hours ago
bangalore, India cloudDFN Full timeWe’re hiring a Cyber Threat Intelligence (CTI) Research Intern If you love digging through the internet’s dark corners, playing with OSINT tools, and writing Python scripts to make sense of chaos, you’ll enjoy this.You’ll help us track, analyze, and report on emerging cyber threats — with a strong focus on dark web and open-source intelligence...
-
Cyber Threat Intelligence Intern
7 hours ago
bangalore, India cloudDFN Full timeWe’re hiring a Cyber Threat Intelligence (CTI) Research Intern If you love digging through the internet’s dark corners, playing with OSINT tools, and writing Python scripts to make sense of chaos, you’ll enjoy this. You’ll help us track, analyze, and report on emerging cyber threats — with a strong focus on dark web and open-source intelligence...
-
Threat Research Analyst
1 week ago
bangalore, India ZeroFox Full timeZeroFox is a leading external cybersecurity company that provides enterprises with a comprehensive platform to protect against threats outside the perimeter. We combine artificial intelligence with human expertise to deliver advanced threat intelligence, digital risk protection, and adversary disruption.We are seeking a highly motivated and experienced...
-
bangalore, India CloudSEK Full timeWHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal We believe that work and the workplace should be joyful and always buzzing with energyCloudSEK, one of India's most trusted Cyber security product companies, is on a mission to build the world's fastest and most reliable AI technology that...
-
Threat Intelligence Analyst
1 week ago
bangalore, India StoneX Group Full timeOverviewAs a Threat Intelligence Analyst, you will be responsible for supporting the threat intelligence function at StoneX. You will work closely with the Exposure Management Manager and Threat Intelligence Lead Analyst to provide timely situational awareness, translate cyber threats into actionable information to ensure resources are focused on the right...
-
Cyber Incident Handler
2 weeks ago
bangalore, India 3Columns Full time3Columns is a specialist cybersecurity firm that delivers a wide range of services, including security assurance, security governance, professional services, and managed services. Solutions include managed security services, offensive security services, cybersecurity consulting, and professional services to help customers deploy all the necessary controls....
-
Threat Intelligence Analyst
3 weeks ago
bangalore, India NTT DATA, Inc. Full timeRole : Threat Intelligence Analyst - L2 Location: Mumbai– Client Site Work Mode: Work from Office Payroll: NTT Data Budget: ₹15 LPA (Including 5% variable) Notice Period: Immediate to 30 days only Requirement Brief : · Minimum 5 years of experience in Threat intelligence. · Only candidates who are expert on Threat Intelligence platform. · CTIA/CEH/CSA...