Threat Hunter Ii
4 days ago
Who we are:
We are the Security, Compliance and Management (S+C+M) team; we are committed to defending Microsoft customers from cyber-attacks as well as providing sophisticated tooling for securing important data. S+C fosters an agile development environment, continuously gathering and analyzing data to combat evolving threats. Our mission is to help protect customers with truly innovative proactive protection, advise customers on emerging trends, and engage in valuable partnerships.
As the Research organization within S+C, it’s our job to stay one step ahead of malicious adversaries and predict the threats of the future. We work with partners across Microsoft to innovate new approaches for detecting and tracking threats, attacker techniques, their tools and infrastructure.
We are always learning. Insatiably curious. We lean into uncertainty, take risks, and learn quickly from our mistakes. We build on each other’s ideas, because we are better together. We stand in awe of what humans dare to achieve and are motivated every day to empower others to do and achieve more through our technology and innovation. Together we make a difference for all of our customers, from end-users to Fortune 50 enterprises.
**Responsibilities**:
What we build:
We build innovative security and data compliance products. Our security products are brought together in the Microsoft 365 Defender (M365D) suite. M365D enables Microsoft’s enterprise customers to detect, investigate, understand, and respond to advanced threats on their networks via a combination of behavioral sensors, cloud security analytics, and threat intelligence.
The Microsoft Threat Experts Team is looking for threat hunters No matter how sophisticated attacker behaviors become, Microsoft 365 Defender (M365D) will help enterprises detect, investigate, and respond to advanced attacks and data breaches on their networks. Our team uses deep knowledge of the attacker landscape and rich telemetry from our sensors to perform root-cause analysis and generate custom alerts, ensuring that M365D customers are well equipped to quickly respond to human adversaries identified in their unique environments.
Ensuring that no human adversary can operate silently begins with experts harnessing the powerful optics provided by M365D, across the attacker kill-chain, coupled with world-class detections. We’re looking for a skilled hunter to harness the power of Microsoft’s trillions of security signals to quickly identify and report the latest human adversary behaviors, drive critical context-rich alerts, build new tools and automations in support of hunting objectives, and drive innovations for detecting advanced attacker tradecraft.
Primary responsibilities would include:
- Explore and correlate large data sets to uncover novel attack techniques, monitor and catalog changes in activity group tradecraft, to research and provide new detection mechanisms.
- Acquire new and leverage existing knowledge of attacker tools, tactics and procedures to improve security posture of customers.
- Self-driven and team cooperated research on novel attack techniques to simulate them in lab on endpoints and cloud infrastructure to identify required detection mechanisms.
- Identify need of required tools for research and analysis and effectively engage and collaborate with partners in engineering and data science to develop and maintain them.
- Effectively engage and collaborate with partners in data science, threat research to develop and maintain high-fidelity detection rules.
- Build hunting tools and automations for use in the discovery of human adversaries.
You would be expected to support a 24/7 operation model that may sometimes involve working in night shifts.
**Qualifications**:
Required experiences.
- 5+ years of experience in a technical role in the areas of Security Operations, Malware analysis, Threat Intelligence, Cyber Incident Response, or Penetration Testing/Red Team
- Comfortable working with extremely large data sets for analysis and visualization, using tools and scripting languages such as: Excel, SQL, Python, Splunk Query Language, Kusto query language and PowerBI
- Ability to track, analyze, and brief on new and ongoing cyber-attacks in cloud infrastructure with understanding on AAD, ADFS and popular authentication/authorization protocols like SAML, OAUTH, OpenID connect
- In-depth understanding of latest cloud-based techniques used by attackers for persistence, privilege escalation, defense evasion and lateral movement in platforms such as Azure AD, Office 365 and Google Workspace
- Functional understanding of common threat analysis models such as the Diamond Model, Cyber Kill Chain, and MITRE ATT&CK.
- Advanced experience using analysis tools (e.g. file/network/OS monitoring tools and/or debuggers) and advanced knowledge of operating system internals and security mechanisms
- Excellent cross-group and interpersonal skills, with the ability to articulate business
-
M365d Threat Hunter
4 days ago
Noida, India Microsoft Full timeWe are the Security, Compliance and Management (S+C+M) team; we are committed to defending Microsoft customers from cyber-attacks as well as providing sophisticated tooling for securing important data. S+C fosters an agile development environment, continuously gathering and analyzing data to combat evolving threats. Our mission is to help protect customers...
-
M365d Threat Hunter 2
4 days ago
Noida, India Microsoft Full timeWe are the Security, Compliance and Management (S+C+M) team; we are committed to defending Microsoft customers from cyber-attacks as well as providing sophisticated tooling for securing important data. S+C fosters an agile development environment, continuously gathering and analyzing data to combat evolving threats. Our mission is to help protect customers...
-
DFI/Threat Hunter Lead
3 weeks ago
Greater Noida, India Kyndryl Full timeWho We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The Role ...
-
Digital Forensics
5 days ago
Greater Noida, Uttar Pradesh, India Kyndryl Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAs a Cybersecurity Specialist, you will be at the forefront of protecting Kyndryl's customers computer systems and networks from unauthorized access, use, disclosure, disruption, modification, or destruction. You will use a variety of tools and techniques to defend against a wide range of cyber threats, such as malware, ransomware, phishing attacks, and data...
-
Automation Engineer
1 day ago
Noida, Uttar Pradesh, India Airtel Digital Full time ₹ 9,00,000 - ₹ 12,00,000 per yearSOAR Automation EngineerJob Description:ALevel 2 SOAR (Security Orchestration, Automation, and Response) Automation Engineeris responsible for designing, implementing, and maintaining automated security workflows to enhance an organization's incident detection, response, and remediation capabilities. This mid-level position works closely with SOC analysts,...
-
Software Engineer II
2 weeks ago
Noida, Uttar Pradesh, India Sumo Logic Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSoftware Engineer II (Backend) As a backend engineer you will be responsible to help create a scalable, reliable and performant log analytics platform for observability and security products to empower our customers to rapidly create high-quality analyses that enable them to react in real time to events and incidents. The logs ingest and query platform...
-
Noida, India ANALOG LEGAL HUB TECHNOLOGY SOLUTIONS PVT LTD Full timeDescription :About Credgenics:- Credgenics is Indias first of its kind NPA resolution platform backed by credible investors including Accel Partners and Titan Capital.- We work with financial institutions, Banks, NBFCs & Digital lending firms to improve the efficiency of their collection using technology, automation intelligence and optimal legal routes to...
-
Cybersecurity Specialist
4 days ago
IN NOIDA (IN) ARTHA INFRATE, India Kyndryl Solutions Private Limited Full time ₹ 8,00,000 - ₹ 12,00,000 per yearDFI/Threat Hunter Lead Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our...
-
Information Security Analyst II
2 days ago
Noida, Uttar Pradesh, India Monotype Full time ₹ 4,00,000 - ₹ 12,00,000 per yearInformation Security Analyst IIAre you our "TYPE"?Monotype (Global)Named "One of the Most Innovative Companies in Design" by Fast Company, Monotype brings brands to life through type and technology that consumers engage with every day. The company's rich legacy includes a library that can be traced back hundreds of years, featuring famed typefaces like...
-
IT Security Analyst II
5 days ago
Hyderabad, Noida, Pune, India IDESLABS PRIVATE LIMITED Full time ₹ 15,00,000 - ₹ 25,00,000 per yearTo be part of a global security operations center and be responsible for - proactively identify threats and vulnerabilities; implement industry best practices; participate in the review and resolution of opportunities from both internal and external IT security audits; provide recommendations to the overall IT security posture of the organization; and...