Cyber Intelligence

EY

Hyderabad

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

EY Hyderabad is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats impacting people, assets, operations, and customers. The role collaborates with SOC, Incident Response, Threat Hunting, and other security teams to improve detection, reduce risk, and support informed security decisions.

The position requires 7+ years in cyber threat intelligence or related fields, strong MITRE ATT&CK knowledge, and experience with SIEM/EDR/TIP platforms.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Intelligence Studies, or related field.
  • 7+ years of experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related cybersecurity disciplines.
  • Experience analyzing sophisticated cyber adversaries including nation-state, ransomware, financially motivated, and insider threats.
  • Strong understanding of the cyber kill chain and MITRE ATT&CK framework.
  • Experience with SIEM platforms such as Google SecOps, Splunk, Microsoft Sentinel, or QRadar.
  • Experience with EDR/XDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or VMware Carbon Black.
  • Experience working with threat intelligence platforms (TIPs).
  • Experience analyzing malware, phishing campaigns, vulnerabilities, and indicators of compromise.
  • Familiarity with cloud security across Microsoft Azure, AWS, and Google Cloud Platform.
  • Experience with Threat Intelligence Platforms (TIPs) such as Recorded Future, ThreatConnect, MISP, Anomali, or EclecticIQ.
  • Experience with Digital Risk Protection platforms.
  • Experience monitoring the dark web and cybercriminal communities.
  • Experience with SOAR automation platforms.
  • Familiarity with Attack Surface Management technologies.
  • Knowledge of intelligence lifecycle methodologies.
  • Experience supporting regulated industries such as financial services, healthcare, or government

Responsibilities

  • Identify, analyze, and communicate cyber threats affecting people, assets, operations and customers.
  • Collaborate with SOC, IR, Threat Hunting, VU&M, Attack Surface Management, Digital Risk Protection, Fraud, and leadership to identify threats and improve detection.
  • Produce strategic, operational, and tactical intelligence reports for technical and executive audiences.
  • Maintain awareness of TTPs using MITRE ATT&CK framework.
  • Identify IOCs/IOAs and behavioral analytics to enhance detection.
  • Develop intelligence requirements and prioritize collection by organizational risk.
  • Perform attribution analysis on threat actors and campaigns where appropriate.
  • Maintain threat profiles, repositories, and knowledge bases.
  • Threat hunt across networks, cloud, endpoints, and identity platforms.
  • Create detection logic and use cases for SIEM/EDR/NDR and cloud security platforms.
  • Validate detection coverage against MITRE ATT&CK techniques.
  • Collaborate with Incident Response during investigations and incidents.
  • Recommend improvements to detection engineering and monitoring based on findings.

Skills

Threat intelligence
Threat hunting
Security operations
Incident response
Vulnerability management
Attack surface management
Digital risk protection
Executive briefing

Education

Bachelor's degree in Cybersecurity or related

Tools

SIEM (Google SecOps, Splunk, MS Sentinel, QRadar)
EDR/XDR (CrowdStrike, Defender, SentinelOne, Carbon Black)
TIPs (Recorded Future, ThreatConnect, MISP, Anomali, EclecticIQ)
SOAR platforms
Attack Surface Management tools

Job description

ONLY HYDERABAD LOCATION

The Cybersecurity Threat Intelligence Analyst is responsible for identifying, analyzing, and communicating cyber threats that could impact the organization's people, assets, operations, and customers. This role collects and analyzes strategic, operational, and tactical threat intelligence from internal and external sources to provide actionable intelligence that enables proactive defense.

The analyst works closely with Security Operations Center (SOC), Incident Response, Threat Hunting, Vulnerability Management, Attack Surface Management, Digital Risk Protection, Fraud, and executive leadership to identify emerging threats, improve detection capabilities, reduce organizational risk, and support informed security decisions.

Cyber Threat Intelligence
  • Collect, analyze, and disseminate actionable cyber threat intelligence from commercial, open-source, government, and industry intelligence feeds.
  • Monitor threat actor activity, malware campaigns, ransomware operations, vulnerabilities, and geopolitical events that may impact the organization.
  • Produce strategic, operational, and tactical intelligence reports for technical and executive audiences.
  • Maintain awareness of adversary tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework.
  • Identify indicators of compromise (IOCs), indicators of attack (IOAs), and behavioral analytics to improve detection capabilities.
  • Develop intelligence requirements and prioritize collection efforts based on organizational risk.
  • Perform attribution analysis on threat actors and campaigns where appropriate.
  • Maintain threat profiles, intelligence repositories, and knowledge bases.
Threat Hunting
  • Conduct proactive threat hunting across enterprise networks, cloud environments, endpoints, and identity platforms.
  • Develop and execute hypothesis-driven threat hunts based on intelligence reporting and adversary behaviors.
  • Identify previously undetected malicious activity using endpoint, network, identity, cloud, and log data.
  • Create new detection logic and use cases for SIEM, EDR, NDR, and cloud security platforms.
  • Validate detection coverage against MITRE ATT&CK techniques.
  • Collaborate with Incident Response teams during investigations and major security incidents.
  • Recommend improvements to detection engineering and monitoring capabilities based on hunt findings.
Digital Risk Protection
  • Monitor external digital assets for potential security risks affecting the organization's brand and reputation.
  • Identify phishing domains, typosquatting, brand impersonation, executive impersonation, and fraudulent websites.
  • Monitor dark web marketplaces, underground forums, messaging platforms, and criminal communities for emerging threats targeting the organization.
  • Identify exposed credentials, data leaks, compromised accounts, and unauthorized disclosures.
  • Coordinate takedown efforts for malicious domains, phishing campaigns, and fraudulent content.
  • Monitor social media and public platforms for cyber threats, disinformation campaigns, and brand abuse.
  • Assess third-party and supply chain cyber risks through external intelligence.
Collaboration
  • Partner with SOC analysts to improve detection and response capabilities.
  • Support Incident Response with intelligence during active investigations.
  • Collaborate with Vulnerability Management to prioritize remediation based on active exploitation.
  • Work with Attack Surface Management teams to identify externally exposed assets and emerging risks.
  • Brief leadership on emerging cyber threats and organizational risk.
  • Participate in tabletop exercises and incident simulations.

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Intelligence Studies, or related field (or equivalent experience).

7+ years of experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related cybersecurity disciplines.

Experience analyzing sophisticated cyber adversaries including nation-state, ransomware, financially motivated, and insider threats.

Strong understanding of the cyber kill chain and MITRE ATT&CK framework.

Experience with SIEM platforms such as Google SecOps, Splunk, Microsoft Sentinel, or QRadar.

Experience with EDR/XDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or VMware Carbon Black.

Experience working with threat intelligence platforms (TIPs).

Experience analyzing malware, phishing campaigns, vulnerabilities, and indicators of compromise.

Familiarity with cloud security across Microsoft Azure, AWS, and Google Cloud Platform.

Experience with Threat Intelligence Platforms (TIPs) such as Recorded Future, ThreatConnect, MISP, Anomali, or EclecticIQ.

Experience with Digital Risk Protection platforms.

Experience monitoring the dark web and cybercriminal communities.

Experience with SOAR automation platforms.

Familiarity with Attack Surface Management technologies.

Knowledge of intelligence lifecycle methodologies.

Experience supporting regulated industries such as financial services, healthcare, or government

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

Atyeti • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Associate Threat Intelligence
Senior Associate Threat Intelligence

Zoho • Hyderabad

On-site
INR 900,000 - 1,500,000
Insurance & Wellness program
Relocation & Mobility benefits
Home loan support
Threat analyst
Threat analyst

Codincity Digital Technologies • Chennai District

On-site
INR 1,200,000 - 1,800,000
Principal, Sr. Threat Intelligence Analyst
Principal, Sr. Threat Intelligence Analyst

Vision Data Analytics • Bengaluru

On-site
INR 800,000 - 1,400,000
PARTNER CONSULTANT - Threat hunting
PARTNER CONSULTANT - Threat hunting

Happiest Minds Technologies • Dadri

On-site
INR 3,000,000 - 5,000,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Kyndryl Inc. • Dadri

Hybrid
INR 1,800,000 - 3,000,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Senior CTI Consultant
Senior CTI Consultant

EY • Thiruvananthapuram

On-site
INR 1,800,000 - 2,800,000
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 3,500,000 - 7,000,000