A complete application in a minute — tailored resume and cover letter, ready to send.
EY Hyderabad is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats impacting people, assets, operations, and customers. The role collaborates with SOC, Incident Response, Threat Hunting, and other security teams to improve detection, reduce risk, and support informed security decisions.
The position requires 7+ years in cyber threat intelligence or related fields, strong MITRE ATT&CK knowledge, and experience with SIEM/EDR/TIP platforms.
The Cybersecurity Threat Intelligence Analyst is responsible for identifying, analyzing, and communicating cyber threats that could impact the organization's people, assets, operations, and customers. This role collects and analyzes strategic, operational, and tactical threat intelligence from internal and external sources to provide actionable intelligence that enables proactive defense.
The analyst works closely with Security Operations Center (SOC), Incident Response, Threat Hunting, Vulnerability Management, Attack Surface Management, Digital Risk Protection, Fraud, and executive leadership to identify emerging threats, improve detection capabilities, reduce organizational risk, and support informed security decisions.
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Intelligence Studies, or related field (or equivalent experience).
7+ years of experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related cybersecurity disciplines.
Experience analyzing sophisticated cyber adversaries including nation-state, ransomware, financially motivated, and insider threats.
Strong understanding of the cyber kill chain and MITRE ATT&CK framework.
Experience with SIEM platforms such as Google SecOps, Splunk, Microsoft Sentinel, or QRadar.
Experience with EDR/XDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or VMware Carbon Black.
Experience working with threat intelligence platforms (TIPs).
Experience analyzing malware, phishing campaigns, vulnerabilities, and indicators of compromise.
Familiarity with cloud security across Microsoft Azure, AWS, and Google Cloud Platform.
Experience with Threat Intelligence Platforms (TIPs) such as Recorded Future, ThreatConnect, MISP, Anomali, or EclecticIQ.
Experience with Digital Risk Protection platforms.
Experience monitoring the dark web and cybercriminal communities.
Experience with SOAR automation platforms.
Familiarity with Attack Surface Management technologies.
Knowledge of intelligence lifecycle methodologies.
Experience supporting regulated industries such as financial services, healthcare, or government