Information & Cybersec Lead

HCL Technologies Limited

Greater Noida

On-site

INR 1,800,000 - 2,400,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HCLTech is seeking a Senior Threat Hunter with 8+ years of cybersecurity experience to lead proactive threat hunting across on-prem, cloud, and hybrid environments. You will detect advanced threats, analyze diverse logs, and drive improvements in detection engineering and incident response.

This role acts as a Tier-4 escalation point, mentoring SOC staff and collaborating with IR, GRC, and IT teams, while aligning findings to MITRE ATT&CK and tracking MTTD metrics.

Qualifications

  • 8+ years of experience in Cyber Security with proven Threat Hunting background.
  • Experience leading threat hunting across endpoints, network, cloud, and identity environments.
  • Strong ability to map findings to MITRE ATT&CK and communicate risk to stakeholders.

Responsibilities

  • Lead hypothesis-driven threat hunting across endpoint, network, cloud, identity, and SaaS platforms.
  • Detect advanced threats including APTs, insider threats, credential abuse, lateral movement, and fileless attacks.
  • Analyze datasets from EDR/XDR, SIEM, NDR, email, identity, and cloud logs.
  • Map findings to MITRE ATT&CK framework and attacker TTPs.
  • Recommend, tune, and optimize detection rules in SIEM and EDR platforms.
  • Automate workflows using KQL, SPL, Python, PowerShell, and SOAR.
  • Reduce false positives and improve signal-to-noise ratio.
  • Perform root cause analysis and post-incident reporting.
  • Lead threat hunting in Microsoft 365, Azure, AWS, and other cloud environments.

Skills

SIEM/SOAR platforms
EDR/XDR
MITRE ATT&CK
KQL
Powershell
Python
Cloud forensics
Cloud security (Azure/AWS)

Tools

Microsoft Sentinel
Splunk
QRadar
Defender
CrowdStrike
SentinelOne

Job description

Experience: 8+ Years in Cyber Security with proven Threat Hunting experience

Employment Type: Full-Time

Role Overview

We are seeking a highly skilled Senior Threat Hunter to lead proactive threat hunting initiatives and detect advanced cyber threats that evade traditional security controls. The ideal candidate will possess deep expertise in adversary tactics, threat intelligence, detection engineering, and incident response, with the ability to translate complex security findings into actionable business insights. This role acts as a Tier-4 escalation point, supports SOC maturity, and drives continuous improvement of detection and response capabilities across on-prem, cloud, and hybrid environments.

Key Responsibilities
Threat Hunting & Adversary Detection
  • Lead hypothesis-driven threat hunting across endpoint, network, cloud, identity, and SaaS platforms.
  • Detect advanced threats including APTs, insider threats, credential abuse, lateral movement, and fileless attacks.
  • Analyze datasets from EDR/XDR, SIEM, NDR, email, identity, and cloud logs.
  • Map findings to MITRE ATT&CK framework and attacker TTPs.
Detection Engineering & Automation
  • Recommend , tune, and optimize detection rules in SIEM and EDR platforms.
  • Automate workflows using KQL, SPL, Python, PowerShell, and SOAR.
  • Reduce false positives and improve signal-to-noise ratio.
  • Consume strategic and tactical threat intelligence.
  • Track emerging threats and attacker techniques.
  • Participate in purple team exercises and adversary simulations.
Incident Response & Advanced Investigations
  • Serve as escalation point for complex security incidents.
  • Support containment, eradication, and recovery activities.
  • Perform root cause analysis and post-incident reporting.
Cloud & Identity Security Hunting
  • Conduct threat hunting in Microsoft 365, Azure, AWS, and other cloud environments.
  • Detect OAuth abuse, MFA bypass, token theft, and persistence mechanisms.
  • Prepare executive-level threat hunting and risk reports.
  • Track metrics such as MTTD, dwell time, and ATT&CK coverage.
  • Mentor junior threat hunters , SOC analysts and Threat intel team .
  • Develop hunt playbooks and training materials.
  • Collaborate with Red Team, IR, GRC, and IT teams.
Required Skills & Qualifications
Technical Skills
  • Experience with SIEM/SOAR platforms (Microsoft Sentinel, Splunk, QRadar)
  • Hands-on with EDR/XDR solutions (Defender, CrowdStrike, SentinelOne and Splunk)
  • Strong understanding of MITRE ATT&CK framework
  • Proficiency in KQL, SPL, Python, and PowerShell
  • Endpoint, network, and cloud forensics
  • Cloud security expertise (Azure/AWS/GCP)
Professional Skills
  • Strong analytical and problem-solving skills
  • Ability to explain complex threats to non-technical audiences
  • Ability to work independently under pressure and ready for 24x7 support.
Preferred Certifications
  • GCED, GCTI, GCIA, GMON
  • CISSP / CISM
  • Microsoft Security Certifications
  • Cloud Security Certifications (Azure/AWS)
Key Responsibilities
Key Responsibilities
Threat Hunting & Adversary Detection
  • Lead hypothesis-driven threat hunting across endpoint, network, cloud, identity, and SaaS platforms.
  • Detect advanced threats including APTs, insider threats, credential abuse, lateral movement, and fileless attacks.
  • Analyze datasets from EDR/XDR, SIEM, NDR, email, identity, and cloud logs.
  • Map findings to MITRE ATT&CK framework and attacker TTPs.
Detection Engineering & Automation
  • Recommend , tune, and optimize detection rules in SIEM and EDR platforms.
  • Automate workflows using KQL, SPL, Python, PowerShell, and SOAR.
  • Reduce false positives and improve signal-to-noise ratio.
  • Consume strategic and tactical threat intelligence.
  • Track emerging threats and attacker techniques.
  • Participate in purple team exercises and adversary simulations.
Incident Response & Advanced Investigations
  • Serve as escalation point for complex security incidents.
  • Support containment, eradication, and recovery activities.
  • Perform root cause analysis and post-incident reporting.
Cloud & Identity Security Hunting
  • Conduct threat hunting in Microsoft 365, Azure, AWS, and other cloud environments.
  • Detect OAuth abuse, MFA bypass, token theft, and persistence mechanisms.
  • Prepare executive-level threat hunting and risk reports.
  • Track metrics such as MTTD, dwell time, and ATT&CK coverage.
  • Mentor junior threat hunters , SOC analysts and Threat intel team .
  • Develop hunt playbooks and training materials.
  • Collaborate with Red Team, IR, GRC, and IT teams.

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Track Lead - Security Investigations, SIEM
Track Lead - Security Investigations, SIEM

HCL Technologies Limited • Dadri

On-site
INR 1,800,000 - 2,500,000
Track Lead - Security Analysis, SIEM
Track Lead - Security Analysis, SIEM

HCL Technologies Limited • Lucknow

On-site
INR 2,500,000 - 4,000,000
Senior Cybersecurity Incident Response Analyst
Senior Cybersecurity Incident Response Analyst

Hewlett Packard Enterprise Development LP • India

Hybrid
INR 2,800,000 - 4,400,000
Health & Wellbeing benefits
Career development programs
Inclusive culture
Senior Administrator - AWS Security, Cloud Security
Senior Administrator - AWS Security, Cloud Security

HCL Technologies Limited • Dadri

On-site
INR 1,200,000 - 2,400,000
Senior Track Lead
Senior Track Lead

HCL Technologies Limited • Chennai District

On-site
INR 2,600,000 - 4,800,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
SME - AWS IAC, Terraform,Python
SME - AWS IAC, Terraform,Python

HCL Technologies Limited • Dadri

On-site
INR 2,800,000 - 4,200,000
Senior Cyber Threat Hunter [T500-28455]
Senior Cyber Threat Hunter [T500-28455]

ADM • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Track Lead - AWS IAC, Terraform,Python
Track Lead - AWS IAC, Terraform,Python

HCL Technologies Limited • Dadri

On-site
INR 1,200,000 - 1,800,000
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Broadway Global Services • Bengaluru

On-site
INR 400,000 - 700,000
Challenging role
Certification support
Growth opportunities
+2