Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
National Payments Corporation of India (NPCI) in Hyderabad is seeking a Threat Intelligence Operations professional to lead the cyber threat intel program and work with SOC teams. You will monitor global threats, map attacker behavior to MITRE ATT&CK, and develop intelligence-driven detections for BFSI platforms.
You will produce strategic and tactical reports for executives, coordinate with detection engineering, and drive continuous improvement of threat-hunting techniques and indicators of
National Payments Corporation of India (NPCI) | Full Time
The National Payments Corporation of India (NPCI) is a pivotal institution in India's digital payments ecosystem, established by the Reserve Bank of India (RBI) and the Indian Banks’ Association (IBA). It operates under the Payment and Settlement Systems Act, 2007, and is incorporated as a “Not for Profit” company under Section 25 of the Companies Act 1956 (now Section 8 of the Companies Act 2013). NPCI is dedicated to building world‑class digital payment infrastructure through innovative and efficient retail payment platforms. As an Equal Opportunity Employer, NPCI is committed to fostering an inclusive workplace culture, with zero tolerance for discrimination based on race, ethnicity, disability, gender identity, or sexual orientation, including support for the LGBTQ+ community.
To learn more about our company please click on link AboutNPCI
At NPCI, we foster a culture of Inclusion, Innovation, and a High- Performance Workplace .
The NPCIWAY isnotjustaframework - it’sasharedcommitmentbyevery individual to align with our evolving business needs, dynamic market conditions, and workforce expectations.
At NPCI, you’ll be part of a purpose-driven organization shaping the future of digital payments in India and beyond. NPCI offers a unique opportunity to work on cutting‑edge projects that directly impact millions. We foster a culture of innovation, inclusion, and high performance, where every individual is empowered to lead with purpose and deliver with passion. With a strong focus on employee wellbeing, continuous learning, and collaborative success, NPCI is more than just a workplace – it’s a platform to grow, contribute, and make a meaningful difference.
Key ResponsibilitiesThreat Intelligence OperationsLead the development, execution, and continuous improvement of the Cyber Threat Intelligence program.Monitor, analyze, and assess global cyber threats impacting the BFSI industry.Produce strategic, operational, and tactical intelligence reports for technical and executive stakeholders.Track emerging threat actors, cyber crime groups, nation-state actors, and financially motivated attackers.Identify Indicators of Compromise (IOCs), Indicators of Attack (IOAs), and adversary Tactics, Techniques, and Procedures (TTPs).Leverage MITRE ATT&CK framework to map adversary behavior and identify detection gaps.Analyze attack patterns targeting banking applications, digital payment platforms, online banking services, and financial transaction systems.Support incident investigations by providing threat context, attribution analysis, and intelligence-driven insights.Develop intelligence-led hunting hypotheses and prioritize threat-hunting activities based on business risk.Collect intelligence from commercial, open-source, dark web, industry, and government intelligence feeds.Evaluate source credibility and intelligence reliability using structured analytical techniques.Track ransomware groups, phishing campaigns, financial malware, fraud operations, and supply chain threats relevant to BFSI organizations.Monitor geopolitical developments and assess potential cyber impacts on financial services operations.Collaborate with SOC and Detection Engineering teams to operationalize threat intelligence.Develop and enhance detection use cases, SIEM analytics rules, watchlists, and threat indicators.Create and maintain KQL queries, Sigma rules, and YARA signatures.Improve detection coverage by aligning monitoring capabilities with emerging threat intelligence.Present intelligence findings and cyber risk assessments to senior leadership and executive stakeholders.Lead threat intelligence briefings and awareness sessions for technical and non-technical audiences.