Lead Threat Intelligence Analyst

Providence India

Hyderabad

On-site

INR 3,000,000 - 6,000,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Providence India is seeking a Lead Threat Intelligence Analyst in Hyderabad to drive proactive threat hunting across endpoints, networks, cloud and identities. The role focuses on hypothesis-driven investigations, malware analysis, and shaping detections beyond traditional controls.

You will leverage MITRE ATT&CK, SIEM/SOAR platforms, EDR/XDR such as CrowdStrike and Microsoft Defender, and scripting skills (Python/PowerShell) to deliver technical reports and executive summaries, and to develop

Qualifications

  • Comprehensive understanding of cyber-attack lifecycles and adversary behavior.
  • Expertise in the MITRE ATT&CK framework.
  • Hands-on experience with SIEM and SOAR platforms (e.g., CrowdStrike Falcon XSOAR).
  • Experience with EDR/XDR solutions (Microsoft Defender, CrowdStrike Falcon).
  • Knowledge of Windows, Linux, AD/Entra ID, Azure, and networking protocols (DNS, HTTP, SMTP, LDAP, TCP/IP).
  • Proficiency in KQL, SQL, Python, and PowerShell.
  • Understanding of malware analysis and digital forensics.
  • Strong analytical, communication, and documentation skills.

Responsibilities

  • Conduct proactive threat hunting across endpoints, network, cloud, identity, and email environments.
  • Develop and implement threat hunting hypotheses based on threats and adversary TTPs.
  • Analyze security telemetry using SIEM, EDR/XDR, Cloud Security, Data Security, EASM, email gateways, Threat Intelligence, Dark Web monitoring, identity management, SOAR, Case Management, and various log sources.
  • Investigating Indicators of Compromise and Indicators of Attack.
  • Align threat hunting and investigation findings with the MITRE ATT&CK framework.
  • Create and refine threat detection rules, use cases, and behavioral analytics based on threat hunting outcomes and investigations to enhance security monitoring coverage.
  • Conduct digital forensic and incident analysis to determine the scope and impact of attacks.
  • Produce technical reports and executive summaries detailing threat hunting activities.
  • Perform triage, investigation, and response to security incidents.
  • Development of SOAR playbooks.

Skills

Threat hunting
MITRE ATT&CK
Analytical thinking
Communication
Documentation
Scripting

Tools

CrowdStrike Falcon XSOAR
Microsoft Defender
SIEM
EDR/XDR

Job description

Job Description – Lead Threat Intelligence Analyst
Lead Threat Intelligence Analyst
Role Summary

Lead Threat Intelligence Analyst is tasked with the proactive identification, investigation, and mitigation of advanced cyber threats within PGC enterprise environments. The candidate will utilize threat intelligence, hypothesis-driven hunting, behavior analytics, and advanced detection techniques to uncover malicious activities not addressed by traditional security controls.

Key Responsibilities
  • Conduct proactive threat hunting across endpoints, network, cloud, identity, and email environments.
  • Develop and implement threat hunting hypotheses based on emerging threats and adversary tactics, techniques, and procedures.
  • Analyze security telemetry using platforms such as SIEM, EDR/XDR, Cloud Security, Data Security, EASM, email security gateways, Threat Intelligence, Dark Web monitoring, identity management, SOAR, Case Management, and various log sources.
  • Investigating Indicators of Compromise and Indicators of Attack.
  • Align threat hunting and investigation findings with the MITRE ATT&CK framework.
  • Create and refine threat detection rules, use cases, and behavioral analytics based on threat hunting outcomes and investigations to enhance security monitoring coverage.
  • Conduct digital forensic and incident analysis to determine the scope and impact of attacks.
  • Produce technical reports and executive summaries detailing threat hunting activities.
  • Perform triage, investigation, and response to security incidents.
  • Development of SOAR playbooks.
Required Skills/Qualifications
  • Comprehensive understanding of cyber-attack lifecycles and adversary behavior.
  • Expertise in the MITRE ATT&CK framework.
  • Experience with SIEM and SOAR platforms, such as CrowdStrike Falcon Next-Gen SIEM and Palo Alto Network Cortex XSOAR. Threat Hunting
  • Hands-on experience with EDR/XDR solutions, including Microsoft Defender and CrowdStrike Falcon.
  • In-depth knowledge of Windows, Linux, Active Directory/Entra ID, Azure Cloud Platform, and networking protocols (DNS, HTTP(s), SMTP, LDAP, TCP/IP).
  • Proficiency in Kusto Query Language (KQL), SQL, and scripting languages such as Python and PowerShell.
  • Understanding of malware analysis and digital forensics.
  • Strong analytical, communication, and documentation skills.
  • Threat Hunting
Preferred Qualifications
  • Over 6-9 years of experience in cybersecurity, with at least 5 years in threat hunting.
  • Relevant certifications such as GIAC Certified Threat Hunter (GCTI/GCTH), GIAC Certified Forensic Analyst (GCFA/GNFA), MITRE ATT&CK Defender (MAD – All modules) or equivalent certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Providence India • Hyderabad

On-site
INR 1,500,000 - 2,400,000
Threat Hunting Analyst
Threat Hunting Analyst

Network Intelligence India • Bengaluru

On-site
INR 800,000 - 1,500,000
Cyber Threat Hunter Professional
Cyber Threat Hunter Professional

Conduent • Navi Mumbai

On-site
INR 1,000,000 - 1,500,000
Threat Hunting Specialist
Threat Hunting Specialist

Terralogic • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Advanced Threat Hunting
Advanced Threat Hunting

PwC India • Mumbai

Hybrid
INR 1,200,000 - 2,400,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Senior Threat Hunter
Senior Threat Hunter

UST • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Threat Hunter - SOC
Threat Hunter - SOC

Network Intelligence • Mumbai

On-site
INR 1,000,000 - 1,500,000
Senior Cyber Threat Hunter [T500-28455]
Senior Cyber Threat Hunter [T500-28455]

ADM • Bengaluru

On-site
INR 4,000,000 - 7,000,000