Senior CTI Consultant

EY

Thiruvananthapuram

On-site

INR 1,800,000 - 2,800,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

EY is seeking a Senior Cyber Threat Intelligence Analyst to join its cybersecurity team in India. The role focuses on threat intelligence monitoring, report writing, and custom feed development, with integration into SIEMs and client-tailored reporting.

The candidate should be comfortable with EST overlap and on-call duties. The ideal candidate will analyze threats using OSINT, MITRE ATT&CK, and related frameworks, and produce in-depth, technical reports for clients, while collaborating with

Qualifications

  • Minimum 3 years of experience with threat intelligence monitoring tools.
  • At least 1 year of experience in threat intelligence report writing.
  • Proficiency with OSINT, IOC lookup and validation, Domain Registrar lookups, VirusTotal, and Dark Web search.
  • Experience with scripting in Python, Azure, and Linux.
  • Familiarity with one or more threat intelligence platforms for feed management.
  • Experience integrating threat intelligence feeds into SIEMs, especially Microsoft Sentinel.
  • Proven experience with domain and social media account takedowns.
  • Strong understanding of MITRE ATT&CK, D3F3ND frameworks, and the Cyber Kill Chain.
  • Excellent English writing skills.
  • Proficiency in Excel and/or Power BI for data visualization.
  • Strong experience with PowerPoint presentations and reporting.
  • Strong verbal English and presentation skills.
  • Cybersecurity certifications (e.g., COMPTIA, SANS GIAC, ISC, EC-Council) are a plus.

Responsibilities

  • Monitor and analyze threat intelligence using tools such as ZeroFox, Digital Shadows, or similar platforms.
  • Write comprehensive and technical cybersecurity reports with strong attention to detail.
  • Utilize OSINT, IOC lookup and validation, Domain Registrar lookups, VirusTotal, and Dark Web search for threat intelligence gathering.
  • Develop, sustain, and enrich custom threat intelligence feeds using platforms like MISP, with scripting in Python, Azure, and Linux.
  • Manage threat intelligence feeds using platforms such as Anomali, ThreatQ, Cyble, Cyware, OpenCTI, and MISP.
  • Integrate threat intelligence feeds into common SIEMs, particularly Microsoft Sentinel.
  • Execute domain and social media account takedowns as necessary.
  • Create custom, in-depth reports specific to client requirements.
  • Apply knowledge of MITRE ATT&CK, D3F3ND frameworks, and the Cyber Kill Chain in threat analysis.
  • Utilize Excel and/or Power BI for data visualization and graph creation.
  • Prepare and deliver PowerPoint presentations and reports to stakeholders.
  • Maintain strong verbal and written communication skills in English.
  • Work independently under pressure and prioritize tasks effectively.
  • Be available for on-call duties for high-priority urgent tasks.
  • Collaborate with Managed Security Service Providers (MSSPs) for backend and client-facing work.

Skills

Threat monitoring
OSINT
IOC lookup
Python scripting
Azure
Linux
MISP
SIEM integration
Microsoft Sentinel
Data visualization
Excel
Power BI
PowerPoint
English writing
MSSP collaboration

Education

3+ years threat intelligence experience

Tools

MISP
Anomali
ThreatQ
Cyble
Cyware
OpenCTI
ZeroFox
Digital Shadows
Microsoft Sentinel

Job description

Position Overview:

We are seeking a highly skilled and experienced Senior Cyber Threat Intelligence Analyst to join our cybersecurity team. The ideal candidate will have a strong background in threat intelligence monitoring, report writing, and the use of various threat intelligence platforms. This role requires a proactive individual who can develop and sustain custom threat intelligence feeds, integrate them into SIEMs, and provide in-depth reporting tailored to client needs. The candidate must be comfortable working in the EST timezone (evening shift for overlap with onshore/client team) and be on-call for high-priority urgent tasks.

Key Responsibilities:
  • Monitor and analyze threat intelligence using tools such as ZeroFox, Digital Shadows, or similar platforms.
  • Write comprehensive and technical cybersecurity reports with strong attention to detail.
  • Utilize OSINT, IOC lookup and validation, Domain Registrar lookups, VirusTotal, and Dark Web search for threat intelligence gathering.
  • Develop, sustain, and enrich custom threat intelligence feeds using platforms like MISP, with scripting in Python, Azure, and Linux.
  • Manage threat intelligence feeds using platforms such as Anomali, ThreatQ, Cyble, Cyware, OpenCTI, and MISP.
  • Integrate threat intelligence feeds into common SIEMs, particularly Microsoft Sentinel.
  • Execute domain and social media account takedowns as necessary.
  • Create custom, in-depth reports specific to client requirements.
  • Apply knowledge of MITRE ATT&CK, D3F3ND frameworks, and the Cyber Kill Chain in threat analysis.
  • Utilize Excel and/or Power BI for data visualization and graph creation.
  • Experience with excel data cleansing, VLookups, Pivot Tables
  • Prepare and deliver PowerPoint presentations and reports to stakeholders.
  • Maintain strong verbal and written communication skills in English.
  • Work independently under pressure and prioritize tasks effectively.
  • Be available for on-call duties for high-priority urgent tasks.
  • Collaborate with Managed Security Service Providers (MSSPs) for backend and client-facing work.
Qualifications:
  • Minimum of 3 years of experience with threat intelligence monitoring tools.
  • At least 1 year of experience in threat intelligence report writing.
  • Proficiency with OSINT, IOC lookup and validation, Domain Registrar lookups, VirusTotal, and Dark Web search.
  • Experience with scripting in Python, Azure, and Linux.
  • Familiarity with one or more threat intelligence platforms for feed management.
  • Experience integrating threat intelligence feeds into SIEMs, especially Microsoft Sentinel.
  • Proven experience with domain and social media account takedowns.
  • Strong understanding of MITRE ATT&CK, D3F3ND frameworks, and the Cyber Kill Chain.
  • Excellent English writing skills.
  • Proficiency in Excel and/or Power BI for data visualization.
  • Strong experience with PowerPoint presentations and reporting.
  • Strong verbal English and presentation skills.
  • Cybersecurity certifications (e.g., COMPTIA, SANS GIAC, ISC, EC-Council) are a plus.
  • Certifications specific to cyber threat intelligence are an asset.
  • Ability to work in the EST timezone (evening shift for overlap with onshore/client team).
  • Strong analytical skills and ability to prioritize tasks effectively.
  • Experience working with MSSPs for backend and client-facing work.
Preferred Skills:
  • Experience with additional threat intelligence platforms.
  • Advanced technical writing and reporting skills.
  • Strong analytical and problem-solving abilities.
  • Ability to work independently and as part of a team.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 1,400,000 - 2,300,000
Senior Associate Threat Intelligence
Senior Associate Threat Intelligence

NPCI • Hyderabad

On-site
INR 900,000 - 1,500,000
Insurance & Wellness program
Relocation & Mobility benefits
Home loan support
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Senior Cyber Threat Hunter [T500-28455]
Senior Cyber Threat Hunter [T500-28455]

ADM • Bengaluru

On-site
INR 4,000,000 - 7,000,000
CTI Analyst
CTI Analyst

UST • Mumbai

On-site
INR 1,200,000 - 1,800,000
Threat Hunting Specialist
Threat Hunting Specialist

Terralogic • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Managed Services Information Security Analyst
Managed Services Information Security Analyst

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,000,000 - 1,600,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Threat Intelligence Analyst
Threat Intelligence Analyst

Tata Consultancy Services • Chennai District

On-site
INR 900,000 - 1,100,000