Senior Researcher - Dark Web & Threat Intelligence

black.ai

Bengaluru

On-site

INR 1,000,000 - 2,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

black.ai is seeking a seasoned professional in Bengaluru to join their Pursuits team, focusing on threat intelligence and dark web analysis. In this role, you will monitor dark web forums and engage with threat actors to analyze emerging threats and data leaks.

You will lead efforts in producing advisories, manage team outputs, and mentor junior researchers, ensuring high-quality intelligence reports are delivered on time. Collaboration with sales teams to support client engagement is also crucial.

Applicants should have 4+ years of experience in threat intelligence, strong analytical abilities, and a proven track record in research and reporting.

Qualifications

  • 4+ years in threat intelligence or related fields.
  • Deep familiarity with dark web forums and OSINT techniques.
  • Strong TA engagement experience.
  • Comfortable with raw breach data and analysis.

Responsibilities

  • Monitor dark web forums and channels for intelligence.
  • Engage threat actors to gather intel on data leaks.
  • Produce advisories and alerts for significant leads.
  • Own request queue and review team findings.

Skills

Threat intelligence
Dark web research
HUMINT
OSINT tradecraft
Analytical skills
Communication skills

Job description

About The Team

The Pursuits team produces dark web and threat intelligence on prospects, the companies Cyble's sales and presales teams are trying to win. Early, validated intelligence shows a prospect what's exposed about it (access for sale, leaks, vulnerable assets) and demonstrates Cyble's offering in action. Our internal customers are sales and presales, and our work directly supports new-client growth. We cover the dark web (access sales, leaks, malicious tools, marketplaces) and threats from ransomware groups, extortion crews, hacktivists, and APTs, plus cloud storage exposures and other vulnerabilities. Our work is both proactive and driven by collaboration with other teams.

About The Role

You take on the hardest collection and the highest-stakes reporting, and you help run the function. You own the request queue, set the quality bar, and guide less experienced researchers. You also still do the work: run sources and threat-actor engagements, deanonymize actors, and write the advisories that reach prospects.

What You’ll Do At Cyble

Collection & intelligence

  • Monitor dark web forums, Telegram channels, and ransomware/extortion group sites daily for intelligence on prospects and notable events.
  • Engage threat actors (TA engagement / HUMINT) to gather intel on private data leaks; target several successful engagements per week.
  • Validate data leaks and TA claims to determine whether they’re legitimate.
  • Deanonymize threat actors: link aliases, accounts, and personas to real-world identities.

Analysis & reporting

  • Produce advisories and flash alerts for significant leads, and contribute blogs and quarterly reports (for example, ransomware and regional dark web roundups).
  • Map a prospect’s real attack surface (subsidiaries, parent companies, subdomains, and vulnerable login portals) when scope isn’t fully specified.
  • Analyze raw breach datasets and corroborate findings before anything is published.

Team ownership & coordination

  • Own the request queue: triage incoming requests, confirm scope, route them, and track deliverables against due dates.
  • Review and quality‑check the team’s findings and reports before they reach stakeholders.
  • Mentor junior researchers and raise the bar on tradecraft and writing.
  • Run daily async standups and the weekly team review, and keep stakeholders informed.
  • Coordinate with sales and relationship managers on what each account needs (report depth, scope, timelines).

What You’ll Need

  • 4+ years in threat intelligence, dark web research, OSINT, or intelligence operations, including senior or lead‑level work.
  • Deep hands‑on familiarity with dark web forums, marketplaces, and Telegram‑based trading of compromised data.
  • Strong TA engagement / HUMINT experience, with sound operational security and source‑handling discipline.
  • Solid OSINT tradecraft: people and entity research, social media and search‑operator (dork) techniques, and corroboration.
  • Comfort with raw breach data: structure, validation, and victim mapping.
  • A track record of impactful findings.
  • Experience guiding or mentoring other researchers and owning a quality bar.
  • Driven to keep learning and stay current on the latest research techniques and tools.
  • Able to use AI tools effectively to speed up research, analysis, and writing.
  • Strong communication, within the team, across other teams, and in writing. You can turn technical findings into clear, defensible analysis that makes both technical and executive stakeholders see the business impact.

Bonus Points If You Have

  • Familiarity with intelligence frameworks (MITRE ATT&CK, the intelligence cycle, analytic standards).
  • Experience supporting a SaaS CTI platform or a sales/POV motion.
  • Basic scripting (Python/regex) for parsing and cleaning leaked datasets.
  • Reading knowledge of a second language common in cybercrime forums (for example, Russian).

How The Role Is Measured?

  • Consistently deliver impactful findings each week (team baseline: 2 to 3 weekly; aim for about 80% high‑impact).
  • The team’s output meets the quality bar: validated, well‑scoped, defensible.
  • Timely turnaround on requests.

If you like working in an inclusive environment, you want to advance your career quickly, and your opinion is valued, look no further than Cyble, Inc. We are young, hungry, and ready to impact the cyber security landscape!

Cyble, Inc. takes into consideration an individual’s skillset, experience and location in making final salary determination.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected Veteran status age, or genetics, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

Cyble • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

Cyble • Karnataka

On-site
INR 1,200,000 - 2,000,000
Bug Hunter - Dark Web & Threat Intelligence
Bug Hunter - Dark Web & Threat Intelligence

Cyble • Bengaluru

On-site
INR 800,000 - 1,200,000
Bug Hunter - Dark Web & Threat Intelligence
Bug Hunter - Dark Web & Threat Intelligence

black.ai • Bengaluru

On-site
INR 800,000 - 1,200,000
AI SOC Lead
AI SOC Lead

Cyble • Bengaluru

On-site
INR 1,500,000 - 2,000,000
AI SOC Lead
AI SOC Lead

black.ai • Bengaluru

On-site
INR 2,200,000 - 4,800,000
Backend Engineer / Architect
Backend Engineer / Architect

black.ai • Bengaluru

On-site
INR 1,500,000 - 2,200,000
Access to training budgets
Conference support
Mentorship
Intelligence Analyst
Intelligence Analyst

ZeroFox • Bengaluru

On-site
INR 600,000 - 900,000
Competitive pay
Culture & events
Generous leave
+3
Intelligence Analyst
Intelligence Analyst

Vigilante ATI, Now Part of ZeroFox • Bengaluru

On-site
INR 600,000 - 1,000,000
Competitive compensation
Community-driven culture
Generous time off
+2
Forward-Deployed Engineer (FDE) - Bangalore/Delhi
Forward-Deployed Engineer (FDE) - Bangalore/Delhi

King River Capital Group • Bengaluru

On-site
INR 1,500,000 - 2,200,000