Senior Researcher - Dark Web & Threat Intelligence

Cyble

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cyble in Bengaluru is looking for a skilled professional to join their Pursuits team as a key contributor to dark web intelligence gathering. In this role, you will monitor dark web forums and engage with threat actors to produce actionable insights while guiding junior researchers.

With over 4 years of experience in threat intelligence or similar fields, you will ensure the quality and effectiveness of findings delivered to internal stakeholders. You will work in an inclusive environment that values career advancement and collaboration.

Qualifications

  • 4+ years of experience in threat intelligence or related fields.
  • Deep familiarity with dark web forums and marketplaces.
  • Experience guiding or mentoring other researchers.
  • Strong communication skills with a focus on clear analysis.

Responsibilities

  • Monitor dark web channels for intel on prospects.
  • Engage threat actors to gather intelligence.
  • Produce advisories for significant leads.
  • Own the request queue and track deliverables.

Skills

Threat intelligence
Dark web research
HUMINT engagement
OSINT tradecraft
Data validation
Communication

Tools

AI tools
Python/regex

Job description

About The Team

The Pursuits team produces dark web and threat intelligence on prospects, the companies Cyble's sales and presales teams are trying to win. Early, validated intelligence shows a prospect what's exposed about it (access for sale, leaks, vulnerable assets) and demonstrates Cyble's offering in action. Our internal customers are sales and presales, and our work directly supports new-client growth.

We cover the dark web (access sales, leaks, malicious tools, marketplaces) and threats from ransomware groups, extortion crews, hacktivists, and APTs, plus cloud storage exposures and other vulnerabilities. Our work is both proactive and driven by collaboration with other teams.

About The Role

You take on the hardest collection and the highest‑stakes reporting, and you help run the function. You own the request queue, set the quality bar, and guide less experienced researchers. You also still do the work: run sources and threat‑actor engagements, deanonymize actors, and write the advisories that reach prospects.

What You’ll Do At Cyble
Collection & intelligence
  • Monitor dark web forums, Telegram channels, and ransomware/extortion group sites daily for intelligence on prospects and notable events.
  • Engage threat actors (TA engagement / HUMINT) to gather intel on private data leaks; target several successful engagements per week.
  • Validate data leaks and TA claims to determine whether they're legitimate.
  • Deanonymize threat actors: link aliases, accounts, and personas to real‑world identities.
Analysis & reporting
  • Produce advisories and flash alerts for significant leads, and contribute blogs and quarterly reports (for example, ransomware and regional dark web roundups).
  • Map a prospect's real attack surface (subsidiaries, parent companies, subdomains, and vulnerable login portals) when scope isn't fully specified.
  • Analyze raw breach datasets and corroborate findings before anything is published.
Team ownership & coordination
  • Own the request queue: triage incoming requests, confirm scope, route them, and track deliverables against due dates.
  • Review and quality‑check the team's findings and reports before they reach stakeholders.
  • Mentor junior researchers and raise the bar on tradecraft and writing.
  • Run daily async standups and the weekly team review, and keep stakeholders informed.
  • Coordinate with sales and relationship managers on what each account needs (report depth, scope, timelines).
What You’ll Need
  • 4+ years in threat intelligence, dark web research, OSINT, or intelligence operations, including senior or lead‑level work.
  • Deep hands‑on familiarity with dark web forums, marketplaces, and Telegram‑based trading of compromised data.
  • Strong TA engagement / HUMINT experience, with sound operational security and source‑handling discipline.
  • Solid OSINT tradecraft: people and entity research, social media and search‑operator (dork) techniques, and corroboration.
  • Comfort with raw breach data: structure, validation, and victim mapping.
  • A track record of impactful findings.
  • Experience guiding or mentoring other researchers and owning a quality bar.
  • Driven to keep learning and stay current on the latest research techniques and tools.
  • Able to use AI tools effectively to speed up research, analysis, and writing.
  • Strong communication, within the team, across other teams, and in writing. You can turn technical findings into clear, defensible analysis that makes both technical and executive stakeholders see the business impact.
Bonus Points If You Have
  • Familiarity with intelligence frameworks (MITRE ATT&CK, the intelligence cycle, analytic standards).
  • Experience supporting a SaaS CTI platform or a sales/POV motion.
  • Basic scripting (Python/regex) for parsing and cleaning leaked datasets.
  • Reading knowledge of a second language common in cybercrime forums (for example, Russian).
How The Role Is Measured?
  • Consistently deliver impactful findings each week (team baseline: 2 to 3 weekly; aim for about 80% high‑impact).
  • The team's output meets the quality bar: validated, well‑scoped, defensible.
  • Timely turnaround on requests.

If you like working in an inclusive environment, you want to advance your career quickly, and your opinion is valued, look no further than Cyble, Inc. We are young, hungry, and ready to impact the cyber security landscape!

Cyble, Inc. takes into consideration an individual’s skillset, experience and location in making final salary determination.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected Veteran status age, or genetics, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

black.ai • Bengaluru

On-site
INR 1,000,000 - 2,000,000
Bug Hunter - Dark Web & Threat Intelligence
Bug Hunter - Dark Web & Threat Intelligence

Cyble • Bengaluru

On-site
INR 800,000 - 1,200,000
Bug Hunter - Dark Web & Threat Intelligence
Bug Hunter - Dark Web & Threat Intelligence

black.ai • Bengaluru

On-site
INR 800,000 - 1,200,000
AI SOC Lead
AI SOC Lead

black.ai • Bengaluru

On-site
INR 2,200,000 - 4,800,000
Intelligence Analyst
Intelligence Analyst

ZeroFox • India

On-site
INR 1,200,000 - 1,800,000
Competitive compensation
Generous time off
Best-in-class benefits
+1
Backend Engineer / Architect
Backend Engineer / Architect

black.ai • Bengaluru

On-site
INR 1,500,000 - 2,200,000
Access to training budgets
Conference support
Mentorship
Cybersecurity Intern – Offensive Security
Cybersecurity Intern – Offensive Security

CloudSEK • Bengaluru

On-site
INR 279,000 - 446,000
Senior Software Engineer – AI
Senior Software Engineer – AI

Cyble • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Impactful Work
Modern Stack
Growth & Learning
DevOps Engineer
DevOps Engineer

Cyble • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Threat Intelligence Researcher
Threat Intelligence Researcher

Arctic Wolf • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Equity for all employees
Comprehensive private benefits plan
Medical insurance for you and family
+2