Senior Researcher - Dark Web & Threat Intelligence

Cyble

Karnataka

On-site

INR 1,200,000 - 2,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cyble is looking for an experienced threat intelligence professional to join their Pursuits team in Karnataka, India. You will lead projects, engage with threat actors, and produce actionable advisories to support new client growth.

Your role will require a minimum of 4 years in threat intelligence or dark web research, along with strong HUMINT skills. You’ll be involved in monitoring, analyzing, and reporting significant findings from dark web sources.

Qualifications

  • 4+ years in threat intelligence or dark web research.
  • Experience mentoring junior researchers.
  • Strong communication skills with an ability to present technical findings.

Responsibilities

  • Monitor dark web for intelligence on prospects.
  • Engage with threat actors to gather intel.
  • Produce advisories and analyze breach data.

Skills

Threat intelligence
Dark web research
Open Source Intelligence (OSINT)
Human Intelligence (HUMINT)
Data validation

Job description

About The Team

The Pursuits team produces dark web and threat intelligence on prospects, the companies Cyble's sales and presales teams are trying to win. Early, validated intelligence shows a prospect what's exposed about it (access for sale, leaks, vulnerable assets) and demonstrates Cyble's offering in action. Our internal customers are sales and presales, and our work directly supports new-client growth.

We cover the dark web (access sales, leaks, malicious tools, marketplaces) and threats from ransomware groups, extortion crews, hacktivists, and APTs, plus cloud storage exposures and other vulnerabilities. Our work is both proactive and driven by collaboration with other teams.

About The Role:

You take on the hardest collection and the highest-stakes reporting, and you help run the function. You own the request queue, set the quality bar, and guide less experienced researchers. You also still do the work: run sources and threat-actor engagements, deanonymize actors, and write the advisories that reach prospects.

What You’ll Do at Cyble:
Collection & intelligence
  • Monitor dark web forums, Telegram channels, and ransomware/extortion group sites daily for intelligence on prospects and notable events.
  • Engage threat actors (TA engagement / HUMINT) to gather intel on private data leaks; target several successful engagements per week.
  • Validate data leaks and TA claims to determine whether they're legitimate.
  • Deanonymize threat actors: link aliases, accounts, and personas to real-world identities.
Analysis & reporting
  • Produce advisories and flash alerts for significant leads, and contribute blogs and quarterly reports (for example, ransomware and regional dark web roundups).
  • Map a prospect's real attack surface (subsidiaries, parent companies, subdomains, and vulnerable login portals) when scope isn't fully specified.
  • Analyze raw breach datasets and corroborate findings before anything is published.
Team ownership & coordination
  • Own the request queue: triage incoming requests, confirm scope, route them, and track deliverables against due dates.
  • Review and quality-check the team's findings and reports before they reach stakeholders.
  • Mentor junior researchers and raise the bar on tradecraft and writing.
  • Run daily async standups and the weekly team review, and keep stakeholders informed.
  • Coordinate with sales and relationship managers on what each account needs (report depth, scope, timelines).
What You’ll Need:
  • 4+ years in threat intelligence, dark web research, OSINT, or intelligence operations, including senior or lead-level work.
  • Deep hands-on familiarity with dark web forums, marketplaces, and Telegram-based trading of compromised data.
  • Strong TA engagement / HUMINT experience, with sound operational security and source-handling discipline.
  • Solid OSINT tradecraft: people and entity research, social media and search-operator (dork) techniques, and corroboration.
  • Comfort with raw breach data: structure, validation, and victim mapping.
  • A track record of impactful findings.
  • Experience guiding or mentoring other researchers and owning a quality bar.
  • Driven to keep learning and stay current on the latest research techniques and tools.
  • Able to use AI tools effectively to speed up research, analysis, and writing.
  • Strong communication, within the team, across other teams, and in writing. You can turn technical findings into clear, defensible analysis that makes both technical and executive stakeholders see the business impact.
Bonus Points If You Have:
  • Familiarity with intelligence frameworks (MITRE ATT&CK, the intelligence cycle, analytic standards).
  • Experience supporting a SaaS CTI platform or a sales/POV motion.
  • Basic scripting (Python/regex) for parsing and cleaning leaked datasets.
  • Reading knowledge of a second language common in cybercrime forums (for example, Russian).
How The Role Is Measured?
  • Consistently deliver impactful findings each week (team baseline: 2 to 3 weekly; aim for about 80% high-impact).
  • The team's output meets the quality bar: validated, well-scoped, defensible.
  • Timely turnaround on requests.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected Veteran status age, or genetics, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

black.ai • Bengaluru

On-site
INR 1,000,000 - 2,000,000
Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

Cyble • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Bug Hunter - Dark Web & Threat Intelligence
Bug Hunter - Dark Web & Threat Intelligence

black.ai • Bengaluru

On-site
INR 800,000 - 1,200,000
Bug Hunter - Dark Web & Threat Intelligence
Bug Hunter - Dark Web & Threat Intelligence

Cyble • Bengaluru

On-site
INR 800,000 - 1,200,000
AI SOC Lead
AI SOC Lead

Cyble • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Intelligence Analyst
Intelligence Analyst

ZeroFox • India

On-site
INR 1,200,000 - 1,800,000
Competitive compensation
Generous time off
Best-in-class benefits
+1
AI SOC Lead
AI SOC Lead

black.ai • Bengaluru

On-site
INR 2,200,000 - 4,800,000
Intelligence Analyst
Intelligence Analyst

ZeroFox • Bengaluru

On-site
INR 600,000 - 900,000
Competitive pay
Culture & events
Generous leave
+3
Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Threat Intelligence Data Engineer
Threat Intelligence Data Engineer

HEROIC • Pune District

On-site