Threat Analyst 2

Jobgether

India

Remote

INR 1,200,000 - 2,400,000

Full time

43 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote-first working model
Exposure to wide security technologies
Collaborative security team
Wellbeing days and training
Diversity and inclusion initiatives

Job summary

Jobgether seeks a Threat Analyst 2 based in India to join a global Managed Detection and Response environment. You will investigate escalated alerts across endpoints, networks, cloud, and identity, perform malware analysis, and contribute to incident response and threat hunting activities.

You will collaborate with experienced analysts on high-severity incidents, document findings, and provide remediation guidance to clients in a 24x7x365 setting, with a remote-first working model and exposure

Qualifications

  • 3–5 years of experience in SOC/MDR/IR environments.
  • Hands-on experience with EDR/SIEM tools.
  • Understanding of ransomware patterns and attacker techniques.
  • Experience with Windows and Linux investigations.
  • Familiarity with MITRE ATT&CK framework.

Responsibilities

  • Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments.
  • Analyze incidents to determine root cause, attack scope, and potential business impact.
  • Support ransomware investigations by examining attacker activity and malware behavior.
  • Deobfuscate scripts and malware samples to identify malicious activity.
  • Conduct proactive threat hunting based on hypotheses and threat intel.
  • Investigate suspicious authentication, privilege escalation, and identity misuse.
  • Perform investigations on Windows and Linux systems including log analysis.
  • Correlate data from EDR, SIEM, cloud logs, and identity platforms.
  • Document findings and provide actionable remediation guidance to clients.
  • Collaborate with senior analysts on complex incidents and incident response activities.
  • Assist in tuning detections and improving response playbooks.

Skills

Threat hunting
Incident response
Analytical thinking
Troubleshooting
Strong documentation
Written & verbal communication

Education

Bachelor's degree in IT/CS or related field

Tools

EDR
SIEM
PowerShell
Python

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst 2 based in India.

This role sits within a global Managed Detection and Response environment focused on identifying, investigating, and helping neutralize sophisticated cyber threats.
You will investigate escalated alerts across endpoint, network, cloud, and identity environments using enterprise security platforms.
The position provides hands-on exposure to incident response, threat hunting, ransomware investigations, malware analysis, and adversary techniques.
You will work closely with experienced analysts on complex and high-severity incidents while developing deeper investigative expertise.
Your findings will help strengthen detection capabilities, response playbooks, and the security posture of clients.
The role combines technical investigation with clear documentation, client-facing remediation guidance, and cross-team collaboration.
You will participate in a rotational schedule supporting a 24x7x365 security operations environment.

Accountabilities
  • Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments.

  • Analyze incidents to establish root cause, attack scope, lateral movement, affected systems, and potential business impact.

  • Support ransomware investigations by examining attacker activity, credential abuse, persistence techniques, and malware behavior.

  • Analyze and deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity.

  • Conduct proactive threat hunting based on defined hypotheses, threat intelligence, and emerging attacker behaviors.

  • Investigate suspicious authentication activity, privilege escalation, and identity or privileged-account misuse.

  • Perform investigations across Windows and Linux environments, including process analysis and examination of relevant logs.

  • Correlate information from EDR, SIEM, cloud logging, identity platforms, and other security data sources.

  • Document investigative findings accurately and provide actionable remediation recommendations to clients.

  • Collaborate with senior analysts on complex or high-severity incidents and contribute to incident response activities.

  • Support detection tuning and the improvement of response playbooks based on lessons learned from investigations.

  • Participate in a rotational schedule supporting continuous 24x7x365 MDR operations.

Requirements
  • 3–5 years of experience in a SOC, MDR, incident response, or related cybersecurity operations environment.

  • Hands-on experience investigating endpoint and network security alerts using EDR and SIEM technologies.

  • Working knowledge of ransomware attack patterns, common intrusion techniques, and adversary behaviors.

  • Practical experience investigating both Windows and Linux systems.

  • Experience analyzing obfuscated scripts and malware behavior, including deobfuscation techniques.

  • Familiarity with adversary tactics and techniques and practical exposure to the MITRE ATT&CK framework.

  • Experience working with Windows Event Logs, Linux logs, and Active Directory fundamentals.

  • Basic understanding of cloud and identity security investigations, including suspicious authentication and privileged-account activity.

  • Ability to analyze network traffic and core protocols such as TCP/IP, DNS, and HTTP/S.

  • Mandatory scripting knowledge, including PowerShell, with Python or another programming language.

  • Strong investigative documentation skills, attention to detail, analytical thinking, and troubleshooting abilities.

  • Ability to manage multiple investigations simultaneously in a fast-paced operational environment.

  • Clear written and verbal communication skills, particularly when documenting technical findings and communicating remediation guidance.

  • A bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent professional experience.

  • Security certifications such as Security+, CySA+, GCIH, or equivalent are advantageous.

  • Willingness to work rotational schedules supporting a continuous 24x7x365 MDR operation.

Benefits
  • Remote-first working model, with remote work as the primary arrangement for most roles.

  • Opportunity to work on real-world cybersecurity incidents and develop expertise across multiple security domains.

  • Exposure to endpoint, network, cloud, identity, SIEM, EDR, threat intelligence, and incident response technologies.

  • Collaboration with experienced security professionals on complex and high-severity investigations.

  • Employee-led diversity and inclusion networks supporting community, education, and advocacy.

  • Annual charity, fundraising, and employee volunteer initiatives.

  • Global sustainability initiatives and employee participation opportunities.

  • Global fitness and trivia activities.

  • Wellbeing days, webinars, and training focused on employee health and wellbeing.

  • Inclusive working environment with support for reasonable adjustments throughout the recruitment process.

  • Opportunities to strengthen investigative, threat-hunting, malware-analysis, and incident-response capabilities.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Threat Analyst - English
Cybersecurity Threat Analyst - English

Jobgether • India

On-site
INR 1,323,000 - 1,853,000
US$10/hour
Freelance
Location India
+1
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Staff MDR Investigator
Staff MDR Investigator

SentinelOne • India

On-site
INR 2,500,000 - 4,000,000
RSUs
ESPP
Competitive leave benefits
+10
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI • Hyderabad

On-site
INR 900,000 - 1,300,000
Staff MDR Investigator
Staff MDR Investigator

SentinelOne • Bengaluru

On-site
INR 2,500,000 - 4,000,000
RSUs
ESPP
Competitive leave
+6
Cyber Security Analyst | Remote | Hybrid | Jobs In India
Cyber Security Analyst | Remote | Hybrid | Jobs In India

DigitalXNode • Chennai District

Hybrid
INR 700,000 - 1,100,000
Senior Threat Hunting & Incident Response Engineer
Senior Threat Hunting & Incident Response Engineer

Coralogix • Gurugram District

On-site
INR 1,800,000 - 3,200,000
Security Analyst II, Google SecOps
Security Analyst II, Google SecOps

Cacheflow • Bengaluru

Hybrid
INR 900,000 - 1,300,000
Medical Insurance
Hybrid Work Model
PTO & Leave
+3
Security Analyst II, Google SecOps
Security Analyst II, Google SecOps

Cyderes • Bengaluru

Hybrid
INR 1,500,000 - 2,300,000
Medical Insurance
Life Insurance
Retirement Match
+6