Threat Hunter

UST

Thrissur

On-site

INR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

UST is seeking a Threat Hunter to bolster its Cyber Security team in India. You will proactively hunt across endpoints, network, cloud and core banking-adjacent systems using Splunk and Microsoft Sentinel, guided by RBI guidelines and industry best practices.

Responsibilities include developing hunting playbooks, interpreting threat intel and advisories, and collaborating with Vulnerability Management, SOC and IT teams to close gaps. Strong FortiRecon and EASM experience is required.

Qualifications

  • 3–6 years in Threat Intelligence or Threat Hunting, BFSI or regulated sector.
  • Hands-on with FortiRecon or similar EASM/Digital Risk platform.
  • Strong Splunk and Microsoft Sentinel expertise (KQL, SPL).
  • Ability to read advisories and threat intel reports; MITRE ATT&CK aware.
  • Familiarity with Windows/Linux internals, cloud security, RBI guidelines.

Responsibilities

  • Conduct proactive threat hunting across endpoints, network, cloud and core banking systems.
  • Monitor FortiRecon outputs and external risk signals to drive hunts.
  • Develop hunting playbooks, write KQL/SPL queries, map to MITRE ATT&CK.
  • Correlate findings across EDR, network and identity logs; escalate incidents to IR.
  • Collaborate with Vulnerability Management, SOC and IT to close gaps.

Skills

Threat Hunting
Threat Intelligence
Vulnerability Management
Splunk
Cloud Security
CrowdStrike
Incident Response
PowerShell

Tools

FortiRecon
Microsoft Sentinel
EDR Tools

Job description

Role Description

Role Summary We are looking for a Threat Hunter to join our Cyber Security team and proactively identify, analyze, and mitigate advanced threats targeting the bank's IT and digital banking infrastructure. The candidate will use FortiRecon for external attack surface and digital risk monitoring, and interpret threat hunting reports and vulnerability advisories to drive proactive hunts using Splunk and Microsoft Sentinel, in line with RBI cybersecurity guidelines and industry best practices.

Key Responsibilities

Conduct proactive, hypothesis-driven threat hunting across endpoints, network, cloud, and core banking-adjacent systems using Splunk and Microsoft Sentinel. Monitor and act on intelligence from FortiRecon (external attack surface management, brand/phishing protection, digital risk monitoring) to identify exposure relevant to a financial services target profile. Interpret threat intelligence reports, vulnerability advisories (CVE bulletins, OEM/vendor advisories), and sector-specific s (CERT-In, RBI/IDRBT, FS-ISAC) to build hunting hypotheses and prioritize action. Develop hunting playbooks, KQL/SPL queries, and use cases mapped to MITRE ATT&CK, with emphasis on threats relevant to banking (phishing, credential theft, fraud‑linked malware, ATM/payment switch threats, insider risk). Correlate findings across EDR, network, cloud, and identity logs to validate threats and hand off confirmed incidents to the Incident Response team. Support timely reporting/escalation in line with CERT-In incident reporting timelines and internal regulatory obligations. Collaborate with Vulnerability Management, SOC, and IT teams to close detection and patching gaps surfaced during hunts. Maintain documentation of hunting methodology, findings, and detection coverage improvements for internal and regulatory audits (RBI IS Audit, VAPT reviews). Stay current on threat actor campaigns and TTPs targeting Indian financial institutions.

Required Skills & Experience

3–6 years in a Threat Intelligence/Threat Hunting role, ideally within BFSI or a regulated industry. Hands‑on experience with FortiRecon or a similar EASM/Digital Risk Protection platform. Strong proficiency in Splunk (SPL) and Microsoft Sentinel (KQL, analytics rules, workbooks). Ability to read and act on vulnerability advisories (CVSS scoring, exploitability, patch prioritization) and threat intel reports. Working knowledge of MITRE ATT&CK and its application to hunt hypotheses. Familiarity with EDR tools (Microsoft Defender, CrowdStrike, SentinelOne, etc.). Understanding of Windows/Linux internals, network protocols, and cloud security (Azure/AWS). Awareness of RBI Cyber Security Framework for Banks, CERT-In guidelines, and PCI-DSS (a plus). Certifications: GCTI, GCFA, CEH, CompTIA Security+, Microsoft SC-200, or equivalent. Scripting skills (Python/PowerShell) for hunt automation. Prior experience in a bank, NBFC, or fintech SOC environment. Exposure to fraud/payment security use cases.

Skills
  • Threat Hunting
  • Threat Intelligence
  • Vulnerability Management
  • Splunk
  • Cloud Security
  • CrowdStrike
  • Incident Response
  • PowerShell
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI • Hyderabad

On-site
INR 900,000 - 1,300,000
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI International • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Comprehensive medical, accidental, and life insurance
On-site medical center and mental wellness support
Inclusive parental leave
+3
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Threat Hunter
Threat Hunter

Tekskills • Mumbai

On-site
INR 800,000 - 1,200,000
Senior Associate Threat Intelligence
Senior Associate Threat Intelligence

NPCI • Hyderabad

On-site
INR 900,000 - 1,500,000
Insurance & Wellness program
Relocation & Mobility benefits
Home loan support
Threat Hunting Analyst
Threat Hunting Analyst

Network Intelligence India • Bengaluru

On-site
INR 800,000 - 1,500,000
Lead Threat Intelligence
Lead Threat Intelligence

National Payments Corporation of India (NPCI) • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
Threat Intelligence Lead
Threat Intelligence Lead

U.S. Bancorp India • Chennai District

On-site
INR 2,500,000 - 4,000,000
Lead Threat Intelligence
Lead Threat Intelligence

NPCI • Hyderabad

On-site
INR 1,500,000 - 2,200,000