Threat Hunting Analyst

Network Intelligence India

Bengaluru

On-site

INR 800,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Network Intelligence India is looking for a candidate to lead threat hunting and develop detection mechanisms for cybersecurity. You will analyze vast security data and refine detection rules while collaborating across teams to enhance security operations.

The ideal candidate has expertise in SIEM platforms and AI/ML modeling, along with strong skills in threat hunting. This position involves regular updates on emerging threats and collaboration with various security units.

Qualifications

  • Hands-on experience analyzing EDR, SIEM, and NDR telemetry.
  • Skills in writing and tuning detection rules and alert logic.
  • Ability to document methodologies and findings clearly.

Responsibilities

  • Conduct hypothesis-driven threat hunting and analyze large volumes of security telemetry.
  • Develop detection rules and correlation queries in SIEM platforms.
  • Perform malware analysis and collaborate with various security teams.

Skills

Threat hunting expertise
Proficiency in SIEM platforms (Splunk, Microsoft Sentinel, Elastic)
Malware analysis skills
Experience with AI/ML models
Understanding of offensive security
Familiarity with cloud-native attack surfaces (AWS, Azure, GCP)
Effective communication and collaboration

Job description

Role & responsibilities
  • Conduct hypothesis-driven threat hunting across endpoint, network, and cloud environments, analyzing large volumes of EDR, SIEM, and NDR telemetry to surface IOCs and TTPs mapped to MITRE ATT&CK.
  • Develop and refine detection rules, correlation queries, and alert logic in SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
  • Perform malware analysis including behavioral analysis, IOC extraction, execution flow review, and threat attribution.
  • Collaborate with SOC, Threat Intelligence, Red Team, and Incident Response teams to investigate, contextualize, and translate purple team findings into detection logic and hunting playbooks.
  • Design and deploy AI/ML models to detect anomalies, classify threats, and reduce false positives, and help evaluate and integrate AI-driven tools into the existing SOC stack.
  • Build and maintain LLM-powered pipelines, agents, and ad-hoc security tooling using Python, with experience across prompt engineering, RAG, and fine-tuning techniques.
  • Strong understanding of penetration testing methodologies, offensive security tooling, and adversary tradecraft, with the ability to translate red team findings into actionable hunt hypotheses.
  • Stay current on emerging threat actor groups, CVEs, zero-days, and evolving adversary techniques.
  • Experience working with cloud security telemetry and familiarity with cloud-native attack surfaces across AWS, Azure, or GCP environments.
  • Ability to work with and query large-scale security data sources programmatically, including log aggregation platforms, threat intelligence APIs, and data lakes.
  • Document methodologies, tool capabilities, and investigation findings clearly, contributing to institutional knowledge and enabling repeatable, scalable hunt operations.
Preferred candidate profile
  • Threat hunting expertise across endpoint, network, and cloud environments, with hands on experience analyzing EDR, SIEM, and NDR telemetry and mapping findings to MITRE ATT&CK.
  • Proficiency in SIEM platforms (Splunk, Microsoft Sentinel, Elastic) including writing and tuning detection rules, correlation queries, and alert logic.
  • Malware analysis skills including behavioral analysis, IOC extraction, execution flow review, and threat attribution.
  • Experience designing and deploying AI/ML models for anomaly detection and threat classification, plus building LLM-powered pipelines and security tooling in Python.
  • Strong understanding of offensive security and adversary tradecraft, with the ability to translate red team and purple team findings into detection logic and hunt hypotheses.
  • Familiarity with cloud-native attack surfaces (AWS, Azure, GCP) and the ability to programmatically query large-scale security data sources including log platforms, threat intel APIs, etc.
  • Effective communicator and collaborator, with the ability to work with SOC, IR, and Threat Intelligence teams and document findings in a clear, repeatable, and scalable way.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunting Specialist
Threat Hunting Specialist

Terralogic • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Advanced Threat Hunting
Advanced Threat Hunting

PwC India • Mumbai

Hybrid
INR 1,200,000 - 2,400,000
Lead Threat Intelligence Analyst
Lead Threat Intelligence Analyst

Providence India • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Cyber Threat Hunter Professional
Cyber Threat Hunter Professional

Conduent • Navi Mumbai

On-site
INR 1,000,000 - 1,500,000
Threat Hunter - SOC
Threat Hunter - SOC

Network Intelligence • Mumbai

On-site
INR 1,000,000 - 1,500,000
Senior Threat Hunter
Senior Threat Hunter

UST • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
ARCHITECT - SOC Monitoring
ARCHITECT - SOC Monitoring

Happiest Minds Technologies • Bengaluru

Hybrid
INR 4,000,000 - 6,500,000
Threathunting Lead
Threathunting Lead

airtel • Gurugram District

On-site
INR 3,500,000 - 5,200,000
Threat Hunting Specialist
Threat Hunting Specialist

Lonvec Technologies Private Limited • Mumbai

Hybrid
INR 4,000,000 - 8,000,000