Jobgether
Jobgether

Threat Analyst

engineeringfull-timeIndia
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities:

    • Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments.
    • Perform structured investigations to determine root cause, attack scope, lateral movement, persistence, and potential business impact.
    • Support ransomware investigations by analyzing attacker behavior, credential abuse, persistence mechanisms, malware activity, and related indicators.
    • Analyze and deobfuscate suspicious scripts, malware samples, and other artifacts to identify malicious behavior.
    • Conduct proactive threat hunting based on defined hypotheses, threat intelligence, emerging attack patterns, and adversary techniques.
    • Investigate suspicious authentication activity, privilege escalation, compromised accounts, and other forms of identity misuse.
    • Perform investigations across Windows and Linux environments, including detailed analysis of system logs, processes, and other relevant artifacts.
    • Correlate information from multiple security sources, including EDR, SIEM, cloud logging, and identity platforms, to build a complete picture of incidents.
    • Analyze network activity involving technologies and protocols such as TCP/IP, DNS, and HTTP/S to identify suspicious communications and attack behavior.
    • Clearly document investigative findings and provide actionable remediation recommendations to stakeholders and clients.
    • Collaborate with senior analysts on high-severity, complex, or sensitive security incidents.
    • Contribute to detection tuning, investigation methodologies, and response playbook improvements based on lessons learned from incidents.
    • Participate in a rotational schedule supporting continuous 24x7x365 managed detection and response operations.
    • Requirements

      • 4–6 years of professional experience in a Security Operations Center (SOC), Managed Detection and Response (MDR), Incident Response, or related cybersecurity operations environment.
      • Hands-on experience investigating endpoint and network security alerts using EDR and SIEM platforms.
      • Practical understanding of ransomware attack patterns, intrusion techniques, persistence mechanisms, credential abuse, and common adversary behaviors.
      • Experience investigating both Windows and Linux systems, including operating system artifacts, processes, and security logs.
      • Experience analyzing obfuscated scripts and malware behavior, with practical knowledge of deobfuscation techniques.
      • Familiarity with adversary tactics, techniques, and procedures (TTPs), with practical exposure to the MITRE ATT&CK framework.
      • Experience analyzing Windows Event Logs, Linux logs, and Active Directory fundamentals.
      • Basic understanding of cloud and identity security investigations, including suspicious authentication activity and privileged account misuse.
      • Ability to analyze network traffic and understand core networking concepts including TCP/IP, DNS, and HTTP/S.
      • Strong scripting capabilities, including PowerShell, with Python or another programming language required.
      • Strong analytical, troubleshooting, and investigative skills, with a methodical approach to complex security problems.
      • Excellent documentation skills and attention to detail when recording investigative evidence, conclusions, and recommendations.
      • Strong written and verbal communication skills, with the ability to clearly explain technical findings.
      • Ability to manage multiple investigations and competing priorities in a fast-paced operational environment.
      • A bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience.
      • Security certifications such as Security+, CySA+, GCIH, or equivalent credentials are advantageous.
      • Legal authorization to work in India without requiring employer sponsorship.
      • Benefits

        • Remote-first working model, with flexibility depending on the requirements of the role.
        • Opportunity to work on real-world cybersecurity incidents and investigate sophisticated threats across multiple technology environments.
        • Exposure to modern EDR, SIEM, cloud, identity, endpoint, and network security technologies.
        • Collaboration with experienced cybersecurity professionals and senior analysts.
        • Opportunities to strengthen expertise in threat hunting, incident response, malware analysis, and adversary techniques.
        • Employee-led diversity and inclusion initiatives designed to foster community, learning, and advocacy.
        • Employee wellbeing programs, including dedicated wellbeing days and regular health and wellness webinars.
        • Opportunities to participate in charitable initiatives, fundraising activities, and employee volunteering programs.
        • Global sustainability initiatives and employee engagement activities.
        • Fitness, trivia, and other programs designed to support employee connection and wellbeing.
        • Supportive environment focused on continuous learning, professional development, and career growth.
        • Inclusive workplace committed to equal opportunity and fair treatment.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now