Threat Analyst
EDRSIEMPowerShellPythonTCP/IPDNSHTTP/SMalware AnalysisThreat HuntingMITRE ATT&CK
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst based in India. As a Threat Analyst, you will investigate and respond to sophisticated cyber threats across endpoint, network, cloud, and identity environments. You will work with enterprise security platforms, logs, and endpoint telemetry to identify malicious activity and determine the scope and impact of incidents. The role provides hands-on exposure to ransomware investigations, malware analysis, threat hunting, and adversary techniques. You will collaborate closely with experienced security professionals on complex and high-severity investigations in a 24x7x365 monitoring environment. Your findings will help strengthen detection capabilities, improve response playbooks, and provide actionable remediation guidance to clients. This is an opportunity to deepen your investigative expertise while working with modern EDR, SIEM, cloud, and identity security technologies. The role is well suited to an analytical cybersecurity professional who thrives in fast-paced environments and enjoys solving complex security problems. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst based in India. As a Threat Analyst, you will investigate and respond to sophisticated cyber threats across endpoint, network, cloud, and identity environments. You will work with enterprise security platforms, logs, and endpoint telemetry to identify malicious activity and determine the scope and impact of incidents. The role provides hands-on exposure to ransomware investigations, malware analysis, threat hunting, and adversary techniques. You will collaborate closely with experienced security professionals on complex and high-severity investigations in a 24x7x365 monitoring environment. Your findings will help strengthen detection capabilities, improve response playbooks, and provide actionable remediation guidance to clients. This is an opportunity to deepen your investigative expertise while working with modern EDR, SIEM, cloud, and identity security technologies. The role is well suited to an analytical cybersecurity professional who thrives in fast-paced environments and enjoys solving complex security problems. Accountabilities: Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments. Perform structured investigations to determine root cause, attack scope, lateral movement, persistence, and potential business impact. Support ransomware investigations by analyzing attacker behavior, credential abuse, persistence mechanisms, malware activity, and related indicators. Analyze and deobfuscate suspicious scripts, malware samples, and other artifacts to identify malicious behavior. Conduct proactive threat hunting based on defined hypotheses, threat intelligence, emerging attack patterns, and adversary techniques. Investigate suspicious authentication activity, privilege escalation, compromised accounts, and other forms of identity misuse. Perform investigations across Windows and Linux environments, including detailed analysis of system logs, processes, and other relevant artifacts. Correlate information from multiple security sources, including EDR, SIEM, cloud logging, and identity platforms, to build a complete picture of incidents. Analyze network activity involving technologies and protocols such as TCP/IP, DNS, and HTTP/S to identify suspicious communications and attack behavior. Clearly document investigative findings and provide actionable remediation recommendations to stakeholders and clients. Collaborate with senior analysts on high-severity, complex, or sensitive security incidents. Contribute to detection tuning, investigation methodologies, and response playbook improvements based on lessons learned from incidents. Participate in a rotational schedule supporting continuous 24x7x365 managed detection and response operations. Requirements 4–6 years of professional experience in a Security Operations Center (SOC), Managed Detection and Response (MDR), Incident Response, or related cybersecurity operations environment. Hands-on experience investigating endpoint and network security alerts using EDR and SIEM platforms. Practical understanding of ransomware attack patterns, intrusion techniques, persistence mechanisms, credential abuse, and common adversary behaviors. Experience investigating both Windows and Linux systems, including operating system artifacts, processes, and security logs. Experience analyzing obfuscated scripts and malware behavior, with practical knowledge of deobfuscation techniques. Familiarity with adversary tactics, techniques, and procedures (TTPs), with practical exposure to the MITRE ATT&CK framework. Experience analyzing Windows Event Logs, Linux logs, and Active Directory fundamentals. Basic understanding of cloud and identity security investigations, including suspicious authentication activity and privileged account misuse. Ability to analyze network traffic and understand core networking concepts including TCP/IP, DNS, and HTTP/S. Strong scripting capabilities, including PowerShell, with Python or another programming language required. Strong analytical, troubleshooting, and investigative skills, with a methodical approach to complex security problems. Excellent documentation skills and attention to detail when recording investigative evidence, conclusions, and recommendations. Strong written and verbal communication skills, with the ability to clearly explain technical findings. Ability to manage multiple investigations and competing priorities in a fast-paced operational environment. A bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience. Security certifications such as Security+, CySA+, GCIH, or equivalent credentials are advantageous. Legal authorization to work in India without requiring employer sponsorship. Benefits Remote-first working model, with flexibility depending on the requirements of the role. Opportunity to work on real-world cybersecurity incidents and investigate sophisticated threats across multiple technology environments. Exposure to modern EDR, SIEM, cloud, identity, endpoint, and network security technologies. Collaboration with experienced cybersecurity professionals and senior analysts. Opportunities to strengthen expertise in threat hunting, incident response, malware analysis, and adversary techniques. Employee-led diversity and inclusion initiatives designed to foster community, learning, and advocacy. Employee wellbeing programs, including dedicated wellbeing days and regular health and wellness webinars. Opportunities to participate in charitable initiatives, fundraising activities, and employee volunteering programs. Global sustainability initiatives and employee engagement activities. Fitness, trivia, and other programs designed to support employee connection and wellbeing. Supportive environment focused on continuous learning, professional development, and career growth. Inclusive workplace committed to equal opportunity and fair treatment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
Not disclosed
Location
India
Job type
Full-time
Category
Security Engineering
Experience
4–6 years
Posted
Today
Job Highlights
- 4–6 years level role
- 100% Remote — open to candidates in India
- Full-time position
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.