Threat Analyst 2
EDRSIEMPowerShellPythonWindows Event LogsLinux logsActive DirectoryTCP/IPDNSHTTP/S
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst 2 based in India. This role sits within a global Managed Detection and Response environment focused on identifying, investigating, and helping neutralize sophisticated cyber threats. You will investigate escalated alerts across endpoint, network, cloud, and identity environments using enterprise security platforms. The position provides hands-on exposure to incident response, threat hunting, ransomware investigations, malware analysis, and adversary techniques. You will work closely with experienced analysts on complex and high-severity incidents while developing deeper investigative expertise. Your findings will help strengthen detection capabilities, response playbooks, and the security posture of clients. The role combines technical investigation with clear documentation, client-facing remediation guidance, and cross-team collaboration. You will participate in a rotational schedule supporting a 24x7x365 security operations environment. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst 2 based in India. This role sits within a global Managed Detection and Response environment focused on identifying, investigating, and helping neutralize sophisticated cyber threats. You will investigate escalated alerts across endpoint, network, cloud, and identity environments using enterprise security platforms. The position provides hands-on exposure to incident response, threat hunting, ransomware investigations, malware analysis, and adversary techniques. You will work closely with experienced analysts on complex and high-severity incidents while developing deeper investigative expertise. Your findings will help strengthen detection capabilities, response playbooks, and the security posture of clients. The role combines technical investigation with clear documentation, client-facing remediation guidance, and cross-team collaboration. You will participate in a rotational schedule supporting a 24x7x365 security operations environment. Accountabilities Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments. Analyze incidents to establish root cause, attack scope, lateral movement, affected systems, and potential business impact. Support ransomware investigations by examining attacker activity, credential abuse, persistence techniques, and malware behavior. Analyze and deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity. Conduct proactive threat hunting based on defined hypotheses, threat intelligence, and emerging attacker behaviors. Investigate suspicious authentication activity, privilege escalation, and identity or privileged-account misuse. Perform investigations across Windows and Linux environments, including process analysis and examination of relevant logs. Correlate information from EDR, SIEM, cloud logging, identity platforms, and other security data sources. Document investigative findings accurately and provide actionable remediation recommendations to clients. Collaborate with senior analysts on complex or high-severity incidents and contribute to incident response activities. Support detection tuning and the improvement of response playbooks based on lessons learned from investigations. Participate in a rotational schedule supporting continuous 24x7x365 MDR operations. Requirements 3–5 years of experience in a SOC, MDR, incident response, or related cybersecurity operations environment. Hands-on experience investigating endpoint and network security alerts using EDR and SIEM technologies. Working knowledge of ransomware attack patterns, common intrusion techniques, and adversary behaviors. Practical experience investigating both Windows and Linux systems. Experience analyzing obfuscated scripts and malware behavior, including deobfuscation techniques. Familiarity with adversary tactics and techniques and practical exposure to the MITRE ATT&CK framework. Experience working with Windows Event Logs, Linux logs, and Active Directory fundamentals. Basic understanding of cloud and identity security investigations, including suspicious authentication and privileged-account activity. Ability to analyze network traffic and core protocols such as TCP/IP, DNS, and HTTP/S. Mandatory scripting knowledge, including PowerShell , with Python or another programming language. Strong investigative documentation skills, attention to detail, analytical thinking, and troubleshooting abilities. Ability to manage multiple investigations simultaneously in a fast-paced operational environment. Clear written and verbal communication skills, particularly when documenting technical findings and communicating remediation guidance. A bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent professional experience. Security certifications such as Security+, CySA+, GCIH , or equivalent are advantageous. Willingness to work rotational schedules supporting a continuous 24x7x365 MDR operation. Benefits Remote-first working model, with remote work as the primary arrangement for most roles. Opportunity to work on real-world cybersecurity incidents and develop expertise across multiple security domains. Exposure to endpoint, network, cloud, identity, SIEM, EDR, threat intelligence, and incident response technologies. Collaboration with experienced security professionals on complex and high-severity investigations. Employee-led diversity and inclusion networks supporting community, education, and advocacy. Annual charity, fundraising, and employee volunteer initiatives. Global sustainability initiatives and employee participation opportunities. Global fitness and trivia activities. Wellbeing days, webinars, and training focused on employee health and wellbeing. Inclusive working environment with support for reasonable adjustments throughout the recruitment process. Opportunities to strengthen investigative, threat-hunting, malware-analysis, and incident-response capabilities. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
Not disclosed
Location
India
Job type
Full-time
Category
Security Engineering
Experience
3–5 years
Posted
Today
Job Highlights
- 3–5 years level role
- 100% Remote — open to candidates in India
- Full-time position
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.