04 Aug
|
Airtel
|
Gurugram
Airtel iSOC is looking for a Threat Hunter & Threat Intelligence Lead to proactively identify, investigate, and disrupt adversary activity across the enterprise. This role will lead threat hunting operations, build and mature threat intelligence (TI) capabilities, and convert intelligence into detection engineering, incident response improvements, and measurable risk reduction. You will partner closely with SOC, IR, security engineering, and IT teams to strengthen prevention, detection, and response.
Key Responsibilities
Lead a structured threat hunting program aligned to MITRE ATT&CK; and emerging attacker TTPs.
Own threat intelligence operations: collection, analysis, enrichment, and dissemination.
Translate intelligence and hunting outcomes into high‑quality detections and SOC use cases.
Conduct advanced investigations and support major incident response activities.
Build and maintain hunting playbooks, detection rules, and dashboards.
Partner with SOC, IR, Red/Purple Teams to validate detection coverage and close gaps.
Define and report KPIs,
threat trends, and risk insights to technical teams and leadership.
Mentor analysts and support maturity of hunting and intel capabilities.
Required Qualifications
5+ years in cyber security with strong experience in Threat Hunting, Threat Intelligence, SOC, or Incident Response.
Hands‑on expertise with SIEM, EDR/XDR, cloud, and identity logs.
Robust knowledge of MITRE ATT&CK;, attacker lifecycle, and adversary tradecraft.
Detection engineering experience using KQL/SPL/SQL or equivalent query languages.
Sound investigation, log analysis, and incident scoping skills.
Clear communicator with ability to present technical findings in business term
Preferred
Cloud & SaaS threat hunting (Azure/AWS/GCP, M365, identity platforms).
Experience with TIPs, SOAR, Sigma, YARA, automation/scripting (Python/PowerShell).
Relevant certifications (e.g., GCIA, GCTI, GCFA, CISSP, SC 200).
📌 Threathunting Lead (Gurugram)
🏢 Airtel
📍 Gurugram