06 Aug
|
Network Intelligence India
|
Bengaluru
06 Aug
Network Intelligence India
Bengaluru
Role & responsibilities
- Conduct hypothesis-driven threat hunting across endpoint, network, and cloud environments, analyzing large volumes of EDR, SIEM, and NDR telemetry to surface IOCs and TTPs mapped to MITRE ATT&CK.;
- Develop and refine detection rules, correlation queries, and alert logic in SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
- Perform malware analysis including behavioral analysis, IOC extraction, execution flow review, and threat attribution.
- Collaborate with SOC, Threat Intelligence, Red Team, and Incident Response teams to investigate, contextualize, and translate purple team findings into detection logic and hunting playbooks.
• Design and deploy AI/ML models to detect anomalies, classify threats, and reduce false positives, and help evaluate and integrate AI-driven tools into the existing SOC stack.
- Build and maintain LLM-powered pipelines, agents, and ad-hoc security tooling using Python, with experience across prompt engineering, RAG, and fine-tuning techniques.
- Strong understanding of penetration testing methodologies, offensive security tooling, and adversary tradecraft, with the ability to translate red team findings into actionable hunt hypotheses.
- Stay current on emerging threat actor groups, CVEs, zero-days, and evolving adversary techniques.
- Experience working with cloud security telemetry and familiarity with cloud-native attack surfaces across AWS, Azure, or GCP environments.
- Ability to work with and query large-scale security data sources programmatically,
including log aggregation platforms, threat intelligence APIs, and data lakes.
• Document methodologies, tool capabilities, and investigation findings clearly, contributing to institutional knowledge and enabling repeatable, scalable hunt operations.
Preferred candidate profile
• Threat hunting expertise across endpoint, network, and cloud environments, with hands on experience analyzing EDR, SIEM, and NDR telemetry and mapping findings to MITRE ATT&CK.;
• Proficiency in SIEM platforms (Splunk, Microsoft Sentinel, Elastic) including writing and tuning detection rules, correlation queries, and alert logic.
• Malware analysis skills including behavioral analysis, IOC extraction, execution flow review, and threat attribution.
• Experience designing and deploying AI/ML models for anomaly detection and threat classification, plus building LLM-powered pipelines and security tooling in Python.
• Strong understanding of offensive security and adversary tradecraft, with the ability to translate red team and purple team findings into detection logic and hunt hypotheses.
• Familiarity with cloud-native attack surfaces (AWS, Azure, GCP) and the ability to programmatically query large-scale security data sources including log platforms, threat intel APIs, etc.
• Effective communicator and collaborator, with the ability to work with SOC, IR, and Threat Intelligence teams and document findings in a explicit, repeatable, and scalable way.
📌 Threat Hunting Analyst (Bengaluru)
🏢 Network Intelligence India
📍 Bengaluru