10 Aug
|
Hindustan Ports
|
India
10 Aug
Hindustan Ports
India
Threat Detection Specialist
Location : Bangalore (5 days work from office)
Experience : 8 - 12 Yr
Job Purpose :
The role is responsible for designing, developing, and operationalizing advanced threat detection capabilities using AI/ML, behavioral analytics, and threat intelligence. This role focuses on translating threat intelligence into actionable detections, enhancing detection coverage across enterprise environments (endpoint, identity, network, and cloud), and continuously improving detection efficacy through collaboration with red teams and threat hunting initiatives.
Reports to : Director Information Security
Please Note: 4-5 years of hands on experience in Azure Sentinel is mandatory.
Key Accountabilities :
Develop and operationalize AI/ML-based threat detection models :
- Develop and operationalize AI/ML-based threat detection models across endpoint, identity, network, and cloud environments.
- Operationalise threat intelligence feeds into AI-driven detection pipelines, ensuring alignment with MITRE ATT&CK; TTPs.
- Design, develop, and deploy detection use cases across SIEM and XDR platforms.
- Build, maintain, and continuously tune detection rules, KQL queries, and analytics for improved detection fidelity.
- Design and enhance UEBA (User and Entity Behaviour Analytics) models to detect anomalies, insider threats, and advanced persistent threats (APTs).
- Collaborate with red team and adversary simulation functions to validate detection coverage against real-world attack scenarios.
- Drive proactive threat hunting by developing automated workflows leveraging AI-assisted query generation and anomaly detection.
- Continuously evaluate detection effectiveness, reduce false positives, and improve signal-to-noise ratio.
- Integrate multiple threat intelligence sources and contextual data to enrich detections and improve response outcomes.
- Contribute to the development of threat detection standards, frameworks, and best practices.
- Maintain up-to-date knowledge of evolving threats, adversary techniques,
and detection technologies to continuously strengthen the organizations cyber defense capabilities.
- Act as an ambassador for DP World at all times when working; promoting and demonstrating positive behaviours in harmony with DP Worlds Principles, values and culture; ensuring the highest level of safety is applied in all activities; understanding and following DP Worlds Code of Conduct and Ethics policies.
- Perform other related duties as assigned.
Job Context :
The Threat Detection Specialist operates within the Cyber Defense function and reports to the Director Information Security. The role is focused on strengthening DP Worlds detection and response capabilities by leveraging AI, threat intelligence, and advanced analytics. It requires close collaboration with SOC, threat intelligence, red team, and engineering teams to ensure comprehensive detection coverage and rapid response to evolving cyber threats.
Qualifications, Experience and Skills :
Knowledge and Experience :
- Bachelors degree in computer science, Cyber Security, Information Systems, or related field.
- 8 years of experience in cybersecurity, with a strong focus on threat detection, threat hunting, or detection engineering.
- Hands-on experience with SIEM/XDR platforms, preferably Microsoft Sentinel and Falcon /Cortex/Stellar Cyber/Defender XDR.
- Strong understanding of MITRE ATT&CK; framework and adversary tactics, techniques, and procedures (TTPs).
- Experience in developing detection logic, analytics, and threat hunting queries (e.g., KQL).
- Experience in AI/ML applications for cybersecurity, including anomaly detection and behavioural analytics.
- Experience working with threat intelligence platforms and integrating intelligence into detection workflows.
- Familiarity with cloud security (Azure, AWS), endpoint security, and identity-based threat detection.
- Relevant certifications such as GCIA, GCIH, GCED, AZ-500, SC-200, or equivalent are preferred.
- Experience in multinational environments is an advantage.
Soft Skills :
- Strong analytical and problem-solving skills.
- Excellent verbal and written communication skills.
- Ability to work in cross-functional teams (SOC, Red Team, Engineering).
- Proactive mindset with strong attention to detail.
- Ability to manage multiple priorities in a quick-paced environment.
- Continuous learning attitude, especially in AI and emerging cyber threats.
Technical Skills :
- Proficiency in KQL (Kusto Query Language) and detection rule development.
- Strong understanding of SIEM, XDR, EDR technologies.
- Experience with UEBA and behavioural analytics platforms.
- Hands-on experience of AI/ML concepts applied to cybersecurity (anomaly detection, classification models).
- Understanding of log sources and telemetry across endpoint, network, identity, and cloud.
- Familiarity with scripting languages (Python, PowerShell) for automation and analysis.
- Experience with threat hunting frameworks and automation tools.
- Strong knowledge of cyber threats, attack techniques, and detection strategies.
Communications and Working Relationships :
Internal :
- Cyber Defense (SOC, Threat Intelligence)
- Technology teams
- Regional and Business Unit IT/Security teams
External :
- Security vendors and partners
- Threat intelligence providers
- Consultants and service providers
Frameworks, Boundaries and Decision-Making Authority :
- Responsible for developing and tuning detection content and analytics within defined cybersecurity frameworks.
- Works within DP World cyber defense strategy and governance guidelines.
- Provides recommendations on detection improvements, tooling, and automation.
📌 DP World - Threat Detection Specialist (India)
🏢 Hindustan Ports
📍 India