12 Sep
|
Kroll
|
Bengaluru
Kroll Cyber Threat Intelligence (CTI) is seeking a motivated and analytically minded Cyber Threat Intelligence Analyst based in India. The role focuses on identifying, investigating, and assessing cyber threats across open web, deep web, and dark web sources, then translating fragmented information into clear, defensible, and actionable intelligence for global business clients. The successful candidate will support international engagements, collaborate across regions, and apply sound intelligence tradecraft to complex investigative questions.
Day-to-day Responsibilities
- Conduct targeted and exploratory investigations across open web, deep web, dark web, and restricted-access sources to identify relevant threat activity, exposed data, fraud indicators, brand abuse, and emerging risk.
- Monitor underground forums, marketplaces, leak sites, illicit communities, messaging channels, paste sites, credential repositories, and other relevant sources for client-specific threats and material changes in the threat landscape.
- Develop and refine collection plans, search strategies, source lists, personas, keywords, and monitoring logic aligned to intelligence requirements and investigative objectives.
- Assess source reliability, information credibility, relevance, and confidence; distinguish corroborated findings from unverified claims and clearly communicate analytical limitations.
- Analyze cybercrime ecosystems, threat actors, campaigns, ransomware and extortion activity, data-theft operations, fraud schemes, and associated tactics, techniques, and procedures.
- Correlate information from multiple sources to identify relationships, patterns, changes in behavior, and implications for clients; maintain structured notes and an auditable evidentiary trail.
- Produce concise intelligence reports, investigative updates, threat assessments, and executive briefings that communicate key judgments, supporting evidence, confidence, and recommended actions.
- Provide focused investigative support during cyber incidents through threat actor research, infrastructure and indicator enrichment, leak-site monitoring, and rapid assessment of external reporting.
- Conduct digital footprint and exposure monitoring to identify leaked credentials, exposed information, impersonation, brand misuse, third-party references, and other indicators of potential risk.
- Participate in client communications, including status updates, investigative briefings, and clarification of findings, under the guidance of engagement leads.
- Track assigned workstreams, document investigative steps, meet delivery timelines, and manage multiple concurrent tasks while maintaining quality, responsiveness, and professionalism.
- Collaborate with CTI peers, incident response professionals, engagement leads, and regional stakeholders to deliver coordinated and intelligence-led client outcomes.
Essential Traits
- Strong intelligence analytical skills, including source evaluation, corroboration, hypothesis development, structured analysis, pattern recognition, and the articulation of confidence and analytical gaps.
- Ability to synthesize large volumes of structured and unstructured information into clear key judgments and client-relevant implications.
- Understanding of cybercrime ecosystems, threat actor behavior, ransomware and extortion, data theft, fraud, credential abuse, brand exploitation, and common threat actor TTPs.
- Ability to handle sensitive investigative information responsibly and maintain clear research notes, source records, and evidentiary documentation.
- Excellent written and verbal English communication skills, with the ability to tailor analysis for technical and non-technical audiences.
- Ability to work independently, exercise sound judgment, and collaborate effectively within a distributed global team.
- Experience in a consulting, managed intelligence, investigations, risk advisory,
or client services environment.
- Experience researching threat actors, online aliases, infrastructure, malware, campaigns, victimology, and relationships across underground ecosystems.
- Experience conducting both recurring monitoring and time-sensitive investigations against defined intelligence requirements.
- Experience preparing client-ready written products, executive summaries, investigative briefings, or recurring monitoring reports.
Prerequisites
- 1-3 years of experience in cyber threat intelligence, dark web research, cyber investigations, OSINT, fraud intelligence, or a closely related analytical discipline.
- Demonstrated hands-on experience investigating and monitoring open web, deep web, and dark web sources, including forums, marketplaces, leak sites, illicit communities, credential sources, and breach data repositories.
- Familiarity with CTI, OSINT, dark web monitoring, link-analysis, breach-data, cryptocurrency tracing, and investigative case-management tools.
- Knowledge of intelligence frameworks and standards such as the intelligence cycle, Structured Analytic Techniques, MITRE ATT&CK;, STIX/TAXII, and intelligence confidence language.
- Relevant certifications or training such as GCTI, SANS FOR578, GIAC Open Source Intelligence, or comparable CTI, OSINT, investigations, or analytical tradecraft programs are a plus.
- Willingness to support global clients, which may occasionally require flexible working hours that overlap with US or EMEA time zones.
- Strong sense of ownership, discretion, professionalism, and commitment to high-quality client service.
- Comfort operating in a consulting model with multiple concurrent workstreams, defined timelines, and evolving investigative priorities.
- Continuous learning mindset and willingness to develop expertise across new sources, tools, threat actors, and investigative methods.
- Brings disciplined curiosity, solid analytical judgment, and the ability to turn difficult-to-access information into transparent intelligence that helps clients make informed decisions.
📌 Associate, Threat Intelligence (Bengaluru)
🏢 Kroll
📍 Bengaluru