Role Summary We are looking for a Threat Hunter to join our Cyber Security team and proactively identify, analyze, and mitigate advanced threats targeting the bank's IT and digital banking infrastructure. The candidate will use FortiRecon for external attack surface and digital risk monitoring, and interpret threat hunting reports and vulnerability advisories to drive proactive hunts using Splunk and Microsoft Sentinel, in line with RBI cybersecurity guidelines and industry best practices. Key Responsibilities Conduct proactive, hypothesis-driven threat hunting across endpoints, network, cloud, and core banking-adjacent systems using Splunk and Microsoft Sentinel. Monitor and act on intelligence from FortiRecon (external attack surface management, brand/phishing protection, digital risk monitoring) to identify exposure relevant to a financial services target profile. Interpret threat intelligence reports, vulnerability advisories (CVE bulletins, OEM/vendor advisories), and sector-specific s (CERT-In, RBI/IDRBT, FS-ISAC) to build hunting hypotheses and prioritize action.
Develop hunting playbooks, KQL/SPL queries, and use cases mapped to MITRE ATT&CK;, with emphasis on threats relevant to banking (phishing, credential theft, fraud-linked malware, ATM/payment switch threats, insider risk). Correlate findings across EDR, network, cloud, and identity logs to validate threats and hand off confirmed incidents to the Incident Response team. Support timely reporting/escalation in line with CERT-In incident reporting timelines and internal regulatory obligations. Collaborate with Vulnerability Management, SOC, and IT teams to close detection and patching gaps surfaced during hunts. Maintain documentation of hunting methodology, findings, and detection coverage improvements for internal and regulatory audits (RBI IS Audit, VAPT reviews). Stay current on threat actor campaigns and TTPs targeting Indian financial institutions. Required Skills & Experience 3–6 years in a Threat I
📌 Threat Hunter (Thrissur)
🏢 UST
📍 Thrissur