Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst 2 based in India.
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst 2 based in India. This role sits within a global Managed Detection and Response environment focused on identifying, investigating, and helping neutralize sophisticated cyber threats. You will investigate escalated alerts across endpoint, network, cloud, and identity environments using enterprise security platforms. The position provides hands-on exposure to incident response, threat hunting, ransomware investigations, malware analysis, and adversary techniques. You will work closely with experienced analysts on complex and high-severity incidents while developing deeper investigative expertise. Your findings will help strengthen detection capabilities, response playbooks, and the security posture of clients. The role combines technical investigation with clear documentation, client-facing remediation guidance, and cross-team collaboration. You will participate in a rotational schedule supporting a 24x7x365 security operations environment.
Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments. Analyze incidents to establish root cause, attack scope, lateral movement, affected systems, and potential business impact. Support ransomware investigations by examining attacker activity, credential abuse, persistence techniques, and malware behavior. Analyze and deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity. Conduct proactive threat hunting based on defined hypotheses, threat intelligence, and emerging attacker behaviors. Investigate suspicious authentication activity, privilege escalation, and identity or privileged-account misuse. Perform investigations across Windows and Linux environments, including process analysis and examination of relevant logs. Correlate information from EDR, SIEM, cloud logging, identity platforms, and other security data sources. Document investigative findings accurately and provide actionable remediation recommendations to clients. Collaborate with senior analysts on complex or high-severity incidents and contribute to incident response activities. Support detection tuning and the improvement of response playbooks based on lessons learned from investigations. Participate in a rotational schedule supporting continuous 24x7x365 MDR operations. Requirements 3–5 years of experience in a SOC, MDR, incident response, or related cybersecurity operations environment. Hands-on experience investigating endpoint and network security alerts using EDR and SIEM technologies. Working knowledge of ransomware attack patterns, common intrusion techniques, and adversary behaviors. Practical experience investigating both Windows and Linux systems. Experience analyzing obfuscated scripts and malware behavior, including deobfuscation techniques. Familiarity with adversary tactics and techniques and practical exposure to the MITRE ATT&CK framework. Experience working with Windows Event Logs, Linux logs, and Active Directory fundamentals. Basic understanding of cloud and identity security investigations, including suspicious authentication and privileged-account activity. Ability to analyze network traffic and core protocols such as TCP/IP, DNS, and HTTP/S. Mandatory scripting knowledge, including PowerShell , with Python or another programming language. Strong investigative documentation skills, attention to detail, analytical thinking, and troubleshooting abilities. Ability to manage multiple investigations simultaneously in a fast-paced operational environment. Clear written and verbal communication skills, particularly when documenting technical findings and communicating remediation guidance. A bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent professional experience. Security certifications such as Security+, CySA+, GCIH , or equivalent are advantageous. Willingness to work rotational schedules supporting a continuous 24x7x365 MDR operation. Benefits Remote-first working model, with remote work as the primary arrangement for most roles. Opportunity to work on real-world cybersecurity incidents and develop expertise across multiple security domains. Exposure to endpoint, network, cloud, identity, SIEM, EDR, threat intelligence, and incident response technologies. Collaboration with experienced security professionals on complex and high-severity investigations. Employee-led diversity and inclusion networks supporting community, education, and advocacy. Annual charity, fundraising, and employee volunteer initiatives. Global sustainability initiatives and employee participation opportunities. Global fitness and trivia activities. Wellbeing days, webinars, and training focused on employee health and wellbeing. Inclusive working environment with support for reasonable adjustments throughout the recruitment process. Opportunities to strengthen investigative, threat-hunting, malware-analysis, and incident-response capabilities.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
jobgether (lever) ↗Browse current JobOpportunity listings from jobgether (lever) →