Verified current Job

Threat Analyst

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst based in India.

Job Remote Full source details
Jobgether Source published Sep 23, 2026 Verified 49 minutes ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst based in India.

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst based in India. This role focuses on investigating and responding to sophisticated cyber threats across enterprise security environments. You will analyze alerts and incidents across endpoint, network, cloud, and identity systems to determine root cause, scope, and potential impact. The position combines hands-on investigation with threat hunting, malware analysis, and security data correlation. You will work closely with experienced analysts on complex and high-severity incidents while contributing to stronger detection and response capabilities. Your investigations will help provide clients with clear findings and actionable recommendations to strengthen their security posture. Working within a remote-first environment, you will support a 24x7x365 managed detection and response operation and gain exposure to real-world cyber threats.

Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments, using structured investigative methods to determine the nature and severity of threats. Analyze incidents to establish root cause, attack scope, lateral movement, persistence mechanisms, credential abuse, and potential business impact. Support ransomware investigations by examining attacker activity, malware behavior, persistence techniques, and compromised credentials. Analyze and deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity and understand attacker behavior. Conduct proactive threat hunts based on defined hypotheses, emerging intelligence, suspicious behaviors, and relevant adversary techniques. Investigate suspicious authentication events, privilege escalation, privileged account misuse, and other forms of identity-based compromise. Perform investigations across Windows and Linux environments, including operating-system logs, processes, authentication activity, and other forensic indicators. Correlate information from multiple security sources, including EDR, SIEM, cloud logging, identity platforms, and network telemetry. Analyze relevant network activity involving protocols and technologies such as TCP/IP, DNS, and HTTP/S to identify suspicious communications and attack patterns. Document investigative findings clearly and provide actionable remediation guidance to support clients in containing threats and improving their security posture. Collaborate with senior analysts on complex or high-severity investigations and contribute to the continuous improvement of investigative practices. Support detection tuning and response playbook improvements based on lessons learned from investigations and emerging threat activity. Participate in a rotational schedule supporting continuous 24x7x365 managed detection and response operations. Requirements 3–5 years of professional experience in a Security Operations Center, Managed Detection and Response, Incident Response, or related cybersecurity operations environment. Hands-on experience investigating endpoint and network security alerts using EDR and SIEM platforms. Working knowledge of ransomware attack patterns, common intrusion techniques, adversary behaviors, and practical application of the MITRE ATT&CK framework. Experience investigating both Windows and Linux systems, including Windows Event Logs, Linux logs, processes, and Active Directory fundamentals. Practical experience analyzing obfuscated scripts and malware behavior, with the ability to perform deobfuscation and identify malicious activity. Basic understanding of cloud and identity security investigations, including suspicious authentication activity, privileged account misuse, and identity-based threats. Ability to analyze network traffic and investigate activity involving TCP/IP, DNS, and HTTP/S. Strong scripting capabilities, including PowerShell and Python or another comparable programming language. Strong analytical, troubleshooting, and investigative skills, with careful attention to technical detail. Ability to manage multiple investigations in a fast-paced environment while maintaining accuracy and clear documentation. Strong written and verbal communication skills, with the ability to communicate technical findings and remediation recommendations clearly. Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience. Security certifications such as Security+, CySA+, GCIH, or equivalent credentials are advantageous. Willingness and ability to participate in a rotational schedule supporting a continuous 24x7x365 security operations environment. Benefits Remote-first working model, with remote work serving as the primary arrangement for most roles. Opportunity to work on real-world cybersecurity investigations across endpoint, network, cloud, and identity environments. Exposure to advanced threat detection, incident response, ransomware investigations, malware analysis, threat hunting, and security operations. Close collaboration with experienced security professionals and opportunities to strengthen investigative expertise. Opportunities to develop practical knowledge across EDR, SIEM, cloud security, identity security, MITRE ATT&CK, and security automation. Professional development opportunities and continued learning within a cybersecurity-focused environment. Employee-led diversity and inclusion networks that support community, education, and advocacy. Employee volunteer days, charitable initiatives, and opportunities to contribute to local communities. Global sustainability initiatives supporting environmental responsibility. Employee wellbeing programs, including wellbeing days, webinars, and health-focused training. Global fitness and trivia activities designed to support employee connection and wellbeing. Inclusive working environment that values diverse perspectives and provides equal opportunities for professional growth.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

jobgether (lever) ↗

Browse current JobOpportunity listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books