JJobsSonar

Threat Analyst

jobgether · India

Accountabilities: Investigate and analyze escalated security alerts and incidents across endpoint, network, cloud, and identity environments to identify malicious activity and determine appropriate response actions. Conduct structured incident investigations to establish root causes, assess attack scope, identify lateral movement, and evaluate potential business impact. Support ransomware investigations by analyzing attacker behaviors, persistence mechanisms, credential abuse techniques, and malware activity. Perform malware analysis and deobfuscation of suspicious scripts and files to uncover indicators of compromise and adversary tactics. Execute proactive threat hunting activities based on emerging intelligence, threat hypotheses, and evolving attack techniques. Investigate suspicious authentication events, privilege escalation attempts, and identity-related security incidents. Analyze security events across both Windows and Linux environments, including system logs, processes, and endpoint telemetry. Correlate information from multiple data sources, including EDR platforms, SIEM solutions, cloud environments, and identity management systems. Document investigative findings, provide clear remediation recommendations, and communicate effectively with internal stakeholders and clients. Collaborate with senior analysts during complex or high-severity incidents and contribute to improving detection capabilities, playbooks, and response processes. Participate in a rotational schedule supporting a 24/7/365 security operations environment. Requirements 4–6 years of experience in Security Operations Centers (SOC), Managed Detection and Response (MDR), Incident Response, or related cybersecurity operations roles. Hands-on experience investigating endpoint and network security incidents using EDR and SIEM technologies. Strong understanding of ransomware attack methodologies, intrusion techniques, and adversary behaviors. Experience performing investigations across Windows and Linux systems, including log analysis and process examination. Practical experience with malware analysis, script deobfuscation, and identifying malicious behaviors. Familiarity with the MITRE ATT&CK framework and adversary tactics, techniques, and procedures (TTPs). Knowledge of Windows Event Logs, Linux logging systems, Active Directory fundamentals, and identity-related security investigations. Understanding of cloud security concepts and identity threat scenarios, including suspicious authentication activity and privileged account misuse. Ability to analyze network traffic and protocols, including TCP/IP, DNS, and HTTP/S. Scripting and automation skills are required, particularly with PowerShell and Python; knowledge of additional programming languages is advantageous. Strong analytical thinking, troubleshooting capabilities, and attention to investigative detail. Excellent written and verbal communication skills with the ability to produce clear technical documentation. Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience. Industry certifications such as Security+, CySA+, GCIH, or equivalent certifications are considered a strong advantage. Ability to manage multiple investigations simultaneously in a dynamic and fast-paced environment. Benefits Remote-first working model providing flexibility and improved work-life balance. Opportunity to work with advanced cybersecurity technologies and real-world threat investigations. Exposure to global cybersecurity operations and collaboration with highly experienced security professionals. Inclusive and diverse workplace supported by employee-led communities and advocacy networks. Professional development opportunities and continuous learning within a rapidly evolving industry. Global wellbeing initiatives, including wellness days, webinars, and employee support programs. Participation in charity events, volunteering initiatives, and sustainability programs. Engaging company culture featuring global fitness challenges, team activities, and knowledge-sharing opportunities. Supportive and collaborative environment that values innovation, diversity, and career growth.
Ready to apply?Apply now

Similar jobs

Browse all

Cloud Platform Engineer

ASE (Analysis Simulation Engineering) AG · Zurich, Zurich, Switzerland

On-siteEasy apply2w ago

DevOps Engineer

Sundayy · United States

RemoteEasy apply401(k), Medical2w ago