
Threat Analyst- Team Lead
- Bangalore, Karnataka
- Permanent
- Full-time
- Maintain supervision over operational tasks and provide day-to-day oversight for threat analysts
- Oversee analysts in their investigation and response
- Activities when security incidents arise to determine possible root cause and resolution
- Effectively communicate information to stakeholders of all levels
- Demonstrate experience in network and host-based intrusion analysis, incident response processes and procedures, digital forensics and/or handling malware
- Acting as a lead throughout incident scenarios and provide subject matter expertise in cybersecurity incident response·
- Successfully executing incident handling procedures as well as direct response to cyber security incidents
- Maintaining current knowledge and recognition of attacker tools, tactics, and procedures to produce indicators of compromise (IOCs) that can be utilized during active and future investigations
- Assessing cyber threat intelligence/open source intelligence and operationalizing that information
- Demonstrating real-world, hands-on experience dealing with sophisticated malware and dynamic cyber threat actors
- Identifying current and emerging threats and application of such research
- 7+ years of experience within a cybersecurity environment with some experience in a leadership role is required
- Bachelor's in information technology, Computer Science, or a related field; or relevant, commensurate work experience
- Experience in a security operations center, or similar environment, and identifying indications of compromise or attack and responding to incidents
- Endpoint and network security experience required; IDS, IPS, EDR, ATP, Malware defenses and monitoring experience
- Threat hunting and threat intelligence experience
- Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc.
- Knowledge of Mitre ATT&CK framework
- Working knowledge of incident response procedures
- Experience with SQL query construction preferred
- Experience with OSQuery is a plus
- Experience administering and supporting Windows OS (both workstations and server) and one of the following: Apple or Linux-based operating systems (e.g. XP, Windows 7, 2003, 2008, OS X)
- Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.