P

Lead Cybersecurity Operations Analyst

Providence Hyderabad, Telangana, India

Hospitals and Health Care · 1,001-5,000 employees

13 h ago
security Principal (10+ yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Lead Cybersecurity Operations Analyst is responsible for proactive threat hunting across enterprise environments using advanced detection techniques and threat intelligence. They will also conduct digital forensic investigations, develop SOAR playbooks, and refine security detection rules to mitigate advanced cyber threats.

What they look for

Threat hunting Cybersecurity SIEM SOAR MITRE ATT&CK EDR/XDR KQL Python PowerShell Malware analysis Digital forensics Incident response Active Directory Azure Cloud Networking protocols SQL

Requirements

Candidates must have over 9 years of cybersecurity experience, with at least 6 years specifically in threat hunting. Proficiency in SIEM/SOAR platforms, EDR/XDR solutions, and scripting languages like Python or PowerShell is required, along with expertise in the MITRE ATT&CK framework.

Full description

Job Description – Lead Cybersecurity Operations Analyst (Threat Hunter)

Job Title

Lead Cybersecurity Operations Analyst

Role Summary:

The Threat Hunter is tasked with the proactive identification, investigation, and mitigation of advanced cyber threats within PGC enterprise environments. The candidate will utilize threat intelligence, hypothesis-driven hunting, behavior analytics, and advanced detection techniques to uncover malicious activities not addressed by traditional security controls.

Key Responsibilities:

  • Conduct proactive threat hunting across endpoints, network, cloud, identity, and email environments.
  • Develop and implement threat hunting hypotheses based on emerging threats and adversary tactics, techniques, and procedures.
  • Analyze security telemetry using platforms such as SIEM, EDR/XDR, Cloud Security, Data Security, EASM, email security gateways, Threat Intelligence, Dark Web monitoring, identity management, SOAR, Case Management, and various log sources.
  • Investigating Indicators of Compromise and Indicators of Attack.
  • Align threat hunting and investigation findings with the MITRE ATT&CK framework.
  • Create and refine threat detection rules, use cases, and behavioral analytics based on threat hunting outcomes and investigations to enhance security monitoring coverage.
  • Conduct digital forensic and incident analysis to determine the scope and impact of attacks.
  • Produce technical reports and executive summaries detailing threat hunting activities.
  • Perform triage, investigation, and response to security incidents.
  • Development of SOAR playbooks.

Required Skills/Qualifications:

  • Comprehensive understanding of cyber-attack lifecycles and adversary behavior.
  • Expertise in the MITRE ATT&CK framework.
  • Experience with SIEM and SOAR platforms, such as CrowdStrike Falcon Next-Gen SIEM and Palo Alto Network Cortex XSOAR.
  • Hands-on experience with EDR/XDR solutions, including Microsoft Defender and CrowdStrike Falcon.
  • In-depth knowledge of Windows, Linux, Active Directory/Entra ID, Azure Cloud Platform, and networking protocols (DNS, HTTP(s), SMTP, LDAP, TCP/IP).
  • Proficiency in Kusto Query Language (KQL), SQL, and scripting languages such as Python and PowerShell.
  • Understanding of malware analysis and digital forensics.
  • Strong analytical, communication, and documentation skills.

Preferred Qualifications:

  • Over 9 years of experience in cybersecurity, with at least 6 years in threat hunting.
  • Relevant certifications such as GIAC Certified Threat Hunter (GCTI/GCTH), GIAC Certified Forensic Analyst (GCFA/GNFA), MITRE ATT&CK Defender (MAD – All modules), GAIC GCTI, or equivalent certifications.

Similar roles