Lead Cybersecurity Operations Analyst
Providence Hyderabad, Telangana, India
Hospitals and Health Care · 1,001-5,000 employees
About the role
The Lead Cybersecurity Operations Analyst is responsible for proactive threat hunting across enterprise environments using advanced detection techniques and threat intelligence. They will also conduct digital forensic investigations, develop SOAR playbooks, and refine security detection rules to mitigate advanced cyber threats.
What they look for
Requirements
Candidates must have over 9 years of cybersecurity experience, with at least 6 years specifically in threat hunting. Proficiency in SIEM/SOAR platforms, EDR/XDR solutions, and scripting languages like Python or PowerShell is required, along with expertise in the MITRE ATT&CK framework.
Full description
Job Description – Lead Cybersecurity Operations Analyst (Threat Hunter)
Job Title
Lead Cybersecurity Operations Analyst
Role Summary:
The Threat Hunter is tasked with the proactive identification, investigation, and mitigation of advanced cyber threats within PGC enterprise environments. The candidate will utilize threat intelligence, hypothesis-driven hunting, behavior analytics, and advanced detection techniques to uncover malicious activities not addressed by traditional security controls.
Key Responsibilities:
- Conduct proactive threat hunting across endpoints, network, cloud, identity, and email environments.
- Develop and implement threat hunting hypotheses based on emerging threats and adversary tactics, techniques, and procedures.
- Analyze security telemetry using platforms such as SIEM, EDR/XDR, Cloud Security, Data Security, EASM, email security gateways, Threat Intelligence, Dark Web monitoring, identity management, SOAR, Case Management, and various log sources.
- Investigating Indicators of Compromise and Indicators of Attack.
- Align threat hunting and investigation findings with the MITRE ATT&CK framework.
- Create and refine threat detection rules, use cases, and behavioral analytics based on threat hunting outcomes and investigations to enhance security monitoring coverage.
- Conduct digital forensic and incident analysis to determine the scope and impact of attacks.
- Produce technical reports and executive summaries detailing threat hunting activities.
- Perform triage, investigation, and response to security incidents.
- Development of SOAR playbooks.
Required Skills/Qualifications:
- Comprehensive understanding of cyber-attack lifecycles and adversary behavior.
- Expertise in the MITRE ATT&CK framework.
- Experience with SIEM and SOAR platforms, such as CrowdStrike Falcon Next-Gen SIEM and Palo Alto Network Cortex XSOAR.
- Hands-on experience with EDR/XDR solutions, including Microsoft Defender and CrowdStrike Falcon.
- In-depth knowledge of Windows, Linux, Active Directory/Entra ID, Azure Cloud Platform, and networking protocols (DNS, HTTP(s), SMTP, LDAP, TCP/IP).
- Proficiency in Kusto Query Language (KQL), SQL, and scripting languages such as Python and PowerShell.
- Understanding of malware analysis and digital forensics.
- Strong analytical, communication, and documentation skills.
Preferred Qualifications:
- Over 9 years of experience in cybersecurity, with at least 6 years in threat hunting.
- Relevant certifications such as GIAC Certified Threat Hunter (GCTI/GCTH), GIAC Certified Forensic Analyst (GCFA/GNFA), MITRE ATT&CK Defender (MAD – All modules), GAIC GCTI, or equivalent certifications.
Similar roles
-
Senior Security Engineer (all genders)
Capmo Munich, Bavaria, Germany
-
Cybersecurity Analyst
Smiths Group Bengaluru, Karnataka, India
-
IT & IAM Security Engineer
Tomorro Paris, Ile-de-France, France · €40K–€45K/yr
-
Cybersecurity Ingenieur Medizintechnik (all gender)
ALTEN München, Brandenburg, Germany · €52K–€75K/yr
-
Cybersecurity Risk Manager (Warsaw, on-site) – Frontex
The White Team Capon Bridge, West Virginia, United States
-
IT Cybersecurity Auditor
Dixio Buenos Aires, Buenos Aires, Argentina