Point your AI agent at freehire and let it find you a job.

Get the CLI →

Jobgether

NewBe an early applicant

Threat Analyst

Posted
Discussion

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Analyst based in India.

This role focuses on investigating and responding to sophisticated cyber threats across enterprise security environments. You will analyze alerts and incidents across endpoint, network, cloud, and identity systems to determine root cause, scope, and potential impact. The position combines hands-on investigation with threat hunting, malware analysis, and security data correlation. You will work closely with experienced analysts on complex and high-severity incidents while contributing to stronger detection and response capabilities. Your investigations will help provide clients with clear findings and actionable recommendations to strengthen their security posture. Working within a remote-first environment, you will support a 24x7x365 managed detection and response operation and gain exposure to real-world cyber threats.

Accountabilities:

  • Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments, using structured investigative methods to determine the nature and severity of threats.
  • Analyze incidents to establish root cause, attack scope, lateral movement, persistence mechanisms, credential abuse, and potential business impact.
  • Support ransomware investigations by examining attacker activity, malware behavior, persistence techniques, and compromised credentials.
  • Analyze and deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity and understand attacker behavior.
  • Conduct proactive threat hunts based on defined hypotheses, emerging intelligence, suspicious behaviors, and relevant adversary techniques.
  • Investigate suspicious authentication events, privilege escalation, privileged account misuse, and other forms of identity-based compromise.
  • Perform investigations across Windows and Linux environments, including operating-system logs, processes, authentication activity, and other forensic indicators.
  • Correlate information from multiple security sources, including EDR, SIEM, cloud logging, identity platforms, and network telemetry.
  • Analyze relevant network activity involving protocols and technologies such as TCP/IP, DNS, and HTTP/S to identify suspicious communications and attack patterns.
  • Document investigative findings clearly and provide actionable remediation guidance to support clients in containing threats and improving their security posture.
  • Collaborate with senior analysts on complex or high-severity investigations and contribute to the continuous improvement of investigative practices.
  • Support detection tuning and response playbook improvements based on lessons learned from investigations and emerging threat activity.
  • Participate in a rotational schedule supporting continuous 24x7x365 managed detection and response operations.
  • Requirements

    • 3–5 years of professional experience in a Security Operations Center, Managed Detection and Response, Incident Response, or related cybersecurity operations environment.
    • Hands-on experience investigating endpoint and network security alerts using EDR and SIEM platforms.
    • Working knowledge of ransomware attack patterns, common intrusion techniques, adversary behaviors, and practical application of the MITRE ATT&CK framework.
    • Experience investigating both Windows and Linux systems, including Windows Event Logs, Linux logs, processes, and Active Directory fundamentals.
    • Practical experience analyzing obfuscated scripts and malware behavior, with the ability to perform deobfuscation and identify malicious activity.
    • Basic understanding of cloud and identity security investigations, including suspicious authentication activity, privileged account misuse, and identity-based threats.
    • Ability to analyze network traffic and investigate activity involving TCP/IP, DNS, and HTTP/S.
    • Strong scripting capabilities, including PowerShell and Python or another comparable programming language.
    • Strong analytical, troubleshooting, and investigative skills, with careful attention to technical detail.
    • Ability to manage multiple investigations in a fast-paced environment while maintaining accuracy and clear documentation.
    • Strong written and verbal communication skills, with the ability to communicate technical findings and remediation recommendations clearly.
    • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience.
    • Security certifications such as Security+, CySA+, GCIH, or equivalent credentials are advantageous.
    • Willingness and ability to participate in a rotational schedule supporting a continuous 24x7x365 security operations environment.
    • Benefits

      • Remote-first working model, with remote work serving as the primary arrangement for most roles.
      • Opportunity to work on real-world cybersecurity investigations across endpoint, network, cloud, and identity environments.
      • Exposure to advanced threat detection, incident response, ransomware investigations, malware analysis, threat hunting, and security operations.
      • Close collaboration with experienced security professionals and opportunities to strengthen investigative expertise.
      • Opportunities to develop practical knowledge across EDR, SIEM, cloud security, identity security, MITRE ATT&CK, and security automation.
      • Professional development opportunities and continued learning within a cybersecurity-focused environment.
      • Employee-led diversity and inclusion networks that support community, education, and advocacy.
      • Employee volunteer days, charitable initiatives, and opportunities to contribute to local communities.
      • Global sustainability initiatives supporting environmental responsibility.
      • Employee wellbeing programs, including wellbeing days, webinars, and health-focused training.
      • Global fitness and trivia activities designed to support employee connection and wellbeing.
      • Inclusive working environment that values diverse perspectives and provides equal opportunities for professional growth.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available