The Cyber Threat Intelligence Lead will play a crucial role in driving the organizations threat intelligence and vulnerability management initiatives. You will lead a small team (3- 4 members) within the Identify Service Line, responsible for collecting, analyzing, and operationalizing cyber threat intelligence to strengthen the companys global cybersecurity posture. You will work closely with both India- and France-based stakeholders to ensure the effective delivery of Cyber Threat Intelligence, Vulnerability Management, and Threat Hunting services.
Key Responsibilities :
Threat Intelligence & Analysis :
- Collect, analyze, and interpret intelligence from : Commercial Cyber Threat Intelligence (CTI) partners Open Source Intelligence (OSINT), MISP, Threat Intelligence Platforms (TIP), and sandbox environments Malware analysis and other threat data sources
- Identify and monitor threat actors, their tactics, techniques, and procedures (TTPs), and assess potential impacts on the organization.
- Perform proactive threat hunting based on Indicators of Compromise (IoCs) using tools such as EDR, SIEM, and SOAR.
- Coordinate with security operations teams to block IoCs in advance across various tools (EDR, Antivirus, Proxy, Email Protection, etc.).
- Track, assess, and communicate vulnerabilities related to the organizations software assets.
- Maintain and regularly update the software inventory within the Vulnerability Assessment scope.
- Collaborate with infrastructure and application teams to prioritize and remediate high-risk vulnerabilities.
- Analyze suspicious packages, files, or URLs using sandbox environments and malware analysis techniques.
- Provide concise technical reports and actionable recommendations based on analysis findings.
- Develop and deliver monthly KPI reports for all CTI, Vulnerability Management, and Threat Hunting activities.
- Present findings and intelligence summaries to management and relevant stakeholders.
- Lead and mentor the Cyber Threat Intelligence team in India.
- Ensure alignment and continuous communication with the Identify Service Line Manager in France.
- Promote process optimization, automation, and documentation within CTI operations.
Required Skills & Experience :
Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Kill Chain, Diamond Model, etc.)Hands-on experience with EDR, SIEM, SOAR, and Threat Intelligence Platforms (TIP)Proficiency in OSINT tools, MISP, and sandboxing / malware analysis solutionsFamiliarity with network security, endpoint protection, and incident responseKnowledge of vulnerability management tools and processes Scripting or automation experience (Python, PowerShell, etc.) is a plusStrong analytical and problem-solving mindsetExcellent written and verbal communication skillsAbility to lead a small technical team and collaborate across geographiesStrong attention to detail and a proactive approach to cybersecurityBachelors degree in Computer Science, Information Security, or related fieldCertifications such as GCTI, GCFA, GCIA, CEH, CISSP, or CompTIA Security+ are a plus(ref : hirist.tech)