Key Responsibilities :
- Collect, analyze, and interpret threat intelligence from multiple sources (internal, external, OSINT)
- Perform proactive threat hunting to identify indicators of compromise (IOCs) and advanced persistent threats (APTs)
- Track and analyze adversary tactics, techniques, and procedures (TTPs) using frameworks like MITRE ATT&CK
- Develop and maintain threat models to identify vulnerabilities and potential attack vectors
- Correlate data from SIEM, EDR/XDR, and other security tools to detect and investigate threats
- Create and deliver actionable intelligence reports, dashboards, and briefings for technical and non-technical stakeholders
- Collaborate with SOC, incident response, and security engineering teams to enhance detection and response capabilities
- Support incident investigations by providing threat intelligence context and insights
- Automate threat intelligence processes using scripting (Python, PowerShell)
- Monitor global threat landscape, vulnerabilities, and emerging attack trends
- Contribute to improving organizational security posture through intelligence-driven recommendations
- Stay updated with latest trends in AI/ML and LLM-related security Skills :
- 5+ years of experience in cybersecurity with strong focus on Threat Intelligence
Hands-on experience in :
- Threat Intelligence Analysis
- Threat Hunting
- Adversary Behavior Tracking
Strong understanding of :
- MITRE ATT&CK Framework
- Threat Modeling Techniques
Experience with :
a. SIEM tools (Splunk, Microsoft Sentinel, etc.)
b. EDR/XDR solutions
c. Threat Intelligence Platforms and OSINT tools
- Strong analytical and problem-solving skills with ability to correlate multiple data sources
- Experience in preparing intelligence reports for varied stakeholders
Good to Have Skills :
- Experience in AI/ML or LLM security
- Knowledge of malware analysis or reverse engineering
- Scripting knowledge in Python or PowerShell
- Familiarity with automation of threat intelligence workflows
- Understanding of cloud security threats (AWS, Azure, GCP)
Certifications (Preferred) :
- GCTI (GIAC Cyber Threat Intelligence)
- GCIA (GIAC Certified Intrusion Analyst)
- CISSP (Certified Information Systems Security Professional)
- Other relevant cybersecurity certifications
(ref:hirist.tech)