Talent.com
Threat Detection Engineer
Threat Detection EngineerArete • Hyderabad, Republic Of India, IN
Threat Detection Engineer

Threat Detection Engineer

Arete • Hyderabad, Republic Of India, IN
8 hours ago
Job description

SUMMARY

The Threat Researcher is a self-starting and motivated analyst on Arete’s Cyber Threat Research team, primarily focused on countermeasure development, threat hunting and profiling, malware analysis, cyber threat research, and tracking known adversaries and emerging threats. The position contributes to the research and publication of threat insights, internal work products, as well as intelligence products to be used by Arete’s customers and stakeholders. A successful threat research and detection engineer thrives on learning the technical aspects of the tactics, techniques, and procedures leveraged by threat actors and finding solutions to challenging problems. You will play a critical role in developing and maintaining high-fidelity detections contributing to Arete’s MSS and DFIR services and collaborating with cross-functional teams to stay ahead of emerging threats. Work may occasionally include after-hours support.

ROLES & RESPONSIBILITIES

  • Develop countermeasures, tools, and methods of detection used for threat hunting and incident response activities to detect, respond, and remediate cyber threats
  • Performs threat hunting in Endpoint Detection & Response (EDR) telemetry data
  • Conduct analysis of malware, threat actor Tactics, Techniques, and Procedures (TTPs), and attack chains to inform detection strategies
  • Identifies cyber threats, trends, and new malware families and threat actor groups, researching various sources that include Arete’s case reports, DFIR & MDR SOC escalations, automated malware analysis sandbox submissions, raw and open-source intelligence
  • Collaborate with Threat Intelligence, DFIR, MDR, and SOC teams to ensure detection coverage aligns with real-world threats
  • Create compelling internal reports and presentations from analysis results
  • Inform various business units within Arete about new threat actor TTPs
  • Uncover adversary activity not detected by current detection mechanisms
  • Identify intelligence and technology gaps
  • Contribute to the development and enhancement of threat detection tools, technologies, and processes to improve automation, data analysis, intelligence sharing, and service offerings
  • Conduct stakeholder briefings to communicate relevant findings
  • Provide tactical research and analysis support for MDR, DFIR, and SOC business units
  • Assist with creating detailed process documentation of analysis workflows to help maintain and update our Standard Operating Procedures for continuous process improvement
  • Participate in weekend handler-on-duty rotations
  • May perform other duties as assigned by management

SKILLS AND KNOWLEDGE

  • Motivated self-starter with a passion for EDR countermeasure development, detection engineering, malware analysis, threat profiling, and cyber threat research
  • Knowledge of Endpoint Detection and Response technology, threat hunting, automated malware analysis sandbox systems, and countermeasure development (e.G., SentinelOne, CrowdStrike, Microsoft KQL)
  • Knowledge of various tools and techniques used by cybercrime threat actors, and desire to extend knowledge of threat actor TTPs
  • Ability to analyze, or use an automated malware analysis system, and identify key indicators of malicious activity for various file types such as Portable executables, Visual Basic scripts, Java scripts, Powershell scripts, Malicious documents, Webshells, and Shellcode
  • Knowledge of obfuscation algorithms and de-obfuscating data
  • Ability to produce high-quality finished work products within short deadlines
  • Ability to work remotely under a minimal supervision environment maintaining high quality analytical production and excellent relationship with stakeholders
  • Ability to manage relationships with stakeholders
  • Adaptable and willing to learn new technologies
  • JOB REQUIREMENTS

  • Bachelor’s degree with a minimum of 5 years of experience related to the job role or Master’s degree in Cybersecurity, Engineering, Computer Science, Information Assurance, or related field with a minimum of 3 years of experience related to the job role
  • Experience writing EDR countermeasures, Yara rules, and Regular Expressions
  • Experience with malware analysis and threat profiling, preferably cybercrime threats like ransomware and ransomware precursors
  • Experience with network traffic, memory, and log analysis
  • Experience with automated malware analysis systems and identifying key indicators of compromise
  • Excellent written and verbal communication skills, with the ability to present technical information to both technical and non-technical stakeholders
  • Ability to work in a fast-paced environment with MDR and DFIR analysts
  • Ability to follow guidance to take non-traditional and creative approaches to solving problems and having the ability to quickly adapt as needed
  • DISCLAIMER

    The above statements are intended to describe the general nature and level of work being performed. They are not intended to be an exhaustive list of all responsibilities, duties, and skills required by personnel so classified.

    WORK ENVIRONMENT

    While performing the responsibilities of this position, the work environment characteristics listed below are representative of the environment the employee will encounter : Usual office working conditions. Reasonable accommodations may be made to enable people with disabilities to perform the essential functions of this job.

    TERMS OF EMPLOYMENT

    Salary and benefits shall be paid consistent with Arete salary and benefit policy.

    DECLARATION

    The Arete Incident Response Human Resources Department retains the sole right and discretion to make changes to this job description.

    EQUAL EMPLOYMENT OPPORTUNITY

    We’re proud to be an equal opportunity employer- and celebrate our employees’ differences, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or Veteran status. Different makes us better.

    Create a job alert for this search

    Engineer Threat Detection • Hyderabad, Republic Of India, IN

    Related jobs
    Lead Security Engineer

    Lead Security Engineer

    interface.ai • Hyderabad, IN
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show more
    Last updated: 30+ days ago • Promoted
    Threat Hunting Specialist

    Threat Hunting Specialist

    Tata Consultancy Services • Hyderabad, Telangana, India
    Role • • : Threat Modelling / Hunting.Location : Hyderabad, Bangalore, Chennai.Date of Interview : 22nd November 2025.Mode of Interview : In Person(F2F). The ideal candidate will be responsible for identify...Show more
    Last updated: 8 days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Photon • hyderabad, telangana, in
    Application Security Engineer (Senior Officer).Reporting to the Global Head of Security, the Application Security Engineer plays a crucial role in leading our Application Security program, ensuring...Show more
    Last updated: 4 hours ago • Promoted • New!
    Threat Researcher

    Threat Researcher

    APTITA SERVICES PRIVATE LIMITED • Hyderabad
    Job Title : Threat Researcher Location : Hyderabad / Remote Experience Required : 5+ years of relevant expe...Show more
    Last updated: 16 hours ago • Promoted • New!
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    OSI Systems Pvt. Ltd. • Hyderabad
    Description : OSI Systems, Inc.We sell our products and provide related services in diversified markets, including homeland security, healthcare, defense, and...Show more
    Last updated: 30+ days ago • Promoted
    Associate Vice President - Senior Lead Security Detection Engineer [T500-21564]

    Associate Vice President - Senior Lead Security Detection Engineer [T500-21564]

    Deutsche Börse • Hyderabad, Telangana, India
    Headquartered in Frankfurt, Germany, Deutsche Börse Group is a leading international exchange organization and market infrastructure provider. They empower investors, financial institutions, and com...Show more
    Last updated: 1 day ago • Promoted
    Senior Security Engineer, Application Security

    Senior Security Engineer, Application Security

    Photon • Hyderabad, Republic Of India, IN
    Application Security Engineer (Senior Officer).Reporting to the Global Head of Security, the Application Security Engineer plays a crucial role in leading our Application Security program, ensuring...Show more
    Last updated: 8 hours ago • Promoted • New!
    Arete - Threat Researcher

    Arete - Threat Researcher

    ARETE-IR LLP • Hyderabad
    Description : SUMMARY : The Threat Researcher is a self-starting and motivated analyst on Aretes Cyber Threat Research...Show more
    Last updated: 16 hours ago • Promoted • New!
    Qualcomm Technologies - Cyber Security Engineer / Lead - Threat Modeling

    Qualcomm Technologies - Cyber Security Engineer / Lead - Threat Modeling

    Qualcomm • Hyderabad
    Description : Position : Cyber Security Engineer, Lead Exp : 5 to 8 Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Arcana • Hyderabad, IN
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show more
    Last updated: 30+ days ago • Promoted
    Medtronic - Senior Product Security Engineer - Vulnerability Assessment

    Medtronic - Senior Product Security Engineer - Vulnerability Assessment

    Medtronic (Medtronic)(279) • Hyderabad
    Description : At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all.Youll lead with...Show more
    Last updated: 8 days ago • Promoted
    Tungsten Automation - Cyber Security Engineer - Threat Hunting

    Tungsten Automation - Cyber Security Engineer - Threat Hunting

    TUNGSTEN DEVELOPMENT PRIVATE LIMITED • Hyderabad
    Job Purpose : This role reports will assist in incident response, threat hunting, and forensics.The ideal candidate will have a well-rounded background in endpoint, OS, networ...Show more
    Last updated: 30+ days ago • Promoted
    Endpoint Security Engineer

    Endpoint Security Engineer

    Tata Consultancy Services • Hyderabad, Telangana, India
    TCS has been a great pioneer in feeding the fire of Young Techies like you.We are a global leader in the technology arena and there's nothing that can stop us from growing together.Role • • : Endpoint...Show more
    Last updated: 21 days ago • Promoted
    Security Engineer - OSCP Certified

    Security Engineer - OSCP Certified

    Hashira • Hyderabad, Telangana, India
    Hashira is an R&D studio focused on solving complex infrastructure challenges in blockchain and AI.Our work supports projects like Ren, KeeperDAO (Rook), Catalog, and Garden, which have collectivel...Show more
    Last updated: 19 days ago • Promoted
    Threat Researcher

    Threat Researcher

    Arete • Hyderabad, Telangana, India
    The Threat Researcher is a self-starting and motivated analyst on Arete’s Cyber Threat Research team, primarily focused on countermeasure development, threat hunting and profiling, malware analysis...Show more
    Last updated: 6 hours ago • Promoted • New!
    Senior Security Engineer - SIEM, DevSecOps, IPS / IDS

    Senior Security Engineer - SIEM, DevSecOps, IPS / IDS

    Emburse • Hyderabad, Telangana, India
    Emburse software engineers contribute to the development of an engaging and interconnected set of system solutions.As an engineer, you will enhance the experiences of your customers, solve interest...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer T500-20922

    Senior Security Engineer T500-20922

    Deutsche Börse Group • Hyderabad, Republic Of India, IN
    Headquartered in Frankfurt, Germany, Deutsche Börse Group is a leading international exchange organization and market infrastructure provider. They empower investors, financial institutions, and com...Show more
    Last updated: 13 days ago • Promoted
    Medtronic - Product Security Engineer II - Vulnerability Assessment

    Medtronic - Product Security Engineer II - Vulnerability Assessment

    Medtronic (Medtronic)(279) • Hyderabad
    Description : At Medtronic you can begin a life-long career of exploration and innovation, while helping champion health...Show more
    Last updated: 20 days ago • Promoted