Job Title: Threat Hunting Lead
Location: Bangalore/Gurgaon
Department: MDR – Threat Hunter
Job Summary:
We are seeking an experienced Senior Threat Hunter to join our Managed Detection and Response team. This role is responsible for proactively identifying advanced threats that evade traditional security controls through intelligence-driven, hypothesis-based threat hunting.
The ideal candidate will leverage telemetry from endpoint, network, cloud, identity, and security platforms to uncover malicious activity, improve detection coverage, and strengthen overall security operations.
Key Responsibilities:
Lead Proactive Threat Hunting Activities
- Design and execute intelligence-driven and hypothesis-based threat hunts across endpoint, network, cloud, identity, and SaaS environments.
- Develop threat hunting hypotheses based on threat intelligence, incident response findings, emerging attacker trends, and MITRE ATT&CK techniques.
- Identify hidden threats, anomalous behaviors, indicators of compromise (IOCs), and indicators of attack (IOAs) that may bypass traditional security monitoring controls.
- Conduct both proactive and reactive threat hunts driven by current threat landscape developments and client-specific concerns.
Advanced Security Investigations
- Investigate suspicious activity and validate potential threats identified through threat hunting activities.
- Analyze attacker behavior, lateral movement, persistence mechanisms, credential theft, privilege escalation, and command-and-control activities.
- Correlate findings across endpoint, network, identity, cloud, and application telemetry sources.
- Support complex forensic and investigative activities when advanced threats are identified.
Detection Engineering & Security Improvement
- Identify visibility gaps and weaknesses in current monitoring and detection capabilities.
- Convert validated threat hunting findings into operational detections, analytics, correlation rules, dashboards, and use cases.
- Collaborate with SOC, MDR, Detection Engineering, and Incident Response teams to enhance detection coverage and reduce attacker dwell time.
- Measure and improve MITRE ATT&CK coverage across security monitoring capabilities.
Threat Intelligence Integration
- Leverage tactical, operational, and strategic threat intelligence to drive threat hunting activities.
- Monitor emerging threats, threat actor campaigns, vulnerabilities, and adversary tradecraft.
- Incorporate external intelligence and internal incident learnings into future hunting activities.
Reporting & Stakeholder Engagement
- Produce detailed technical reports and executive-level summaries of threat hunting outcomes.
- Present findings, recommendations, and threat intelligence insights to security teams, leadership, and clients.
- Develop and maintain threat hunting playbooks, methodologies, and operational documentation.
- Mentor junior analysts and contribute to the maturity of threat hunting capabilities.
Required Qualifications:
Experience
- 8+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Detection Engineering, Cyber Threat Intelligence, or related disciplines.
- Minimum 5+ years of dedicated threat hunting experience.
- Demonstrated experience conducting hypothesis-driven and intelligence-led threat hunts.
- Experience leveraging the MITRE ATT&CK framework to develop and execute threat hunts.
- Experience working within enterprise SOC, MDR, MSSP, consulting, or cyber defense environments.
Technical Expertise
- Hands-on experience with enterprise EDR/XDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or equivalent solutions.
- Strong experience with SIEM technologies such as Microsoft Sentinel, Splunk, Google SecOps, or equivalent platforms.
- Advanced proficiency in KQL, SPL, SQL, or other security analytics query languages.
- Ability to research in depth and derive outcomes
- Strong understanding of Windows, Linux and cloud attack techniques and security monitoring.
- Experience hunting across Azure, AWS, and/or Google Cloud environments.
- Experience developing scripts and automation using Python, PowerShell, Bash, or similar languages.
Preferred Qualifications:
- Incident Response Experience (Strongly Preferred)
- Candidates with significant Incident Response experience will be strongly preferred and prioritized.
- Preferred experience includes:
- Leading or supporting incident investigations involving ransomware, advanced persistent threats (APTs), insider threats, and credential compromise.
- Digital Forensics and Incident Response (DFIR) engagements.
- Malware analysis and adversary behavior analysis.
- Demonstrated exploit development experience, or any contributed to CVEs.
- Large Enterprise Threat Hunting Experience (Strongly Preferred)
- Candidates with experience conducting threat hunting activities within large and complex enterprise environments will receive priority consideration.
- Preferred experience includes:
- Threat hunting across environments containing 10,000+ endpoints, distributed networks, hybrid cloud environments, and complex identity ecosystems.
- Experience supporting large, highly regulated organizations, including:
- Financial Services
- Banking
- Insurance
- Capital Markets
- Healthcare
- Energy & Utilities
- Critical Infrastructure
- Government
- Experience analyzing large-scale telemetry datasets from SIEM, EDR/XDR, cloud, identity, network, and security monitoring platforms.
- Experience identifying sophisticated threats that evade traditional detection capabilities.
- Experience operating within mature SOC, MDR, MSSP, or Cyber Defense organizations.
- Experience assessing detection coverage, identifying visibility gaps, and improving enterprise monitoring effectiveness.
- Detection engineering and security content development.
- Threat Intelligence platforms such as Recorded Future, Mandiant Intelligence, Sixgill, or equivalent.
- Security orchestration and automation (SOAR).
- Client-facing consulting experience.
- Experience delivering threat hunting services within Managed Detection and Response (MDR) programs.
Additional Preferred Experience
Preferred Certifications:
- GIAC GCTI
- GCIH
- GCFA
- GCIA
- GMON
- CISSP
- Microsoft Security Certifications
- Azure Security Engineer Associate
- CrowdStrike Certified Falcon Hunter
Other advanced threat hunting, digital forensics, or incident response certifications.
What Success Looks Like:
- Identifies sophisticated threats before they become security incidents.
- Develops effective hunting hypotheses aligned to current threat landscape and organizational risk.
- Continuously improves detection coverage and visibility across enterprise environments.
- Provides expert investigative support during high-severity cyber incidents.
- Translates threat hunting outcomes into measurable security improvements.
- Acts as a trusted subject matter expert in Threat Hunting, Incident Response, and Cyber Defense Operations.
Priority consideration will be given to candidates who possess both advanced Threat Hunting and hands-on Incident Response experience within large-scale enterprise environments, particularly financial services and other highly regulated industries.
Job Title: Threat Hunting Lead
Location: Bangalore/Gurgaon
Department: MDR – Threat Hunter
Job Summary:
We are seeking an experienced Senior Threat Hunter to join our Managed Detection and Response team. This role is responsible for proactively identifying advanced threats that evade traditional security controls through intelligence-driven, hypothesis-based threat hunting.
The ideal candidate will leverage telemetry from endpoint, network, cloud, identity, and security platforms to uncover malicious activity, improve detection coverage, and strengthen overall security operations.
Key Responsibilities:
Lead Proactive Threat Hunting Activities
- Design and execute intelligence-driven and hypothesis-based threat hunts across endpoint, network, cloud, identity, and SaaS environments.
- Develop threat hunting hypotheses based on threat intelligence, incident response findings, emerging attacker trends, and MITRE ATT&CK techniques.
- Identify hidden threats, anomalous behaviors, indicators of compromise (IOCs), and indicators of attack (IOAs) that may bypass traditional security monitoring controls.
- Conduct both proactive and reactive threat hunts driven by current threat landscape developments and client-specific concerns.
Advanced Security Investigations
- Investigate suspicious activity and validate potential threats identified through threat hunting activities.
- Analyze attacker behavior, lateral movement, persistence mechanisms, credential theft, privilege escalation, and command-and-control activities.
- Correlate findings across endpoint, network, identity, cloud, and application telemetry sources.
- Support complex forensic and investigative activities when advanced threats are identified.
Detection Engineering & Security Improvement
- Identify visibility gaps and weaknesses in current monitoring and detection capabilities.
- Convert validated threat hunting findings into operational detections, analytics, correlation rules, dashboards, and use cases.
- Collaborate with SOC, MDR, Detection Engineering, and Incident Response teams to enhance detection coverage and reduce attacker dwell time.
- Measure and improve MITRE ATT&CK coverage across security monitoring capabilities.
Threat Intelligence Integration
- Leverage tactical, operational, and strategic threat intelligence to drive threat hunting activities.
- Monitor emerging threats, threat actor campaigns, vulnerabilities, and adversary tradecraft.
- Incorporate external intelligence and internal incident learnings into future hunting activities.
Reporting & Stakeholder Engagement
- Produce detailed technical reports and executive-level summaries of threat hunting outcomes.
- Present findings, recommendations, and threat intelligence insights to security teams, leadership, and clients.
- Develop and maintain threat hunting playbooks, methodologies, and operational documentation.
- Mentor junior analysts and contribute to the maturity of threat hunting capabilities.
Required Qualifications:
Experience
- 8+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Detection Engineering, Cyber Threat Intelligence, or related disciplines.
- Minimum 5+ years of dedicated threat hunting experience.
- Demonstrated experience conducting hypothesis-driven and intelligence-led threat hunts.
- Experience leveraging the MITRE ATT&CK framework to develop and execute threat hunts.
- Experience working within enterprise SOC, MDR, MSSP, consulting, or cyber defense environments.
Technical Expertise
- Hands-on experience with enterprise EDR/XDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or equivalent solutions.
- Strong experience with SIEM technologies such as Microsoft Sentinel, Splunk, Google SecOps, or equivalent platforms.
- Advanced proficiency in KQL, SPL, SQL, or other security analytics query languages.
- Ability to research in depth and derive outcomes
- Strong understanding of Windows, Linux and cloud attack techniques and security monitoring.
- Experience hunting across Azure, AWS, and/or Google Cloud environments.
- Experience developing scripts and automation using Python, PowerShell, Bash, or similar languages.
Preferred Qualifications:
- Incident Response Experience (Strongly Preferred)
- Candidates with significant Incident Response experience will be strongly preferred and prioritized.
- Preferred experience includes:
- Leading or supporting incident investigations involving ransomware, advanced persistent threats (APTs), insider threats, and credential compromise.
- Digital Forensics and Incident Response (DFIR) engagements.
- Malware analysis and adversary behavior analysis.
- Demonstrated exploit development experience, or any contributed to CVEs.
- Large Enterprise Threat Hunting Experience (Strongly Preferred)
- Candidates with experience conducting threat hunting activities within large and complex enterprise environments will receive priority consideration.
- Preferred experience includes:
- Threat hunting across environments containing 10,000+ endpoints, distributed networks, hybrid cloud environments, and complex identity ecosystems.
- Experience supporting large, highly regulated organizations, including:
- Financial Services
- Banking
- Insurance
- Capital Markets
- Healthcare
- Energy & Utilities
- Critical Infrastructure
- Government
- Experience analyzing large-scale telemetry datasets from SIEM, EDR/XDR, cloud, identity, network, and security monitoring platforms.
- Experience identifying sophisticated threats that evade traditional detection capabilities.
- Experience operating within mature SOC, MDR, MSSP, or Cyber Defense organizations.
- Experience assessing detection coverage, identifying visibility gaps, and improving enterprise monitoring effectiveness.
- Detection engineering and security content development.
- Threat Intelligence platforms such as Recorded Future, Mandiant Intelligence, Sixgill, or equivalent.
- Security orchestration and automation (SOAR).
- Client-facing consulting experience.
- Experience delivering threat hunting services within Managed Detection and Response (MDR) programs.
Additional Preferred Experience
Preferred Certifications:
- GIAC GCTI
- GCIH
- GCFA
- GCIA
- GMON
- CISSP
- Microsoft Security Certifications
- Azure Security Engineer Associate
- CrowdStrike Certified Falcon Hunter
Other advanced threat hunting, digital forensics, or incident response certifications.
What Success Looks Like:
- Identifies sophisticated threats before they become security incidents.
- Develops effective hunting hypotheses aligned to current threat landscape and organizational risk.
- Continuously improves detection coverage and visibility across enterprise environments.
- Provides expert investigative support during high-severity cyber incidents.
- Translates threat hunting outcomes into measurable security improvements.
- Acts as a trusted subject matter expert in Threat Hunting, Incident Response, and Cyber Defense Operations.
Priority consideration will be given to candidates who possess both advanced Threat Hunting and hands-on Incident Response experience within large-scale enterprise environments, particularly financial services and other highly regulated industries.
Job Title: Threat Hunting Lead
Location: Bangalore/Gurgaon
Department: MDR – Threat Hunter
Job Summary:
We are seeking an experienced Senior Threat Hunter to join our Managed Detection and Response team. This role is responsible for proactively identifying advanced threats that evade traditional security controls through intelligence-driven, hypothesis-based threat hunting.
The ideal candidate will leverage telemetry from endpoint, network, cloud, identity, and security platforms to uncover malicious activity, improve detection coverage, and strengthen overall security operations.
Key Responsibilities:
Lead Proactive Threat Hunting Activities
- Design and execute intelligence-driven and hypothesis-based threat hunts across endpoint, network, cloud, identity, and SaaS environments.
- Develop threat hunting hypotheses based on threat intelligence, incident response findings, emerging attacker trends, and MITRE ATT&CK techniques.
- Identify hidden threats, anomalous behaviors, indicators of compromise (IOCs), and indicators of attack (IOAs) that may bypass traditional security monitoring controls.
- Conduct both proactive and reactive threat hunts driven by current threat landscape developments and client-specific concerns.
Advanced Security Investigations
- Investigate suspicious activity and validate potential threats identified through threat hunting activities.
- Analyze attacker behavior, lateral movement, persistence mechanisms, credential theft, privilege escalation, and command-and-control activities.
- Correlate findings across endpoint, network, identity, cloud, and application telemetry sources.
- Support complex forensic and investigative activities when advanced threats are identified.
Detection Engineering & Security Improvement
- Identify visibility gaps and weaknesses in current monitoring and detection capabilities.
- Convert validated threat hunting findings into operational detections, analytics, correlation rules, dashboards, and use cases.
- Collaborate with SOC, MDR, Detection Engineering, and Incident Response teams to enhance detection coverage and reduce attacker dwell time.
- Measure and improve MITRE ATT&CK coverage across security monitoring capabilities.
Threat Intelligence Integration
- Leverage tactical, operational, and strategic threat intelligence to drive threat hunting activities.
- Monitor emerging threats, threat actor campaigns, vulnerabilities, and adversary tradecraft.
- Incorporate external intelligence and internal incident learnings into future hunting activities.
Reporting & Stakeholder Engagement
- Produce detailed technical reports and executive-level summaries of threat hunting outcomes.
- Present findings, recommendations, and threat intelligence insights to security teams, leadership, and clients.
- Develop and maintain threat hunting playbooks, methodologies, and operational documentation.
- Mentor junior analysts and contribute to the maturity of threat hunting capabilities.
Required Qualifications:
Experience
- 8+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Detection Engineering, Cyber Threat Intelligence, or related disciplines.
- Minimum 5+ years of dedicated threat hunting experience.
- Demonstrated experience conducting hypothesis-driven and intelligence-led threat hunts.
- Experience leveraging the MITRE ATT&CK framework to develop and execute threat hunts.
- Experience working within enterprise SOC, MDR, MSSP, consulting, or cyber defense environments.
Technical Expertise
- Hands-on experience with enterprise EDR/XDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or equivalent solutions.
- Strong experience with SIEM technologies such as Microsoft Sentinel, Splunk, Google SecOps, or equivalent platforms.
- Advanced proficiency in KQL, SPL, SQL, or other security analytics query languages.
- Ability to research in depth and derive outcomes
- Strong understanding of Windows, Linux and cloud attack techniques and security monitoring.
- Experience hunting across Azure, AWS, and/or Google Cloud environments.
- Experience developing scripts and automation using Python, PowerShell, Bash, or similar languages.
Preferred Qualifications:
- Incident Response Experience (Strongly Preferred)
- Candidates with significant Incident Response experience will be strongly preferred and prioritized.
- Preferred experience includes:
- Leading or supporting incident investigations involving ransomware, advanced persistent threats (APTs), insider threats, and credential compromise.
- Digital Forensics and Incident Response (DFIR) engagements.
- Malware analysis and adversary behavior analysis.
- Demonstrated exploit development experience, or any contributed to CVEs.
- Large Enterprise Threat Hunting Experience (Strongly Preferred)
- Candidates with experience conducting threat hunting activities within large and complex enterprise environments will receive priority consideration.
- Preferred experience includes:
- Threat hunting across environments containing 10,000+ endpoints, distributed networks, hybrid cloud environments, and complex identity ecosystems.
- Experience supporting large, highly regulated organizations, including:
- Financial Services
- Banking
- Insurance
- Capital Markets
- Healthcare
- Energy & Utilities
- Critical Infrastructure
- Government
- Experience analyzing large-scale telemetry datasets from SIEM, EDR/XDR, cloud, identity, network, and security monitoring platforms.
- Experience identifying sophisticated threats that evade traditional detection capabilities.
- Experience operating within mature SOC, MDR, MSSP, or Cyber Defense organizations.
- Experience assessing detection coverage, identifying visibility gaps, and improving enterprise monitoring effectiveness.
- Detection engineering and security content development.
- Threat Intelligence platforms such as Recorded Future, Mandiant Intelligence, Sixgill, or equivalent.
- Security orchestration and automation (SOAR).
- Client-facing consulting experience.
- Experience delivering threat hunting services within Managed Detection and Response (MDR) programs.
Additional Preferred Experience
Preferred Certifications:
- GIAC GCTI
- GCIH
- GCFA
- GCIA
- GMON
- CISSP
- Microsoft Security Certifications
- Azure Security Engineer Associate
- CrowdStrike Certified Falcon Hunter
Other advanced threat hunting, digital forensics, or incident response certifications.
What Success Looks Like:
- Identifies sophisticated threats before they become security incidents.
- Develops effective hunting hypotheses aligned to current threat landscape and organizational risk.
- Continuously improves detection coverage and visibility across enterprise environments.
- Provides expert investigative support during high-severity cyber incidents.
- Translates threat hunting outcomes into measurable security improvements.
- Acts as a trusted subject matter expert in Threat Hunting, Incident Response, and Cyber Defense Operations.
Priority consideration will be given to candidates who possess both advanced Threat Hunting and hands-on Incident Response experience within large-scale enterprise environments, particularly financial services and other highly regulated industries.