Associate, Threat Intelligence
HybridBengaluru, Karnataka, India
Job Summary
Identify, collect, and analyze cyber threat intelligence from open, deep, and dark web sources while conducting targeted investigations into data leaks, fraud, and threat actor activity. Provide direct support to incident response efforts through threat research, indicator enrichment, and rapid investigative analysis. Produce clear, concise, and actionable intelligence reports for technical and non-technical stakeholders. Assist with incident detection, vulnerability assessments, and digital footprint monitoring to identify emerging risks. Participate in client communications, including status updates and investigative briefings, under guidance from engagement leads. Manage multiple concurrent tasks in a consulting model while collaborating with CTI peers and incident responders to ensure successful client outcomes. This role supports international engagements with flexible hours overlapping US or EMEA time zones, located in Bangalore, India, in a hybrid arrangement.
Required Qualifications
- Willingness to support global clients, which may occasionally require flexible working hours overlapping with US or EMEA time zones.
- Strong sense of ownership, professionalism, and commitment to client satisfaction.
- Continuous learning mindset in a fast‐evolving threat landscape.
- Demonstrated experience analyzing threats across the open web, deep web, and dark web.
- Prior exposure to incident response support, security operations, or threat detection activities.
- Working knowledge of vulnerability assessments, exposure management, and digital footprint monitoring.
- Strong analytical, investigative, and critical‐thinking skills.
- Excellent written and verbal English communication skills.
- Ability to work independently and as part of a distributed, global team.
- 1–3+ years of experience in cyber threat intelligence, security research, SOC, or cyber investigations.
- Experience working in consulting, intelligence, MDR, or managed security services environment.
- Familiarity with OSINT, CTI, and investigative tools (e.g., dark web forums, marketplaces, breach data sources).
- Understanding of cybercrime ecosystems, threat actor TTPs, ransomware, fraud, or data‐theft operations.
Desired Qualifications
- Relevant certifications (e.g., CEH, Security+, GCIA, GCTI, OSCP)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.