Threat Analyst (MDR)

Jobgether· India· lever· publicerad 2026-07-24
Krav:PythonCloudAISecuritySeniorRemote

Accountabilities: The Threat Analyst (MDR) will be responsible for monitoring, investigating, and responding to cybersecurity incidents while supporting continuous improvement of security operations processes. The role requires strong analytical capabilities, technical expertise, and the ability to collaborate effectively with internal teams and customers.

Investigate and respond to security alerts, incidents, and potential cyber threats across enterprise environments.

Provide escalation support and guidance to junior threat analysts during complex investigations.

Perform security monitoring, log analysis, and threat investigation using enterprise security platforms.

Analyze endpoint and network security data to identify malicious activity and determine appropriate response actions.

Support threat detection, containment, and remediation activities to help neutralize security risks.

Create and maintain incident cases, documentation, reports, and customer communications throughout threat response activities.

Interact with customers through various communication channels to provide updates and support incident resolution.

Research emerging threats, vulnerabilities, exploits, and indicators of compromise to improve detection capabilities.

Contribute to security operations process improvements, documentation, and operational best practices.

Develop threat intelligence insights, security metrics, and trend analysis reports.

Support security and threat response teams with investigation assistance and technical expertise.

Participate in onboarding and training activities for new analysts.

Requirements:

The ideal candidate will have hands-on experience in security operations, threat detection, and incident response, with a strong understanding of enterprise security technologies and attacker techniques.

2–4 years of experience working in a Security Operations Center (SOC), cybersecurity team, or IT security environment.

Experience with endpoint and network security technologies, including IDS, IPS, EDR, ATP, malware protection, and monitoring solutions.

Strong understanding of incident response processes and cybersecurity investigation methodologies.

Knowledge of common adversary tactics and techniques, including persistence, obfuscation, and defense evasion methods.

Familiarity with the MITRE ATT&CK framework is preferred.

Experience with security information and event management (SIEM) platforms is a plus.

Strong knowledge of Windows operating systems, including workstation and server environments.

Experience with Linux or macOS operating systems is beneficial.

Understanding of network traffic analysis, including TCP/IP, routing, switching, and network protocols.

Strong ability to analyze Windows event logs and security data.

Experience with scripting or query languages such as KQL, PowerShell, or Python.

Knowledge of SQL query development and OSQuery is an advantage.

Excellent troubleshooting, analytical thinking, and problem-solving skills.

Strong written and verbal communication skills with the ability to document technical findings clearly.

Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or equivalent practical experience.

Advanced cybersecurity certifications are preferred but not mandatory.

Ability to work flexible schedules, including weekends and holidays, as part of a 24/7 security operations function.

Ability to work effectively both independently and as part of a collaborative team.

Benefits:

Remote-first working environment with flexibility for eligible roles.

Opportunity to work on advanced cybersecurity technologies and real-world threat investigations.

Exposure to global security operations and enterprise-level environments.

Continuous learning opportunities to develop cybersecurity and threat intelligence skills.

Employee wellbeing programs, including wellness initiatives and support resources.

Inclusive workplace culture focused on collaboration, innovation, and diverse perspectives.

Opportunities to participate in employee communities, sustainability initiatives, and company-led activities.

Career growth opportunities within a global cybersecurity organization.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1