Threat Analyst
Jobgether
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
155 open threat roles across 58 companies are on ApplySarthi right now, most of them in Bengaluru (5), Pune (1), Chennai (1).
- Threat Intelligence Consultant-Threat AnalysisIBM
- Senior Threat AdvisorSentinelOne
- Senior Insider Threat AnalystWorkday
- Cybersecurity Intelligence Senior Associate — Applied Cyber Threat Research (ACTR)JPMorgan
- Safety Threat Investigator, Safety InvestigationsRoblox
What threat roles keep asking for: Python (33%), SIEM (26%), SQL (14%) — counted across their open postings here.
Linux jobs · Python jobs · SIEM jobs
Jobgether has 3,838 open roles listed here.
- Analista de Gestão de Mudanças
- Analista de Governança e Transparência ESG III - Temporária
- Associate Product Manager, BMO Global Asset Management
- Bilingual Field technology Consultant
- Bilingual Vocational Rehabilitation Specialist
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for threat roles keep coming back to Python, SIEM, SQL. Practise those questions before you sit with Jobgether.
Questions you are likely to be asked
- Why do you want to join Jobgether?
- What is your experience with Linux? Tell me one thing you learned the hard way.
- Tell me about an analysis that changed a decision. What did you find?
- How do you check that your numbers are right before you share them?
- Walk me through a dashboard or report you built. Who used it, and for what?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Threat Analyst at Jobgether interview free →Accountabilities:: Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments, using structured investigative methods to determine the nature and severity of threats. Analyze incidents to establish root cause, attack scope, lateral movement, persistence mechanisms, credential abuse, and potential business impact. Support ransomware investigations by examining attacker activity, malware behavior, persistence techniques, and compromised credentials. Analyze and deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity and understand attacker behavior. Conduct proactive threat hunts based on defined hypotheses, emerging intelligence, suspicious behaviors, and relevant adversary techniques. Investigate suspicious authentication events, privilege escalation, privileged account misuse, and other forms of identity-based compromise. Perform investigations across Windows and Linux environments, including operating-system logs, processes, authentication activity, and other forensic indicators. Correlate information from multiple security sources, including EDR, SIEM, cloud logging, identity platforms, and network telemetry. Analyze relevant network activity involving protocols and technologies such as TCP/IP, DNS, and HTTP/S to identify suspicious communications and attack patterns. Document investigative findings clearly and provide actionable remediation guidance to support clients in containing threats and improving their security posture. Collaborate with senior analysts on complex or high-severity investigations and contribute to the continuous improvement of investigative practices. Support detection tuning and response playbook improvements based on lessons learned from investigations and emerging threat activity. Participate in a rotational schedule supporting continuous 24x7x365 managed detection and response operations. Requirements 3–5 years of professional experience in a Security Operations Center, Managed Detection and Response, Incident Response, or related cybersecurity operations environment. Hands-on experience investigating endpoint and network security alerts using EDR and SIEM platforms. Working knowledge of ransomware attack patterns, common intrusion techniques, adversary behaviors, and practical application of the MITRE ATT&CK framework. Experience investigating both Windows and Linux systems, including Windows Event Logs, Linux logs, processes, and Active Directory fundamentals. Practical experience analyzing obfuscated scripts and malware behavior, with the ability to perform deobfuscation and identify malicious activity. Basic understanding of cloud and identity security investigations, including suspicious authentication activity, privileged account misuse, and identity-based threats. Ability to analyze network traffic and investigate activity involving TCP/IP, DNS, and HTTP/S. Strong scripting capabilities, including PowerShell and Python or another comparable programming language. Strong analytical, troubleshooting, and investigative skills, with careful attention to technical detail. Ability to manage multiple investigations in a fast-paced environment while maintaining accuracy and clear documentation. Strong written and verbal communication skills, with the ability to communicate technical findings and remediation recommendations clearly. Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience. Security certifications such as Security+, CySA+, GCIH, or equivalent credentials are advantageous. Willingness and ability to participate in a rotational schedule supporting a continuous 24x7x365 security operations environment. Benefits Remote-first working model, with remote work serving as the primary arrangement for most roles. Opportunity to work on real-world cybersecurity investigations across endpoint, network, cloud, and identity environments. Exposure to advanced threat detection, incident response, ransomware investigations, malware analysis, threat hunting, and security operations. Close collaboration with experienced security professionals and opportunities to strengthen investigative expertise. Opportunities to develop practical knowledge across EDR, SIEM, cloud security, identity security, MITRE ATT&CK, and security automation. Professional development opportunities and continued learning within a cybersecurity-focused environment. Employee-led diversity and inclusion networks that support community, education, and advocacy. Employee volunteer days, charitable initiatives, and opportunities to contribute to local communities. Global sustainability initiatives supporting environmental responsibility. Employee wellbeing programs, including wellbeing days, webinars, and health-focused training. Global fitness and trivia activities designed to support employee connection and wellbeing. Inclusive working environment that values diverse perspectives and provides equal opportunities for professional growth.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- .Net Software DeveloperJobgether
- Account DirectorJobgether
- Account Director, Renewals & GrowthJobgether
- Advisor, BMO SmartFolio WFHJobgether
- Agentic AI DeveloperJobgether
- AI Graphic Designer + Video EditorJobgether
- AI/ML Data ScientistJobgether
- Analista de Automação e IA com N8NJobgether
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on lever · posted 2026-09-23. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.