Position:
Global Threat Intelligence Researcher
Company:
CloudSEK
Location:
India, Bengaluru
Employment type:
Not specified
Work Arrangement:
Not specified
Short Summary:
CloudSEK is seeking a highly motivated and analytical Threat Intelligence Researcher to join their Global Threat Intelligence Team, focusing on tracking global threat activity through various analytical methods.
Responsibilities:
- Conduct ransomware IAV (Initial Access Vector) mapping to understand infiltration patterns, affiliate ecosystems, and monetisation structures.
- Perform e-crime and underground forum research to identify, profile, and map threat actors (TAs), their infrastructure, tools, and tradecraft.
- Execute infrastructure hunting campaigns focusing on APT and e-crime C2 frameworks, leveraging passive DNS, TLS certificates, and web fingerprinting techniques.
- Develop and maintain cyber HUMINT sources, focusing on early warning, infiltration, and intelligence collection aligned with organisational goals.
- Correlate and analyse global threat campaigns across ransomware, APT, and access broker ecosystems to identify shared TTPs and infrastructure linkages.
- Apply analytical models such as MITRE ATT&CK, MITRE Engage, Diamond Model, and Cyber Kill Chain to develop structured threat intelligence outputs.
- Produce tactical, operational, and strategic intelligence reports with actionable recommendations for global stakeholders.
- Contribute to tooling, automation, and methodology development for IAV mapping, C2 identification, and infrastructure clustering.
Requirement:
- 3+ years of experience in threat intelligence, malware analysis, threat hunting, or digital investigations.
- Proven experience in tracking ransomware groups, access brokers, or APT campaigns through open-source, dark web, and technical telemetry.
- Deep understanding of MITRE ATT&CK, MITRE Engage, Diamond Model, and Cyber Kill Chain frameworks.
- Familiarity with C2 frameworks (e.g., Cobalt Strike, Mythic, Sliver, Quasar, etc.) and infrastructure hunting methodologies.
- Practical experience with IAV analysis, including exploitation of vulnerabilities, phishing, and social engineering vectors.
- Strong OSINT and technical investigation skills (Shodan, Censys, FOFA, Netlas, VirusTotal, Hybrid Analysis, etc.).
- Demonstrable contributions to the cybersecurity community (e.g., blogs, research, GitHub, conference talks, or technical content) is a must.
- Excellent written and verbal communication skills for both technical and executive audiences.
Benefits:
- Flexible working hours.
- Food, unlimited snacks and drinks available while at the office.
- Opportunities for team bonding through games, fun, and music.
- CloudSEK is an equal opportunity employer committed to building a diverse and inclusive workplace.