icims
Sr Manager Security Analytics & Operations Senior (Cyber Threat Intel Analyst)
Charles Schwab
Hyderabad, IND
Full-time
Senior · 7+ years experience
Onsite
Discovered Yesterday
MITRE ATT&CKGoogle SecOpsSplunkMicrosoft SentinelQRadarCrowdStrike Falcon
Free
Job Fit Check
Base Career helps you apply smarter for this job.
?%
Ready to ScanKey skills for this role
MITRE ATT&CKGoogle SecOpsSplunk
Key Skills for This Role
MITRE ATT&CKGoogle SecOpsSplunkMicrosoft SentinelQRadarCrowdStrike Falcon
Full Job Posting
Key Responsibilities
- Cyber Threat Intelligence Collect, analyze, and disseminate actionable cyber threat intelligence from commercial, open-source, government, and industry intelligence feeds. Monitor threat actor activity, malware campaigns, ransomware operations, vulnerabilities, and geopolitical events that may impact the organization. Produce strategic, operational, and tactical intelligence reports for technical and executive audiences. Maintain awareness of adversary tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework. Identify indicators of compromise (IOCs), indicators of attack (IOAs), and behavioral analytics to improve detection capabilities. Develop intelligence requirements and prioritize collection efforts based on organizational risk. Perform attribution analysis on threat actors and campaigns where appropriate. Maintain threat profiles, intelligence repositories, and knowledge bases.
- Threat Hunting Conduct proactive threat hunting across enterprise networks, cloud environments, endpoints, and identity platforms. Develop and execute hypothesis-driven threat hunts based on intelligence reporting and adversary behaviors. Identify previously undetected malicious activity using endpoint, network, identity, cloud, and log data. Create new detection logic and use cases for SIEM, EDR, NDR, and cloud security platforms. Validate detection coverage against MITRE ATT&CK techniques. Collaborate with Incident Response teams during investigations and major security incidents. Recommend improvements to detection engineering and monitoring capabilities based on hunt findings.
- Digital Risk Protection Monitor external digital assets for potential security risks affecting the organization's brand and reputation. Identify phishing domains, typosquatting, brand impersonation, executive impersonation, and fraudulent websites. Monitor dark web marketplaces, underground forums, messaging platforms, and criminal communities for emerging threats targeting the organization. Identify exposed credentials, data leaks, compromised accounts, and unauthorized disclosures. Coordinate takedown efforts for malicious domains, phishing campaigns, and fraudulent content. Monitor social media and public platforms for cyber threats, disinformation campaigns, and brand abuse. Assess third-party and supply chain cyber risks through external intelligence.
- Collaboration Partner with SOC analysts to improve detection and response capabilities. Support Incident Response with intelligence during active investigations. Collaborate with Vulnerability Management to prioritize remediation based on active exploitation. Work with Attack Surface Management teams to identify externally exposed assets and emerging risks. Brief leadership on emerging cyber threats and organizational risk. Participate in tabletop exercises and incident simulations.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Intelligence Studies, or related field (or equivalent experience).
- 7+ years of experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related cybersecurity disciplines.
- Experience analyzing sophisticated cyber adversaries including nation-state, ransomware, financially motivated, and insider threats.
- Strong understanding of the cyber kill chain and MITRE ATT&CK framework.
- Experience with SIEM platforms such as Google SecOps, Splunk, Microsoft Sentinel, or QRadar.
- Experience with EDR/XDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or VMware Carbon Black.
- Experience working with threat intelligence platforms (TIPs).
- Experience analyzing malware, phishing campaigns, vulnerabilities, and indicators of compromise.
- Familiarity with cloud security across Microsoft Azure, AWS, and Google Cloud Platform.
Preferred Qualifications
- Experience with Threat Intelligence Platforms (TIPs) such as Recorded Future, ThreatConnect, MISP, Anomali, or EclecticIQ.
- Experience with Digital Risk Protection platforms.
- Experience monitoring the dark web and cybercriminal communities.
- Experience with SOAR automation platforms.
- Familiarity with Attack Surface Management technologies.
- Knowledge of intelligence lifecycle methodologies.
- Experience supporting regulated industries such as financial services, healthcare, or government
About Charles Schwab
Banking33700 employeesFounded 1971
Financial services firm providing brokerage, banking, and advisory services.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Charles Schwab
Sr Specialist Security Analytics & Operations (Cyber Threat Intel Analyst)
Hyderabad, IND
SeniorFull-time
Discovered YesterdayView →
Sr Specialist - Security Analytics & Operations
Hyderabad, IND
SeniorFull-time
Discovered 2 days agoView →
Senior Manager, Software Development & Engineering Lead (PL)
Hyderabad, IND
SeniorFull-time
Discovered 2 days agoView →
Specialist - Security Analytics & Operations
Hyderabad, IND
Discovered TodayFull-time
Specialist - Security Analytics & Operations
Hyderabad, IND
Discovered TodayFull-time
Associate - Security Analytics & Operations
Hyderabad, IND
Discovered TodayFull-time
Sr Specialist Security Analytics & Operations (Cyber Threat Intel Analyst)
Hyderabad, IND
Discovered YesterdayFull-time
Investment Consultant - International, UK
London, GBR
Discovered 2 days agoFull-time
Specialist - Security Analytics & Operations
Hyderabad, IND
Discovered 2 days agoFull-time
Sr Specialist - Security Analytics & Operations
Hyderabad, IND
Discovered 2 days agoFull-time
Senior Manager, Software Development & Engineering Lead (PL)
Hyderabad, IND
Discovered 2 days agoFull-time