Threat Hunter
Angel One · Bengaluru, Karnataka, India
Angel One · Bengaluru, Karnataka, India
**About Angel One:** Angel One is one of India’s fastest growing fin-techs, on a bold mission to make investing simple, smart, and inclusive for every Indian. With over 3+ crore clients, we’re building at scale – and building for impact. Our Super App helps clients manage their investments, trade seamlessly, and access financial tools tailored to their goals. We are working to build personalized financial journeys for our clients, powered by new-age tech, AI, Machine Learning and Data Science. We're a builder's company at heart. You’ll have the space to experiment, the freedom to move with velocity, and the mandate to make bold, user-first decisions – every single day. The vibe? Think less hierarchy, more momentum. Everyone has a seat at the table and a shot to build something that lasts. Be part of a team that’s scaling sustainably, thinking big, and building for the next billion. **Why You'll Love Working at Angel One!** - **Tech Systems that run at Scale:** From AI to real-time data infra, you’ll work on tech that’s ahead of the curve and solve problems that truly matter. - **Build one of India’s Leading Fintech Platform:** We’re not just disrupting finance – we’re shaping how billion Indians access wealth. - **Own It. Drive It. Scale It:** You’ll have the freedom to lead, the resources to build, and the opportunity to leave your mark. - **Empowered Growth:** We invest in your growth and empower you to explore your full potential. - **Exceptional Benefits:** Our comprehensive benefits package includes health insurance, wellness programs, learning & development opportunities, and more. **Role:** Data & AI Engineer (DE2) – Agentic Data Systems **Location:** Bangalore (Hybrid) Lead end-to-end threat hunting activities — hypothesis-driven, intelligence-driven, and anomaly-based — across enterprise, network, endpoint, and cloud environments. • Design and maintain a threat hunting program aligned to MITRE ATT&CK, NIST CSF/SP 800-53, PCI-DSS, RBI Cyber Security Framework, ISO/IEC 27001, and SANS/PEAK hunting methodologies. • Work hands-on within the SOC to triage, investigate, and hunt for advanced threats, APTs, insider threats, and BFSI-specific fraud/TTPs (e.g., banking trojans, SWIFT/payment fraud, credential theft). • Develop and refine hunting hypotheses using threat intelligence (CTI), MITRE ATT&CK TTP mapping, and IOC/IOA analysis. • Build and tune detection content, hunting queries, and analytics in SIEM/EDR/XDR/SOAR platforms; convert successful hunts into automated detections. • Perform threat hunting across cloud environments (AWS/Azure/GCP), including cloud-native logs, IAM misuse, container/K8s threats, and CSPM findings. • Correlate hunting findings with vulnerability management, red/purple team exercises, and incident response to strengthen detection coverage. • Mentor SOC analysts (L1/L2) in hunting techniques; lead knowledge-sharing sessions and build institutional hunting playbooks/runbooks. • Support regulatory and audit requirements specific to BFSI (RBI, SEBI, IRDAI guidelines) through documented hunting evidence and metrics. • Present hunting outcomes, threat trends, and risk insights to CISO/security leadership. **Who you are:** 7–10 years in cybersecurity, with at least 4–5 years in SOC operations and dedicated threat hunting. • Strong hands-on experience with SIEM (Splunk, QRadar, Sentinel, Google SecOps/Chronicle), EDR/XDR (CrowdStrike, SentinelOne, Defender), and SOAR platforms. • Solid understanding of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, and TTP-based hunting methodologies. • Working knowledge of cloud security across AWS/Azure/GCP — cloud logging, IAM, network flow logs, and cloud threat detection (strongly preferred). • Experience with scripting/query languages (KQL, SPL, Python, or similar) for hunt automation and analytics. • Familiarity with BFSI threat landscape: payment fraud, SWIFT security, banking malware, insider risk, and regulatory expectations (RBI/SEBI/IRDAI). • Strong knowledge of network protocols, Windows/Linux internals, malware analysis fundamentals, and digital forensics. • Excellent analytical, documentation, and stakeholder communication skills. Preferred Certifications & Training • GIAC: GCTI (Cyber Threat Intelligence), GCFA (Forensic Analyst), GCIH (Incident Handler), or GCDA (Detection Analyst) • Certified Threat Intelligence Analyst (CTIA) or eCTHP (eLearnSecurity Certified Threat Hunting Professional) • CompTIA CySA+ (Cybersecurity Analyst) or Security+ • Certified SOC Analyst (CSA) / Certified Ethical Hacker (CEH) • Cloud security certifications: AWS Certified Security – Specialty, Microsoft SC-200/AZ-500, or Google Professional Cloud Security Engineer • MITRE ATT&CK-aligned training (e.g., MAD certification) and SANS FOR508/FOR578 training preferred • CISSP or CISM (advantageous for senior candidates) **At Angel One, our thriving culture is rooted in Diversity, Equity, and Inclusion (DEI).** *As an Equal opportunity employer, we wholeheartedly welcome people from all backgrounds irrespective of caste, religion, gender, marital status, sexuality, disability, class or age to be part of our team. We believe that everyone's unique experiences and viewpoints make us stronger together. Come and be a part of #OneSpace\\*, where your individuality is celebrated and embraced.*