Threat Detection Analyst
Exabeam Threat Detection Analyst
About the role
We are hiring a Threat Detection Analyst to join our team in Pune. This is a hands-on analysis role for someone who wants to spend their day in the telemetry: triaging alerts, chasing down suspicious behaviour, and turning what they find into better detections.
You will sit alongside the engineers who build our detection content, which means your findings have a short path to the product. When you spot a noisy rule or a coverage gap, you will be the one who raises it and helps fix it.
This is a good role for an analyst who is early in their career but serious about the craft, and who wants to work on detection quality rather than only closing tickets.
- Monitor and triage security alerts raised by the Exabeam and LogRhythm platforms, escalating what needs deeper investigation.
- Investigate suspicious user and entity behaviour, and document findings clearly for engineering and customer-facing teams.
- Test and validate new detection content before release, reporting false positives with the evidence needed to tune them.
- Maintain and improve triage runbooks so investigations are repeatable across the team.
- Track emerging threats and adversary techniques, and flag gaps in current detection coverage.
- Work with detection engineers to refine correlation rules and behavioural analytics models.
- Support escalations that call for hands-on analysis of security telemetry.
- Experience in a security operations, threat detection, or incident response role, or a strong foundation from a security-focused degree or certification pathway.
- Working knowledge of SIEM tooling, and the ability to write and refine search queries against security telemetry.
- Understanding of common attack techniques across endpoint, network, identity, and cloud, and familiarity with MITRE ATT&CK.
- Ability to read logs from operating systems, firewalls, and identity providers and reason about what actually happened.
- Clear written communication, and the discipline to document an investigation so a colleague can follow it.
- Willingness to work as part of a rota that supports colleagues and customers across time zones.
- Scripting ability in Python or a similar language for automating repetitive analysis.
- Exposure to user and entity behaviour analytics (UEBA) or anomaly-based detection.
- Familiarity with cloud provider security logging, such as AWS CloudTrail, Azure Activity Logs, or GCP audit logs.
- Certifications such as CompTIA Security+, GCIH, or GCIA.