Threat Detection Analyst

Exabeam is a leader in intelligence and automation that powers security operations for the world's smartest companies. As a global cybersecurity innovator, Exabeam provides industry-proven, security-focused, and flexible solutions for faster, more accurate threat detection, investigation, and response (TDIR). Exabeam and LogRhythm have merged.

About the role

We are hiring a Threat Detection Analyst to join our team in Pune. This is a hands-on analysis role for someone who wants to spend their day in the telemetry: triaging alerts, chasing down suspicious behaviour, and turning what they find into better detections.

You will sit alongside the engineers who build our detection content, which means your findings have a short path to the product. When you spot a noisy rule or a coverage gap, you will be the one who raises it and helps fix it.

This is a good role for an analyst who is early in their career but serious about the craft, and who wants to work on detection quality rather than only closing tickets.
  • Monitor and triage security alerts raised by the Exabeam and LogRhythm platforms, escalating what needs deeper investigation.
  • Investigate suspicious user and entity behaviour, and document findings clearly for engineering and customer-facing teams.
  • Test and validate new detection content before release, reporting false positives with the evidence needed to tune them.
  • Maintain and improve triage runbooks so investigations are repeatable across the team.
  • Track emerging threats and adversary techniques, and flag gaps in current detection coverage.
  • Work with detection engineers to refine correlation rules and behavioural analytics models.
  • Support escalations that call for hands-on analysis of security telemetry.
Essential
  • Experience in a security operations, threat detection, or incident response role, or a strong foundation from a security-focused degree or certification pathway.
  • Working knowledge of SIEM tooling, and the ability to write and refine search queries against security telemetry.
  • Understanding of common attack techniques across endpoint, network, identity, and cloud, and familiarity with MITRE ATT&CK.
  • Ability to read logs from operating systems, firewalls, and identity providers and reason about what actually happened.
  • Clear written communication, and the discipline to document an investigation so a colleague can follow it.
  • Willingness to work as part of a rota that supports colleagues and customers across time zones.
Desirable
  • Scripting ability in Python or a similar language for automating repetitive analysis.
  • Exposure to user and entity behaviour analytics (UEBA) or anomaly-based detection.
  • Familiarity with cloud provider security logging, such as AWS CloudTrail, Azure Activity Logs, or GCP audit logs.
  • Certifications such as CompTIA Security+, GCIH, or GCIA.

See also

Data Analytics jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available