Posted on: 27/07/2026
Job Title : Senior Dark Web & Cyber Threat Intelligence (CTI) Analyst
Experience : 8-10 years
Location : Bangalore-Hybrid / Remote
Department : Cyber Threat Intelligence (CTI) / Digital Risk Protection (DRP)
About the Role :
We are seeking an experienced Senior Dark Web & Cyber Threat Intelligence (CTI) Analyst with 8-10 years of hands-on experience in Cyber Threat Intelligence, Dark Web Monitoring, Threat Research, Digital Risk Protection, OSINT Investigations, and Cybercrime Intelligence.
The ideal candidate should possess deep knowledge of cybercriminal ecosystems, underground forums, Telegram channels, ransomware groups, Initial Access Brokers (IABs), credential leak marketplaces, carding communities, malware operators, threat actor infrastructures, and cybercriminal tactics, techniques, and procedures (TTPs). The candidate will be responsible for identifying, collecting, analyzing, enriching, and operationalizing intelligence to proactively identify threats targeting organizations, brands, executives, customers, and critical assets.
Key Responsibilities :
Dark Web & Underground Intelligence Monitoring :
- Monitor Deep Web and Dark Web forums, marketplaces, breach sites, ransomware leak portals, underground communities, and criminal communication platforms.
- Track cybercriminal groups, ransomware operators, threat actors, initial access brokers, fraud actors, hacktivist groups, and nation-state threat actors.
- Identify emerging threats, attack campaigns, credential leaks, malware sales, exploit discussions, access sales, and data breach activities.
- Conduct threat actor attribution and profiling activities.
- Monitor cybercrime trends, underground economies, and criminal monetization models.
Threat Actor Intelligence :
- Develop and maintain detailed Threat Actor Profiles.
- Track :
i. Threat actor aliases
ii. TTPs
iii. Infrastructure
iv. Malware usage
v. Victimology
vi. Motivations
vii. Affiliations
viii. Campaign evolution.
- Analyze cybercriminal communications across :
i. Telegram
ii. Discord
iii. IRC
iv. Dark Web Forums
v. Closed Communities
vi. Paste Sites
vii. Criminal Marketplaces.
- Maintain continuous visibility into :
i. APT Groups
ii. Ransomware Groups
iii. Initial Access Brokers
iv. Infostealer Ecosystems
v. Fraud Networks
vi. Cybercrime Syndicates
vii. Hacktivist Campaigns.
Cyber Threat Intelligence Operations :
- Conduct tactical, operational, and strategic intelligence analysis.
- Produce actionable intelligence supporting :
i. Threat Hunting
ii. SOC Operations
iii. Vulnerability Management
iv. Brand Protection
v. Executive Protection.
- Analyze :
i. Malware Campaigns
ii. Phishing Infrastructure
iii. Botnets
iv. Exploit Kits
v. Ransomware Operations
vi. Fraud Campaigns
vii. Credential Theft Operations.
- Map adversary behavior to :
i. MITRE ATT&CK
ii. Diamond Model
iii. Cyber Kill Chain
iv. Intelligence Lifecycle Frameworks.
Digital Risk Protection (DRP) :
- Monitor and identify risks related to :
i. Brand Impersonation
ii. Executive/VIP Targeting
iii. Credential Leaks
iv. Data Breaches
v. Rogue Mobile Applications
vi. Fake Social Media Accounts
vii. Phishing Domains
viii. Fraudulent Websites
ix. Domain Abuse
x. Supply Chain Risks
xi. Third-Party Exposure
xii. Sensitive Data Exposure.
- Work closely with remediation and takedown teams to coordinate rapid removal of malicious infrastructure and impersonation assets.
OSINT & Cyber Investigations :
- Conduct advanced Open Source Intelligence (OSINT) investigations.
- Correlate intelligence from multiple sources to uncover hidden relationships and threat activity.
- Investigate :
i. Phishing Campaigns
ii. Brand Abuse
iii. Executive Impersonation
iv. Data Leaks
v. Credential Exposure
vi. Fraud Operations
vii. Threat Actor Infrastructure.
- Perform infrastructure analysis involving :
i. Domains
ii. IP Addresses
iii. Hosting Providers
iv. DNS Records
v. SSL Certificates
vi. Cloud Assets
vii. Malware Infrastructure.
Malware & Adversary Intelligence :
- Track and analyze :
i. Infostealers
ii. Banking Trojans
iii. Loaders
iv. Remote Access Trojans (RATs)
v. Ransomware Families
vi. Botnets.
- Extract actionable intelligence from malware campaigns.
- Correlate malware indicators with threat actor activity.
- Analyze attacker infrastructure and malware distribution mechanisms.
Intelligence Reporting & Executive Briefings :
- Develop and deliver :
i. Tactical Intelligence Reports
ii. Operational Intelligence Assessments
iii. Strategic Threat Reports
iv. Threat Actor Profiles
v. Executive Intelligence Briefings
vi. Emerging Threat Alerts
vii. Industry Threat Assessments
viii. Campaign Tracking Reports
ix. Customer Intelligence Reports.
- Present intelligence findings to :
i. CISOs
ii. CXOs
iii. Security Leadership
iv. Incident Response Teams
v. Threat Hunting Teams.
Intelligence Collection & Automation :
- Develop intelligence collection plans and intelligence requirements.
- Automate collection, enrichment, and correlation workflows.
- Create intelligence-driven detection opportunities.
- Improve intelligence quality and reduce false positives.
- Support intelligence sharing programs.
Required Technical Skills :
Threat Intelligence Frameworks :
- MITRE ATT&CK, Diamond Model, Cyber Kill Chain, Intelligence Lifecycle, Threat Modeling, Adversary Emulation Concepts.
Dark Web Expertise :
- Strong understanding of :
i. TOR Ecosystem
ii. Dark Web Marketplaces
iii. Underground Forums
iv. Ransomware Leak Sites
v. Initial Access Broker Ecosystems
vi. Cybercrime-as-a-Service Operations
vii. Credential Marketplaces
viii. Underground Economy Models.
OSINT Tools :
- Hands-on expertise with : Maltego, SpiderFoot, Shodan, Censys, Recon-ng, FOCA, Intelligence X, RiskIQ / PassiveTotal, VirusTotal, GreyNoise, SecurityTrails, Hunter.io, WhoisXML, Have I Been Pwned, OpenCTI, MISP.
Dark Web & Threat Intelligence Platforms :
- Hands-on experience with one or more : Recorded Future, Flashpoint, Intel 471, Cybersixgill, DarkOwl, KELA, SearchLight Cyber, SOCRadar, Constella Intelligence, ThreatConnect, Anomali, OpenCTI, MISP.
Technical Competencies :
- Threat Hunting, Threat Research, IOC Extraction & Enrichment, Malware Intelligence, Infrastructure Analysis, Data Correlation, Intelligence Analysis, YARA, Sigma Rules, Python Scripting, API Integrations, Automation Development.
Preferred Qualifications :
- Bachelor's or Master's Degree in Cyber Security, Information Security, Computer Science, or related discipline.
Preferred Certifications :
- GIAC Cyber Threat Intelligence (GCTI), GIAC Open Source Intelligence (GOSI), Certified Threat Intelligence Analyst (CTIA), SANS FOR578, CISSP, CEH, GREM, GCFA.
Success Criteria :
- Independently identify and track sophisticated threat actors.
- Produce high-confidence intelligence with minimal false positives.
- Deliver actionable intelligence that directly supports detection, prevention, remediation, takedown, and incident response activities.
- Demonstrate deep understanding of cybercrime ecosystems and adversary operations.
- Continuously monitor and report on emerging threats impacting customers and organizations globally.
Experience Required :
- 8-10 years of experience in Cyber Threat Intelligence, Dark Web Intelligence, Threat Research, Digital Risk Protection, Cybercrime Investigations, Threat Hunting, or related cybersecurity domains.
- Experience supporting enterprise customers across Financial Services, Healthcare, Technology, Manufacturing, and Government, Telecom, or Critical Infrastructure sectors is highly preferred.
Website :
https : //beyondcloudintel.com/
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1658122