HamburgerMenu
hirist

Senior Dark Web & Cyber Threat Intelligence Analyst

SnehVin Business Solutions
8 - 10 Years
Bangalore

Posted on: 27/07/2026

Job Description

Job Title : Senior Dark Web & Cyber Threat Intelligence (CTI) Analyst


Experience : 8-10 years


Location : Bangalore-Hybrid / Remote


Department : Cyber Threat Intelligence (CTI) / Digital Risk Protection (DRP)


About the Role :


We are seeking an experienced Senior Dark Web & Cyber Threat Intelligence (CTI) Analyst with 8-10 years of hands-on experience in Cyber Threat Intelligence, Dark Web Monitoring, Threat Research, Digital Risk Protection, OSINT Investigations, and Cybercrime Intelligence.


The ideal candidate should possess deep knowledge of cybercriminal ecosystems, underground forums, Telegram channels, ransomware groups, Initial Access Brokers (IABs), credential leak marketplaces, carding communities, malware operators, threat actor infrastructures, and cybercriminal tactics, techniques, and procedures (TTPs). The candidate will be responsible for identifying, collecting, analyzing, enriching, and operationalizing intelligence to proactively identify threats targeting organizations, brands, executives, customers, and critical assets.


Key Responsibilities :


Dark Web & Underground Intelligence Monitoring :


- Monitor Deep Web and Dark Web forums, marketplaces, breach sites, ransomware leak portals, underground communities, and criminal communication platforms.


- Track cybercriminal groups, ransomware operators, threat actors, initial access brokers, fraud actors, hacktivist groups, and nation-state threat actors.


- Identify emerging threats, attack campaigns, credential leaks, malware sales, exploit discussions, access sales, and data breach activities.


- Conduct threat actor attribution and profiling activities.


- Monitor cybercrime trends, underground economies, and criminal monetization models.


Threat Actor Intelligence :


- Develop and maintain detailed Threat Actor Profiles.


- Track :


i. Threat actor aliases


ii. TTPs


iii. Infrastructure


iv. Malware usage


v. Victimology


vi. Motivations


vii. Affiliations


viii. Campaign evolution.


- Analyze cybercriminal communications across :


i. Telegram


ii. Discord


iii. IRC


iv. Dark Web Forums


v. Closed Communities


vi. Paste Sites


vii. Criminal Marketplaces.


- Maintain continuous visibility into :


i. APT Groups


ii. Ransomware Groups


iii. Initial Access Brokers


iv. Infostealer Ecosystems


v. Fraud Networks


vi. Cybercrime Syndicates


vii. Hacktivist Campaigns.


Cyber Threat Intelligence Operations :


- Conduct tactical, operational, and strategic intelligence analysis.


- Produce actionable intelligence supporting :


i. Threat Hunting


ii. SOC Operations


iii. Vulnerability Management


iv. Brand Protection


v. Executive Protection.


- Analyze :


i. Malware Campaigns


ii. Phishing Infrastructure


iii. Botnets


iv. Exploit Kits


v. Ransomware Operations


vi. Fraud Campaigns


vii. Credential Theft Operations.


- Map adversary behavior to :


i. MITRE ATT&CK


ii. Diamond Model


iii. Cyber Kill Chain


iv. Intelligence Lifecycle Frameworks.


Digital Risk Protection (DRP) :


- Monitor and identify risks related to :


i. Brand Impersonation


ii. Executive/VIP Targeting


iii. Credential Leaks


iv. Data Breaches


v. Rogue Mobile Applications


vi. Fake Social Media Accounts


vii. Phishing Domains


viii. Fraudulent Websites


ix. Domain Abuse


x. Supply Chain Risks


xi. Third-Party Exposure


xii. Sensitive Data Exposure.


- Work closely with remediation and takedown teams to coordinate rapid removal of malicious infrastructure and impersonation assets.


OSINT & Cyber Investigations :


- Conduct advanced Open Source Intelligence (OSINT) investigations.


- Correlate intelligence from multiple sources to uncover hidden relationships and threat activity.


- Investigate :


i. Phishing Campaigns


ii. Brand Abuse


iii. Executive Impersonation


iv. Data Leaks


v. Credential Exposure


vi. Fraud Operations


vii. Threat Actor Infrastructure.


- Perform infrastructure analysis involving :


i. Domains


ii. IP Addresses


iii. Hosting Providers


iv. DNS Records


v. SSL Certificates


vi. Cloud Assets


vii. Malware Infrastructure.


Malware & Adversary Intelligence :


- Track and analyze :


i. Infostealers


ii. Banking Trojans


iii. Loaders


iv. Remote Access Trojans (RATs)


v. Ransomware Families


vi. Botnets.


- Extract actionable intelligence from malware campaigns.


- Correlate malware indicators with threat actor activity.


- Analyze attacker infrastructure and malware distribution mechanisms.


Intelligence Reporting & Executive Briefings :


- Develop and deliver :


i. Tactical Intelligence Reports


ii. Operational Intelligence Assessments


iii. Strategic Threat Reports


iv. Threat Actor Profiles


v. Executive Intelligence Briefings


vi. Emerging Threat Alerts


vii. Industry Threat Assessments


viii. Campaign Tracking Reports


ix. Customer Intelligence Reports.


- Present intelligence findings to :


i. CISOs


ii. CXOs


iii. Security Leadership


iv. Incident Response Teams


v. Threat Hunting Teams.


Intelligence Collection & Automation :


- Develop intelligence collection plans and intelligence requirements.


- Automate collection, enrichment, and correlation workflows.


- Create intelligence-driven detection opportunities.


- Improve intelligence quality and reduce false positives.


- Support intelligence sharing programs.


Required Technical Skills :


Threat Intelligence Frameworks :


- MITRE ATT&CK, Diamond Model, Cyber Kill Chain, Intelligence Lifecycle, Threat Modeling, Adversary Emulation Concepts.


Dark Web Expertise :


- Strong understanding of :


i. TOR Ecosystem


ii. Dark Web Marketplaces


iii. Underground Forums


iv. Ransomware Leak Sites


v. Initial Access Broker Ecosystems


vi. Cybercrime-as-a-Service Operations


vii. Credential Marketplaces


viii. Underground Economy Models.


OSINT Tools :


- Hands-on expertise with : Maltego, SpiderFoot, Shodan, Censys, Recon-ng, FOCA, Intelligence X, RiskIQ / PassiveTotal, VirusTotal, GreyNoise, SecurityTrails, Hunter.io, WhoisXML, Have I Been Pwned, OpenCTI, MISP.


Dark Web & Threat Intelligence Platforms :


- Hands-on experience with one or more : Recorded Future, Flashpoint, Intel 471, Cybersixgill, DarkOwl, KELA, SearchLight Cyber, SOCRadar, Constella Intelligence, ThreatConnect, Anomali, OpenCTI, MISP.


Technical Competencies :


- Threat Hunting, Threat Research, IOC Extraction & Enrichment, Malware Intelligence, Infrastructure Analysis, Data Correlation, Intelligence Analysis, YARA, Sigma Rules, Python Scripting, API Integrations, Automation Development.


Preferred Qualifications :


- Bachelor's or Master's Degree in Cyber Security, Information Security, Computer Science, or related discipline.


Preferred Certifications :


- GIAC Cyber Threat Intelligence (GCTI), GIAC Open Source Intelligence (GOSI), Certified Threat Intelligence Analyst (CTIA), SANS FOR578, CISSP, CEH, GREM, GCFA.


Success Criteria :


- Independently identify and track sophisticated threat actors.


- Produce high-confidence intelligence with minimal false positives.


- Deliver actionable intelligence that directly supports detection, prevention, remediation, takedown, and incident response activities.


- Demonstrate deep understanding of cybercrime ecosystems and adversary operations.


- Continuously monitor and report on emerging threats impacting customers and organizations globally.


Experience Required :


- 8-10 years of experience in Cyber Threat Intelligence, Dark Web Intelligence, Threat Research, Digital Risk Protection, Cybercrime Investigations, Threat Hunting, or related cybersecurity domains.


- Experience supporting enterprise customers across Financial Services, Healthcare, Technology, Manufacturing, and Government, Telecom, or Critical Infrastructure sectors is highly preferred.


Website :


https : //beyondcloudintel.com/


info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...