Source description
About the role
Threat Intelligence Analyst (L2)
Location
India (Hybrid)
Role Level
L2 – Advanced Operations / Intelligence Analysis / Incident Support
Role Summary
The L2 Threat Intelligence Analyst is responsible for advanced analysis, enrichment, and operational use of cyber threat intelligence to support security operations and incident response activities across enterprise environments.
This role handles threat intelligence alerts and requests , performs deeper contextual analysis using Talos and Recorded Future , supports incident investigations with intelligence insights, and escalates strategic or complex intelligence.
In‑Scope Threat Intelligence Platforms
Cisco Talos
Recorded Future
Key Responsibilities (L2)
L2 Threat Intelligence Analysis & Enrichment
Analyze threat intelligence alerts, feeds, and reports
Perform contextual enrichment of indicators of compromise (IOCs), including:
IP addresses
Domains and URLs
File hashes
Threat actors and malware families
Validate intelligence relevance and confidence before use in investigations.
Intelligence Support for Security Incidents
Support SOC, IR, and security operations teams by providing actionable threat intelligence during active incidents.
Correlate Talos and Recorded Future intelligence with:
Network and endpoint alerts
Email security findings
Cloud and infrastructure security events
Help assess threat severity, likelihood, and potential impact .
Threat Monitoring & Trend Analysis (L2)
Monitor intelligence sources for:
Emerging threats
Campaign activity
Exploited vulnerabilities
Industry‑relevant threat trends
Identify patterns and recurring indicators that may indicate broader attack campaigns.
Escalate high‑risk or novel threat activity to Client Incident Response Teams
Use‑Case and Detection Support
Provide intelligence input to improve:
SIEM/SOC detection use cases
Alert prioritization and triage decisions
Support tuning initiatives by validating IOC quality and reducing false positives.
Reporting & Documentation
Document intelligence assessments clearly in tickets, reports, or case notes.
Produce operational intelligence summaries for shift handovers and incident reviews.
Adhere to SLAs, SOPs, and escalation procedures.
Required Skills & Experience
Mandatory
6+ years' experience in Threat Intelligence, SOC, or Security Operations roles
Hands‑on operational experience with:
Cisco Talos
Recorded Future
Strong understanding of:
Cyber kill chain and attack lifecycle
Common threat actor TTPs
Malware and vulnerability exploitation concepts
Preferred
Experience supporting SOC or incident response teams with threat intelligence
Familiarity with MITRE ATT&CK framework
Experience in managed security services or large enterprise SOCs
Certifications (Preferred / Nice to Have)
Threat intelligence or SOC‑focused certifications
Security+ / CySA+ or equivalent
Any vendor‑neutral threat intelligence training
More at PeopleLogic Business Solutions