Kpmg India Services Llp

Cyber_MS_KDNI-MDR - Threat Hunting Lead

Kpmg India Services Llp
Bengaluru/Bangalore
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 8 yearsMin. 8 years

Job Description

Cyber_MS_KDNI-MDR - Threat Hunting Lead

Job Title: Threat Hunting Lead
Location: Bangalore/Gurgaon

Department: MDR – Threat Hunter

Job Summary:

We are seeking an experienced Senior Threat Hunter to join our Managed Detection and Response team. This role is responsible for proactively identifying advanced threats that evade traditional security controls through intelligence-driven, hypothesis-based threat hunting.

The ideal candidate will leverage telemetry from endpoint, network, cloud, identity, and security platforms to uncover malicious activity, improve detection coverage, and strengthen overall security operations.

Key Responsibilities:

Lead Proactive Threat Hunting Activities

  • Design and execute intelligence-driven and hypothesis-based threat hunts across endpoint, network, cloud, identity, and SaaS environments.
  • Develop threat hunting hypotheses based on threat intelligence, incident response findings, emerging attacker trends, and MITRE ATT&CK techniques.
  • Identify hidden threats, anomalous behaviors, indicators of compromise (IOCs), and indicators of attack (IOAs) that may bypass traditional security monitoring controls.
  • Conduct both proactive and reactive threat hunts driven by current threat landscape developments and client-specific concerns.

Advanced Security Investigations

  • Investigate suspicious activity and validate potential threats identified through threat hunting activities.
  • Analyze attacker behavior, lateral movement, persistence mechanisms, credential theft, privilege escalation, and command-and-control activities.
  • Correlate findings across endpoint, network, identity, cloud, and application telemetry sources.
  • Support complex forensic and investigative activities when advanced threats are identified.

Detection Engineering & Security Improvement

  • Identify visibility gaps and weaknesses in current monitoring and detection capabilities.
  • Convert validated threat hunting findings into operational detections, analytics, correlation rules, dashboards, and use cases.
  • Collaborate with SOC, MDR, Detection Engineering, and Incident Response teams to enhance detection coverage and reduce attacker dwell time.
  • Measure and improve MITRE ATT&CK coverage across security monitoring capabilities.

Threat Intelligence Integration

  • Leverage tactical, operational, and strategic threat intelligence to drive threat hunting activities.
  • Monitor emerging threats, threat actor campaigns, vulnerabilities, and adversary tradecraft.
  • Incorporate external intelligence and internal incident learnings into future hunting activities.

Reporting & Stakeholder Engagement

  • Produce detailed technical reports and executive-level summaries of threat hunting outcomes.
  • Present findings, recommendations, and threat intelligence insights to security teams, leadership, and clients.
  • Develop and maintain threat hunting playbooks, methodologies, and operational documentation.
  • Mentor junior analysts and contribute to the maturity of threat hunting capabilities.

Required Qualifications:

Experience

  • 8+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Detection Engineering, Cyber Threat Intelligence, or related disciplines.
  • Minimum 5+ years of dedicated threat hunting experience.
  • Demonstrated experience conducting hypothesis-driven and intelligence-led threat hunts.
  • Experience leveraging the MITRE ATT&CK framework to develop and execute threat hunts.
  • Experience working within enterprise SOC, MDR, MSSP, consulting, or cyber defense environments.

Technical Expertise

  • Hands-on experience with enterprise EDR/XDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or equivalent solutions.
  • Strong experience with SIEM technologies such as Microsoft Sentinel, Splunk, Google SecOps, or equivalent platforms.
  • Advanced proficiency in KQL, SPL, SQL, or other security analytics query languages.
  • Ability to research in depth and derive outcomes
  • Strong understanding of Windows, Linux and cloud attack techniques and security monitoring.
  • Experience hunting across Azure, AWS, and/or Google Cloud environments.
  • Experience developing scripts and automation using Python, PowerShell, Bash, or similar languages.

Preferred Qualifications:

  • Incident Response Experience (Strongly Preferred)
    • Candidates with significant Incident Response experience will be strongly preferred and prioritized.
    • Preferred experience includes:
    • Leading or supporting incident investigations involving ransomware, advanced persistent threats (APTs), insider threats, and credential compromise.
    • Digital Forensics and Incident Response (DFIR) engagements.
    • Malware analysis and adversary behavior analysis.
    • Demonstrated exploit development experience, or any contributed to CVEs.
  • Large Enterprise Threat Hunting Experience (Strongly Preferred)
    • Candidates with experience conducting threat hunting activities within large and complex enterprise environments will receive priority consideration.
    • Preferred experience includes:
    • Threat hunting across environments containing 10,000+ endpoints, distributed networks, hybrid cloud environments, and complex identity ecosystems.
    • Experience supporting large, highly regulated organizations, including: 
    • Financial Services
    • Banking
    • Insurance
    • Capital Markets
    • Healthcare
    • Energy & Utilities
    • Critical Infrastructure
    • Government
    • Experience analyzing large-scale telemetry datasets from SIEM, EDR/XDR, cloud, identity, network, and security monitoring platforms.
    • Experience identifying sophisticated threats that evade traditional detection capabilities.
    • Experience operating within mature SOC, MDR, MSSP, or Cyber Defense organizations.
    • Experience assessing detection coverage, identifying visibility gaps, and improving enterprise monitoring effectiveness.
  • Detection engineering and security content development.
  • Threat Intelligence platforms such as Recorded Future, Mandiant Intelligence, Sixgill, or equivalent.
  • Security orchestration and automation (SOAR).
  • Client-facing consulting experience.
  • Experience delivering threat hunting services within Managed Detection and Response (MDR) programs.

Additional Preferred Experience

Preferred Certifications:

  • GIAC GCTI
  • GCIH
  • GCFA
  • GCIA
  • GMON
  • CISSP
  • Microsoft Security Certifications
  • Azure Security Engineer Associate
  • CrowdStrike Certified Falcon Hunter

Other advanced threat hunting, digital forensics, or incident response certifications.

What Success Looks Like:

  • Identifies sophisticated threats before they become security incidents.
  • Develops effective hunting hypotheses aligned to current threat landscape and organizational risk.
  • Continuously improves detection coverage and visibility across enterprise environments.
  • Provides expert investigative support during high-severity cyber incidents.
  • Translates threat hunting outcomes into measurable security improvements.
  • Acts as a trusted subject matter expert in Threat Hunting, Incident Response, and Cyber Defense Operations.

Priority consideration will be given to candidates who possess both advanced Threat Hunting and hands-on Incident Response experience within large-scale enterprise environments, particularly financial services and other highly regulated industries.

 

Job Title: Threat Hunting Lead
Location: Bangalore/Gurgaon

Department: MDR – Threat Hunter

Job Summary:

We are seeking an experienced Senior Threat Hunter to join our Managed Detection and Response team. This role is responsible for proactively identifying advanced threats that evade traditional security controls through intelligence-driven, hypothesis-based threat hunting.

The ideal candidate will leverage telemetry from endpoint, network, cloud, identity, and security platforms to uncover malicious activity, improve detection coverage, and strengthen overall security operations.

Key Responsibilities:

Lead Proactive Threat Hunting Activities

  • Design and execute intelligence-driven and hypothesis-based threat hunts across endpoint, network, cloud, identity, and SaaS environments.
  • Develop threat hunting hypotheses based on threat intelligence, incident response findings, emerging attacker trends, and MITRE ATT&CK techniques.
  • Identify hidden threats, anomalous behaviors, indicators of compromise (IOCs), and indicators of attack (IOAs) that may bypass traditional security monitoring controls.
  • Conduct both proactive and reactive threat hunts driven by current threat landscape developments and client-specific concerns.

Advanced Security Investigations

  • Investigate suspicious activity and validate potential threats identified through threat hunting activities.
  • Analyze attacker behavior, lateral movement, persistence mechanisms, credential theft, privilege escalation, and command-and-control activities.
  • Correlate findings across endpoint, network, identity, cloud, and application telemetry sources.
  • Support complex forensic and investigative activities when advanced threats are identified.

Detection Engineering & Security Improvement

  • Identify visibility gaps and weaknesses in current monitoring and detection capabilities.
  • Convert validated threat hunting findings into operational detections, analytics, correlation rules, dashboards, and use cases.
  • Collaborate with SOC, MDR, Detection Engineering, and Incident Response teams to enhance detection coverage and reduce attacker dwell time.
  • Measure and improve MITRE ATT&CK coverage across security monitoring capabilities.

Threat Intelligence Integration

  • Leverage tactical, operational, and strategic threat intelligence to drive threat hunting activities.
  • Monitor emerging threats, threat actor campaigns, vulnerabilities, and adversary tradecraft.
  • Incorporate external intelligence and internal incident learnings into future hunting activities.

Reporting & Stakeholder Engagement

  • Produce detailed technical reports and executive-level summaries of threat hunting outcomes.
  • Present findings, recommendations, and threat intelligence insights to security teams, leadership, and clients.
  • Develop and maintain threat hunting playbooks, methodologies, and operational documentation.
  • Mentor junior analysts and contribute to the maturity of threat hunting capabilities.

Required Qualifications:

Experience

  • 8+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Detection Engineering, Cyber Threat Intelligence, or related disciplines.
  • Minimum 5+ years of dedicated threat hunting experience.
  • Demonstrated experience conducting hypothesis-driven and intelligence-led threat hunts.
  • Experience leveraging the MITRE ATT&CK framework to develop and execute threat hunts.
  • Experience working within enterprise SOC, MDR, MSSP, consulting, or cyber defense environments.

Technical Expertise

  • Hands-on experience with enterprise EDR/XDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or equivalent solutions.
  • Strong experience with SIEM technologies such as Microsoft Sentinel, Splunk, Google SecOps, or equivalent platforms.
  • Advanced proficiency in KQL, SPL, SQL, or other security analytics query languages.
  • Ability to research in depth and derive outcomes
  • Strong understanding of Windows, Linux and cloud attack techniques and security monitoring.
  • Experience hunting across Azure, AWS, and/or Google Cloud environments.
  • Experience developing scripts and automation using Python, PowerShell, Bash, or similar languages.

Preferred Qualifications:

  • Incident Response Experience (Strongly Preferred)
    • Candidates with significant Incident Response experience will be strongly preferred and prioritized.
    • Preferred experience includes:
    • Leading or supporting incident investigations involving ransomware, advanced persistent threats (APTs), insider threats, and credential compromise.
    • Digital Forensics and Incident Response (DFIR) engagements.
    • Malware analysis and adversary behavior analysis.
    • Demonstrated exploit development experience, or any contributed to CVEs.
  • Large Enterprise Threat Hunting Experience (Strongly Preferred)
    • Candidates with experience conducting threat hunting activities within large and complex enterprise environments will receive priority consideration.
    • Preferred experience includes:
    • Threat hunting across environments containing 10,000+ endpoints, distributed networks, hybrid cloud environments, and complex identity ecosystems.
    • Experience supporting large, highly regulated organizations, including: 
    • Financial Services
    • Banking
    • Insurance
    • Capital Markets
    • Healthcare
    • Energy & Utilities
    • Critical Infrastructure
    • Government
    • Experience analyzing large-scale telemetry datasets from SIEM, EDR/XDR, cloud, identity, network, and security monitoring platforms.
    • Experience identifying sophisticated threats that evade traditional detection capabilities.
    • Experience operating within mature SOC, MDR, MSSP, or Cyber Defense organizations.
    • Experience assessing detection coverage, identifying visibility gaps, and improving enterprise monitoring effectiveness.
  • Detection engineering and security content development.
  • Threat Intelligence platforms such as Recorded Future, Mandiant Intelligence, Sixgill, or equivalent.
  • Security orchestration and automation (SOAR).
  • Client-facing consulting experience.
  • Experience delivering threat hunting services within Managed Detection and Response (MDR) programs.

Additional Preferred Experience

Preferred Certifications:

  • GIAC GCTI
  • GCIH
  • GCFA
  • GCIA
  • GMON
  • CISSP
  • Microsoft Security Certifications
  • Azure Security Engineer Associate
  • CrowdStrike Certified Falcon Hunter

Other advanced threat hunting, digital forensics, or incident response certifications.

What Success Looks Like:

  • Identifies sophisticated threats before they become security incidents.
  • Develops effective hunting hypotheses aligned to current threat landscape and organizational risk.
  • Continuously improves detection coverage and visibility across enterprise environments.
  • Provides expert investigative support during high-severity cyber incidents.
  • Translates threat hunting outcomes into measurable security improvements.
  • Acts as a trusted subject matter expert in Threat Hunting, Incident Response, and Cyber Defense Operations.

Priority consideration will be given to candidates who possess both advanced Threat Hunting and hands-on Incident Response experience within large-scale enterprise environments, particularly financial services and other highly regulated industries.

 

Job Title: Threat Hunting Lead
Location: Bangalore/Gurgaon

Department: MDR – Threat Hunter

Job Summary:

We are seeking an experienced Senior Threat Hunter to join our Managed Detection and Response team. This role is responsible for proactively identifying advanced threats that evade traditional security controls through intelligence-driven, hypothesis-based threat hunting.

The ideal candidate will leverage telemetry from endpoint, network, cloud, identity, and security platforms to uncover malicious activity, improve detection coverage, and strengthen overall security operations.

Key Responsibilities:

Lead Proactive Threat Hunting Activities

  • Design and execute intelligence-driven and hypothesis-based threat hunts across endpoint, network, cloud, identity, and SaaS environments.
  • Develop threat hunting hypotheses based on threat intelligence, incident response findings, emerging attacker trends, and MITRE ATT&CK techniques.
  • Identify hidden threats, anomalous behaviors, indicators of compromise (IOCs), and indicators of attack (IOAs) that may bypass traditional security monitoring controls.
  • Conduct both proactive and reactive threat hunts driven by current threat landscape developments and client-specific concerns.

Advanced Security Investigations

  • Investigate suspicious activity and validate potential threats identified through threat hunting activities.
  • Analyze attacker behavior, lateral movement, persistence mechanisms, credential theft, privilege escalation, and command-and-control activities.
  • Correlate findings across endpoint, network, identity, cloud, and application telemetry sources.
  • Support complex forensic and investigative activities when advanced threats are identified.

Detection Engineering & Security Improvement

  • Identify visibility gaps and weaknesses in current monitoring and detection capabilities.
  • Convert validated threat hunting findings into operational detections, analytics, correlation rules, dashboards, and use cases.
  • Collaborate with SOC, MDR, Detection Engineering, and Incident Response teams to enhance detection coverage and reduce attacker dwell time.
  • Measure and improve MITRE ATT&CK coverage across security monitoring capabilities.

Threat Intelligence Integration

  • Leverage tactical, operational, and strategic threat intelligence to drive threat hunting activities.
  • Monitor emerging threats, threat actor campaigns, vulnerabilities, and adversary tradecraft.
  • Incorporate external intelligence and internal incident learnings into future hunting activities.

Reporting & Stakeholder Engagement

  • Produce detailed technical reports and executive-level summaries of threat hunting outcomes.
  • Present findings, recommendations, and threat intelligence insights to security teams, leadership, and clients.
  • Develop and maintain threat hunting playbooks, methodologies, and operational documentation.
  • Mentor junior analysts and contribute to the maturity of threat hunting capabilities.

Required Qualifications:

Experience

  • 8+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Detection Engineering, Cyber Threat Intelligence, or related disciplines.
  • Minimum 5+ years of dedicated threat hunting experience.
  • Demonstrated experience conducting hypothesis-driven and intelligence-led threat hunts.
  • Experience leveraging the MITRE ATT&CK framework to develop and execute threat hunts.
  • Experience working within enterprise SOC, MDR, MSSP, consulting, or cyber defense environments.

Technical Expertise

  • Hands-on experience with enterprise EDR/XDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or equivalent solutions.
  • Strong experience with SIEM technologies such as Microsoft Sentinel, Splunk, Google SecOps, or equivalent platforms.
  • Advanced proficiency in KQL, SPL, SQL, or other security analytics query languages.
  • Ability to research in depth and derive outcomes
  • Strong understanding of Windows, Linux and cloud attack techniques and security monitoring.
  • Experience hunting across Azure, AWS, and/or Google Cloud environments.
  • Experience developing scripts and automation using Python, PowerShell, Bash, or similar languages.

Preferred Qualifications:

  • Incident Response Experience (Strongly Preferred)
    • Candidates with significant Incident Response experience will be strongly preferred and prioritized.
    • Preferred experience includes:
    • Leading or supporting incident investigations involving ransomware, advanced persistent threats (APTs), insider threats, and credential compromise.
    • Digital Forensics and Incident Response (DFIR) engagements.
    • Malware analysis and adversary behavior analysis.
    • Demonstrated exploit development experience, or any contributed to CVEs.
  • Large Enterprise Threat Hunting Experience (Strongly Preferred)
    • Candidates with experience conducting threat hunting activities within large and complex enterprise environments will receive priority consideration.
    • Preferred experience includes:
    • Threat hunting across environments containing 10,000+ endpoints, distributed networks, hybrid cloud environments, and complex identity ecosystems.
    • Experience supporting large, highly regulated organizations, including: 
    • Financial Services
    • Banking
    • Insurance
    • Capital Markets
    • Healthcare
    • Energy & Utilities
    • Critical Infrastructure
    • Government
    • Experience analyzing large-scale telemetry datasets from SIEM, EDR/XDR, cloud, identity, network, and security monitoring platforms.
    • Experience identifying sophisticated threats that evade traditional detection capabilities.
    • Experience operating within mature SOC, MDR, MSSP, or Cyber Defense organizations.
    • Experience assessing detection coverage, identifying visibility gaps, and improving enterprise monitoring effectiveness.
  • Detection engineering and security content development.
  • Threat Intelligence platforms such as Recorded Future, Mandiant Intelligence, Sixgill, or equivalent.
  • Security orchestration and automation (SOAR).
  • Client-facing consulting experience.
  • Experience delivering threat hunting services within Managed Detection and Response (MDR) programs.

Additional Preferred Experience

Preferred Certifications:

  • GIAC GCTI
  • GCIH
  • GCFA
  • GCIA
  • GMON
  • CISSP
  • Microsoft Security Certifications
  • Azure Security Engineer Associate
  • CrowdStrike Certified Falcon Hunter

Other advanced threat hunting, digital forensics, or incident response certifications.

What Success Looks Like:

  • Identifies sophisticated threats before they become security incidents.
  • Develops effective hunting hypotheses aligned to current threat landscape and organizational risk.
  • Continuously improves detection coverage and visibility across enterprise environments.
  • Provides expert investigative support during high-severity cyber incidents.
  • Translates threat hunting outcomes into measurable security improvements.
  • Acts as a trusted subject matter expert in Threat Hunting, Incident Response, and Cyber Defense Operations.

Priority consideration will be given to candidates who possess both advanced Threat Hunting and hands-on Incident Response experience within large-scale enterprise environments, particularly financial services and other highly regulated industries.

 

Experience Level

Senior Level

Job role

Work location
Work locationBangalore, Karnataka, India
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 8 years

About company

Name
NameKpmg India Services Llp
Job posted by Kpmg India Services Llp

Similar jobs you can apply for

Security Guard
Dapa group

Security Guard

Dapa group
Koramangala, Bengaluru/Bangalore
₹25,000 - ₹26,000
Work from Office
Full Time
Min. 1 year
Basic English
D R G Security Services Private Limited

Field Officer

D R G Security Services Private Limited
Gottigere, Bengaluru/Bangalore
₹40,000 - ₹45,000
Work from Office
Full Time
Min. 3 years
Basic English
Bombay Intelligence Security Ltd

Security Guard Supervisor

Bombay Intelligence Security Ltd
Electronics City, Bengaluru/Bangalore
₹29,000 - ₹33,000
Work from Office
Full Time
Min. 1 year
No English Required
The Career Choice

Security Guard

The Career Choice
Bagaluru, Bengaluru/Bangalore
₹22,000 - ₹24,000
Work from Office
Full Time
Min. 6 months
Basic English

Security Guard

Eagle Wings Global Securitas
KR Puram, Bengaluru/Bangalore
₹18,000 - ₹19,000
Work from Office
Part Time
Full Time
Any experience
No English Required

Field Officer

Eagle Wings Global Securitas
Bennigana Halli, Bengaluru/Bangalore
₹30,000 - ₹40,000*
Field Job
Full Time
Min. 1 year
Basic English

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 8 to 31 years are eligible to apply for this job. You can apply for more jobs in Bengaluru/Bangalore to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Bengaluru/Bangalore at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Bengaluru/Bangalore . Through apna, you can find jobs in 64 cities across India. Join NOW!

Senior Threat Hunting Lead in Kpmg India Services Llp | apna.co