Proactive Threat Hunting
Develop hypotheses and conduct hunts across network, endpoints, cloud, identity, and applications to detect advanced persistent threats (APTs).
Identify abnormal user/machine behaviors and uncover stealthy adversary activity.
Detection & Investigation
Analyse large datasets from SIEM, EDR/XDR, IDS/IPS, firewall logs, and application logs.
Use frameworks like MITRE ATT&CK to classify and track adversary tactics and techniques.
Correlate findings with Threat Intelligence feeds to validate and prioritize threats.
Incident Response Support
Work with SOC and Incident Response teams to escalate and contain suspicious activity.
Provide forensic evidence and context for ongoing investigations.
Detection Engineering
Develop custom detection queries, scripts, and playbooks for repeated hunts.
Tune and enhance existing rules in SIEM / EDR to reduce false positives.
Threat Intelligence Integration
Translate threat intelligence (IoCs, TTPs) into actionable detection logic.
Stay updated on emerging threats, malware families, and zero-day exploits.
Reporting & Communication
Document threat hunting cases, results, and recommended mitigations.
Prepare reports and dashboards for management and technical stakeholders.
Provide input to strengthen bank security policies, procedures, and defense strategy.
Continuous Improvement
Automate recurring hunting processes using Python, PowerShell, or KQL.
Share knowledge and mentor SOC analysts or junior security staff.
Fixed Monthly Salary based on grade (P-611 likely mid-senior band).
Performance Incentives / Variable Pay for meeting security KPIs.
Provident Fund (PF) & Gratuity contributions.
Special Security Allowances (some banks offer additional pay for cyber defense roles).
Preferential rates on loans, credit cards, and banking products.
Medical Insurance for employee + dependents.
Life Insurance & Personal Accident Coverage.
Tie-ups with hospitals for annual health check-ups.
Some banks also provide mental health/wellness programs.
Paid Leaves (casual, earned, sick leave).
Maternity / Paternity Leave.
Public holidays + bank-specific optional holidays.
In some cases, flexible work schedules or partial work-from-home options, especially for cyber roles.
Exposure to cutting-edge cybersecurity projects (threat hunting, red teaming, SOC automation).
Training & certifications support β CISSP, CEH, GCFA, GCTI, OSCP, cloud security certs (AWS/Azure/GCP).
Clear path to move into Senior Threat Hunter, Threat Intelligence Lead, Security Architect, or CISO track.
Opportunities to collaborate with global cyber defense teams.