Posted 30 August, 2026
Threat hunting
Tata Consultancy Services
VasanthaNagar, KA, IN
Full Time
Reference: 9d6c599580414745
Job Description
Company: TCS
\nSkill: Threat Hunting / Modeling
\nExperience: 6 to 15 Years
\nLocation: Bengaluru
\nInterview Mode: Face to Face (Walkin) Interview
\nDate: 29th Aug 2026(Saturday)
\nJob description:
\nProactive Threat Hunting
\n- \n
- Conduct hypothesis-driven and data-driven threat hunting across endpoints, networks, cloud, and identity systems. \n
- Identify anomalous behaviors, TTPs, and indicators of compromise using MITRE ATT&CK and threat intel sources. \n
- Perform deep-dive investigation into suspicious activities, lateral movement, privilege escalation, and persistence techniques. \n
Analysis & Detection Engineering
\n- \n
- Analyze logs, telemetry, and events from SIEM, EDR, XDR, NDR, Firewall, and Cloud security tools. \n
- Develop new detection rules, signatures, and behavioral analytics to improve SOC detection capabilities. \n
- Validate, tune, and optimize detection logic to reduce false positives. \n
Threat Intelligence Integration
\n- \n
- Consume threat intel reports, IOCs, malware analysis feeds, and emerging threat trends. \n
- Translate threat intel into actionable hunting queries, playbooks, and detection rules. \n
Incident Response Support
\n- \n
- Collaborate with SOC Analysts and Incident Response teams during investigations. \n
- Provide recommendations for containment, remediation, and hardening. \n
- Perform root-cause analysis on identified threats. \n
Reporting & Documentation
\n- \n
- Prepare detailed hunt reports, findings, and risk insights for leadership. \n
- Document new hunting methodologies, playbooks, and detection logic. \n
Required Skills and Qualifications
\n- \n
- Experience in Threat Hunting, SOC, Incident Response, or Cyber Defense. \n
- Strong understanding of: \n
- MITRE ATT&CK Framework. \n
- Windows/Linux internals. \n
- Network protocols (TCP/IP, DNS, HTTP, etc.). \n
- Cloud platforms (AWS, Azure, GCP). \n
- Hands-on experience with SIEM/EDR/XDR tools such as: \n
- Splunk, Sentinel, QRadar, ELK. \n
- CrowdStrike, Defender ATP, Tanium, Carbon Black, Palo Alto Cortex. \n
- Ability to write complex queries using: \n
- KQL, SQL, SPL, YARA, Sigma rules. \n
- Experience analyzing malicious files, scripts, and techniques used by APT groups. \n
- Strong analytical, investigative, and problemsolving skills. \n