Dark Web Researcher – Threat Intelligence
Bengaluru, Karnataka
Cyderes
Cyderes offers tech-enabled managed security services for real-time risk and compliance management in modern enterprises.
Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and access management, and professional services designed to manage the cybersecurity risks of enterprise clients. We specialize in multi-technology, complex environments with the in speed and agility needed to tackle the most advanced cyber threats. We leverage our global scale and decades of experience to accelerate our clients’ cyber outcomes through a full lifecycle of cybersecurity services. We are a global company with operating centers in the United States, Canada, the United Kingdom, and India.
About the Job:We are seeking a skilled and driven Dark Web Researcher to join our Threat Intelligence team. In this role, you will leverage the CyberInt platform and a suite of dark web and threat actor monitoring tools to proactively identify emerging risks, data exposures, and threat activity targeting our clients across industries such as healthcare, education, and finance. You will play a key role in brand protection, leaked credential discovery, social media risk analysis, and monitoring for phishing domains and attack surface exposures. Your research will extend to initial access brokers (IABs) and dark web chatter that could signal intent or active targeting of our clients. You'll also support our threat hunting operations by creating queries and validating whether observed risks have materialized into active threats
Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.
About the Job:We are seeking a skilled and driven Dark Web Researcher to join our Threat Intelligence team. In this role, you will leverage the CyberInt platform and a suite of dark web and threat actor monitoring tools to proactively identify emerging risks, data exposures, and threat activity targeting our clients across industries such as healthcare, education, and finance. You will play a key role in brand protection, leaked credential discovery, social media risk analysis, and monitoring for phishing domains and attack surface exposures. Your research will extend to initial access brokers (IABs) and dark web chatter that could signal intent or active targeting of our clients. You'll also support our threat hunting operations by creating queries and validating whether observed risks have materialized into active threats
Responsibilities:
- Monitor and analyze dark web forums, marketplaces, Telegram channels, and leak sites using CyberInt and other OSINT/darknet tools.
- Identify and assess: Leaked credentials and sensitive dataPhishing domains and impersonation sitesThreat actor discussions mentioning client brands or environmentsSale of access by Initial Access Brokers (IABs)
- Track emerging threat actor TTPs, malware families, ransomware groups, and underground ecosystem trends.
- Correlate dark web findings with client infrastructure and attack surface to assess risk and exposure.
- Develop threat hunting queries (e.g., using SIEM/EDR platforms) based on dark web discoveries to determine active targeting or compromise
- Create concise, actionable intelligence reports to communicate risks to internal and client stakeholders.
- Assist in incident enrichment, providing dark web context and attribution to ongoing investigations or IR cases
- Stay current on major malware and ransomware variants, and support attribution or profiling work when actors reference client asset
Requirements:
- 3+ years of experience in threat intelligence, dark web research, or cybercrime investigations
- Hands-on experience with CyberInt or similar dark web intelligence platforms (e.g., Flashpoint, Cybersixgill, KELA, Recorded Future)
- Strong OSINT skills and familiarity with darknet environments and tradecraft
- Understanding of malware families, ransomware operations, and threat actor group dynamics
- Experience with brand protection monitoring, phishing detection, and social media threat analysis
- Ability to write clear, intelligence-driven reports for technical and executive audiences
- Familiarity with attack surface management and common enterprise exposure risk
Preferred Qualifications:
- Experience tracking Initial Access Brokers (IABs) and ransomware affiliates
- Knowledge of security risks specific to healthcare, education, and financial sectors
- Basic scripting or automation skills (Python, Regex, etc.) for hunting or parsing data
- Experience writing threat hunting queries (e.g., Splunk, Elastic, Sigma rules)
- Previous consulting or client-facing experience in intelligence reporting or briefings
Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
2
0
0
Categories:
Research Jobs
Threat Intel Jobs
Tags: Automation Cyber crime Cyber defense EDR Finance IAM Malware Monitoring OSINT Python Risk analysis Scripting SIEM Splunk Threat intelligence TTPs
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Systems Engineer jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSystems Administrator jobsSenior Cybersecurity Engineer jobsCybersecurity Editor jobsCybersecurity Content Editor jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsIT Security Analyst jobsSenior Network Security Engineer jobsChief Information Security Officer jobsSenior Information Security Engineer jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsIT Security Engineer jobsSecurity Specialist jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsCybersecurity Specialist jobsSenior IT Auditor jobsSenior Software Engineer jobs
SaaS jobsEncryption jobsTS/SCI jobsJava jobsCEH jobsSplunk jobsTop Secret jobsThreat detection jobsTerraform jobsIDS jobsSDLC jobsMalware jobsIPS jobsRMF jobsFinance jobsSQL jobsForensics jobsDocker jobsIntrusion detection jobsActive Directory jobsSOC 2 jobsCompTIA jobsOWASP jobsVPN jobsAnsible jobs
ITIL jobsClearance Required jobsTCP/IP jobsCRISC jobsGIAC jobsHIPAA jobsDoDD 8570 jobsIT infrastructure jobsMITRE ATT&CK jobsJira jobsOSCP jobsBanking jobsSOAR jobsData Analytics jobsSOX jobsIndustrial jobsDNS jobsZero Trust jobsCCSP jobsJavaScript jobsUNIX jobsGCIH jobsCISO jobsArtificial Intelligence jobsPolygraph jobs