About this role
Job Title: Lead CTI Analyst
Organization Name: NEC Corporation of India Ltd.
Location: Noida, Chennai, Bangalore
Reporting Relationship: Senior Technical Manager
Role Summary:
We are seeking a Lead CTI Analyst to work as a Cyber Threat Intelligence (CTI) domain SME supporting AI-driven automation of cybersecurity use cases. The role will focus on CTI data collection, analysis, curation, normalization, enrichment, and quality validation to build high-quality datasets and knowledge sources for AI automation, LLM/RAG solutions, and cybersecurity analytics. The role is for a Lead Engineer who will provide technical leadership, mentor and manage team members, guide solution design and implementation, and ensure timely delivery of project outcomes.
Job Description / Responsibilities:
- Act as a Cyber Threat Intelligence (CTI) domain SME for AI automation of cybersecurity use cases.
- Collect, analyze, validate, curate, and normalize CTI data from open-source, commercial, and internal sources to support AI automation.
- Apply CTI analysis frameworks such as the CTI lifecycle, Diamond Model, Cyber Kill Chain, and Analysis of Competing Hypotheses (ACH) to structure and assess intelligence.
- Perform MITRE ATT&CK mapping and maintain contextual relationships between threat actors, campaigns, malware, vulnerabilities, techniques, and indicators.
- Handle IoCs using industry best practices, including defanging, hash-type identification, contextual validation, deduplication, and false-positive avoidance.
- Work with TLP 2.0 and PAP markings and ensure appropriate handling and dissemination of CTI data.
- Create, validate, and enrich STIX 2.1 objects and support TAXII 2.1-based CTI exchange and ingestion workflows.
- Operate and manage CTI platforms such as MISP and OpenCTI, including data models, APIs, feed management, PyMISP, and GraphQL.
- Use CTI enrichment services such as VirusTotal, URLScan, AbuseIPDB, Shodan, Censys, OTX, Whois, and PassiveDNS to enrich and validate indicators and entities.
- Apply OSINT tradecraft and security fundamentals while maintaining appropriate operational security (OPSEC).
- Support the creation of high-quality, traceable, and reusable CTI datasets for LLM fine-tuning, RAG, automated analysis, and other AI-driven cybersecurity applications.
- Manage the team of junior analysts and provide technical guidance.
- Collaborate with cybersecurity, data, AI/ML, and engineering teams to translate CTI analyst knowledge into structured data, rules, prompts, evaluation datasets, and automation workflows.
- Stay current with emerging threats, vulnerabilities, threat actor activity, malware, and CTI analysis methodologies.
Communication and Documentation:
- Excellent written and oral communication, presentation, listening and interpersonal skills.
- Collaborating effectively with internal and external team.
- Excellent reporting, time management, analytical & communication skills.
Preferred Skills:
- Experience with commercial Cyber Threat Intelligence (CTI) platforms and vendors.
- Familiarity with detection rule standards such as YARA, Sigma, Snort, and Suricata.
- Exposure to AI/ML, LLM, RAG, data curation, or cybersecurity automation use cases.
- Surface-level malware analysis and DFIR fundamentals.
- Knowledge of cloud security concepts.
- Certifications such as GCTI, GCIH, GCFA, CTIA, eCTHPv2, OSCP, or equivalent would be good to have.
Qualifications and Technical Skills:
- 4-6 years of previous experience in Cyber Threat Intelligence, threat research, security analysis, or a related cybersecurity domain.
- Strong knowledge of CTI analysis frameworks including CTI lifecycle, Diamond Model, Cyber Kill Chain, and ACH.
- Hands-on experience with MITRE ATT&CK mapping, TLP 2.0/PAP marking, STIX 2.1/TAXII 2.1, and IoC handling best practices.
- Experience with OSINT tradecraft, security fundamentals, and OPSEC principles.
- Hands-on experience with MISP and/or OpenCTI, including data models, APIs, PyMISP, GraphQL, and feed management.
- Experience using CTI enrichment tools/services such as VirusTotal, URLScan, AbuseIPDB, Shodan, Censys, OTX, Whois, and PassiveDNS.
- Good understanding of detection content standards including YARA, Sigma, Snort, and Suricata.
- Python knowledge, preferably with libraries such as stix2, PyMISP, taxii2-client, and vt-py.
- Working knowledge of SQL and one or more security query/search languages such as KQL, SPL, or Elastic DSL.
- Strong analytical, troubleshooting, problem-solving, and data-curation skills.
Specialization Description
Performs assessments of systems and networks within the networking environment or enclave and identifies systems and networks that deviate from acceptable configurations, enclave policy, or local policy. Evaluates incident response procedures and capabilities. Exploits system and network vulnerabilities and misconfigurations for purposes of gathering data from target or adversary automated information systems or networks and to enable operations and intelligence collection capabilities. Leverages computer networks to disrupt, deny, degrade, or destroy information resident in computers and computer networks, or the computers and networks themselves.
Level Description
Senior level professional that applies advanced knowledge of job area typically obtained through advanced education and work experience. Works independently applying an advanced knowledge of a job area typically obtained through advanced education and work experience. Works to achieve results in a job area, overseeing and managing projects/ processes independently with limited supervision. Problems faced are difficult and are sometimes complex, though are routine. Coaching and reviewing the work of lower level professionals.
Headquartered in Japan, NEC is a leader in the integration of IT and network technologies. With over 123 years of expertise in providing solutions for empowering people, businesses, and society, NEC stands tall as a champion in enabling change and transformation across the globe. Present in India since 1950, NEC has been instrumental in burgeoning India’s digitization journey continually for the past 70 years.
NEC India has proved its commitment to orchestrating a bright future through its diverse businesses from Telecommunications to Public Safety, Logistics, Transportation, Retail, Finance, Unified Communication and IT platforms , serving across the public and private sectors. NEC India, through the deployment of cutting-edge technology, has been powering India in seminal ways, making lives easier, safer, and more productive for all.
With its Centre of Excellence for verticals like Analytics platform solutions, Big Data, Biometrics, Mobile and Retail , NEC India brings to the table, innovative, seamless solutions for India and across the world.
NEC India is headquartered in New Delhi and has its offices panned across the country. It has branches in Ahmedabad, Bengaluru, Chennai, Mumbai, Noida and Surat.
Specialties:
IT & Networking Solutions, Unified Communication Solutions, Safety and Security Solutions, Integrated Retail Solutions, Data Centre Solutions, Safe and Smart City Solutions, Transportation Solutions, SDN Solutions, Carrier Telecom Solutions, and Solutions for Society.
NEC Career Site - LinkedIn