Information & Cybersec Lead

Apply Now โ†—
๐Ÿ“ Gautam Buddha Nagar, India

About this role

Job Summary

Location: Noida/Bangalore / Hybrid

Experience: 8+ Years in Cyber Security with proven Threat Hunting experience

Employment Type: Full-Time

Role Overview

We are seeking a highly skilled Senior Threat Hunter to lead proactive threat hunting initiatives and detect advanced cyber threats that evade traditional security controls. The ideal candidate will possess deep expertise in adversary tactics, threat intelligence, detection engineering, and incident response, with the ability to translate complex security findings into actionable business insights. This role acts as a Tier-4 escalation point, supports SOC maturity, and drives continuous improvement of detection and response capabilities across on-prem, cloud, and hybrid environments.

Key Responsibilities

Threat Hunting & Adversary Detection

  • Lead hypothesis-driven threat hunting across endpoint, network, cloud, identity, and SaaS platforms.
  • Detect advanced threats including APTs, insider threats, credential abuse, lateral movement, and fileless attacks.
  • Analyze datasets from EDR/XDR, SIEM, NDR, email, identity, and cloud logs.
  • Map findings to MITRE ATT&CK framework and attacker TTPs.

Detection Engineering & Automation

  • Recommend , tune, and optimize detection rules in SIEM and EDR platforms.
  • Translate hunt results into reusable detection use cases.
  • Automate workflows using KQL, SPL, Python, PowerShell, and SOAR.
  • Reduce false positives and improve signal-to-noise ratio.

Threat Intelligence & Research

  • Consume strategic and tactical threat intelligence.
  • Track emerging threats and attacker techniques.
  • Participate in purple team exercises and adversary simulations.

Incident Response & Advanced Investigations

  • Serve as escalation point for complex security incidents.
  • Support containment, eradication, and recovery activities.
  • Perform root cause analysis and post-incident reporting.

Cloud & Identity Security Hunting

  • Conduct threat hunting in Microsoft 365, Azure, AWS, and other cloud environments.
  • Detect OAuth abuse, MFA bypass, token theft, and persistence mechanisms.

Reporting, Metrics & Leadership Communication

  • Prepare executive-level threat hunting and risk reports.
  • Track metrics such as MTTD, dwell time, and ATT&CK coverage.

Mentorship & Program Maturity

  • Mentor junior threat hunters , SOC analysts and Threat intel team .
  • Develop hunt playbooks and training materials.
  • Collaborate with Red Team, IR, GRC, and IT teams.

Required Skills & Qualifications

Technical Skills

  • Experience with SIEM/SOAR platforms (Microsoft Sentinel, Splunk, QRadar)
  • Hands-on with EDR/XDR solutions (Defender, CrowdStrike, SentinelOne and Splunk)
  • Strong understanding of MITRE ATT&CK framework
  • Proficiency in KQL, SPL, Python, and PowerShell
  • Endpoint, network, and cloud forensics
  • Cloud security expertise (Azure/AWS/GCP)

Professional Skills

  • Strong analytical and problem-solving skills
  • Excellent written and verbal communication
  • Ability to explain complex threats to non-technical audiences
  • Ability to work independently under pressure and ready for 24x7 support.

Preferred Certifications

  • GCED, GCTI, GCIA, GMON
  • CISSP / CISM
  • Microsoft Security Certifications
  • Cloud Security Certifications (Azure/AWS)

Key Responsibilities

Key Responsibilities

Threat Hunting & Adversary Detection

  • Lead hypothesis-driven threat hunting across endpoint, network, cloud, identity, and SaaS platforms.
  • Detect advanced threats including APTs, insider threats, credential abuse, lateral movement, and fileless attacks.
  • Analyze datasets from EDR/XDR, SIEM, NDR, email, identity, and cloud logs.
  • Map findings to MITRE ATT&CK framework and attacker TTPs.

Detection Engineering & Automation

  • Recommend , tune, and optimize detection rules in SIEM and EDR platforms.
  • Translate hunt results into reusable detection use cases.
  • Automate workflows using KQL, SPL, Python, PowerShell, and SOAR.
  • Reduce false positives and improve signal-to-noise ratio.

Threat Intelligence & Research

  • Consume strategic and tactical threat intelligence.
  • Track emerging threats and attacker techniques.
  • Participate in purple team exercises and adversary simulations.

Incident Response & Advanced Investigations

  • Serve as escalation point for complex security incidents.
  • Support containment, eradication, and recovery activities.
  • Perform root cause analysis and post-incident reporting.

Cloud & Identity Security Hunting

  • Conduct threat hunting in Microsoft 365, Azure, AWS, and other cloud environments.
  • Detect OAuth abuse, MFA bypass, token theft, and persistence mechanisms.

Reporting, Metrics & Leadership Communication

  • Prepare executive-level threat hunting and risk reports.
  • Track metrics such as MTTD, dwell time, and ATT&CK coverage.

Mentorship & Program Maturity

  • Mentor junior threat hunters , SOC analysts and Threat intel team .
  • Develop hunt playbooks and training materials.
  • Collaborate with Red Team, IR, GRC, and IT teams.

Skill Requirements

Other Requirements

Frequently Asked Questions

Is the salary disclosed for the Information & Cybersec Lead position at HCLTech?
The salary for this Information & Cybersec Lead role at HCLTech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Information & Cybersec Lead position at HCLTech located?
This Information & Cybersec Lead role at HCLTech is based in Gautam Buddha Nagar, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
How do I apply for the Information & Cybersec Lead position at HCLTech?
Click the "Apply Now" button on this page. You will be redirected to HCLTech's official application portal hosted on successfactors where you can submit your application directly.
When was the Information & Cybersec Lead job at HCLTech posted?
This Information & Cybersec Lead position at HCLTech was posted on Aug 27, 2026. Apply as soon as possible โ€” early applications are often reviewed first.
Information & Cybersec Lead
HCLTech
Apply for this role โ†—

You'll be redirected to HCLTech's official application page on successfactors.