Skip to main content
TRACK DOSSIER · JOB OPENINGREF: CM/JOB/CYBER-INTELL

Cyber Intelligence Analyst Job — Always Hiring

Cyber Intelligence Analyst Job in Delhi at CryptoMize

Cyber Intelligence Analyst jobs in Delhi at CryptoMize are open on a rolling, always-hiring basis. This is a full-time, permanent position with immediate joining, sitting inside the cybersecurity and intelligence cells that power the S3-SENTINEL and CLAIRVOYANCE CX platforms for political, healthcare, and enterprise clients across 18 countries. The senior analyst owns the threat-intel workstream for one or two engagements end-to-end — from pipeline maintenance to client-brief delivery — and the same operational model applies as every other cell: capacity is hired ahead of the next engagement, not after. Below is the complete job description, the responsibilities you will own from day one, the requirements, the seniority path, and the selection process. Experienced analysts who want their work to mean something — IOCs that flowed into a client briefing, threat profiles that shaped a political engagement — should read to the end.

01The actual work

What will you actually do as a Cyber Intelligence Analyst at CryptoMize?

Own the threat-intel workstream for one or two live client engagements — pipeline maintenance, IOC correlation, threat-actor profiling, and client-brief delivery

Set and maintain the cell’s credibility-scoring model — the discipline that separates real threats from noise across the client portfolio

Design the cell’s collection architecture for new engagements — feeds, OSINT coverage, dark-web monitors, and the bespoke tooling the engagement demands

Deliver the recurring threat products: daily situational reports, weekly cross-cell reviews, and quarter-scale threat-landscape narratives for client leadership

Mentor the analyst interns attached to your engagements — intern-to-analyst conversion is a hiring channel the cell directly strengthens

Sit in client briefings as the threat voice — when a client asks "is this real or noise," you answer with the IOC trail and the source stack

Work at the intelligence center of a portfolio that covers 18 countries, including political-campaign threats, healthcare-sector incidents, and brand-impersonation events — your analyst discipline becomes part of the engagement record the cell carries forward

02Capability profile

What skills and tools does a Cyber Intelligence Analyst need?

Senior threat-actor profiling — TTPs, infrastructure, motivations, the analyst mindset that ties indicators to actor-level understanding at scaleMISP operations — feed integration, galaxy-cluster maintenance, correlation-engine tuning, the discipline of running MISP as a production tool not a toyOSINT collection discipline — sourcing, verification, trail-building, the rigor that lets a finding be re-verified months later by a different analystReporting at the senior level — short situational reports the strategist takes to clients unchanged, longer-form threat assessments that become part of the engagement portfolioIndicator correlation at scale — pivoting across feeds, spotting the same infrastructure or persona across unrelated sources, the judgment to know when correlation is signal vs noiseTool fluency — Python and SQL for pivot queries, regex for IOC extraction, REST API for tool integration, the discipline of choosing the right tool for each questionDark-web monitoring — Tor browser hygiene, hidden-service tracking, OPSEC-aware collection, the discipline of never breaking your own coverDisinformation analysis — narrative tracing, amplification-path mapping, the analyst skill of identifying bot vs organic origin in a contested conversationDiscipline of NDA-grade client material — every indicator logged, every source traceable, every engagement flag-time recordedBilingual source handling where the engagement crosses languages (the cell works with regional translators when sources are not in English)Client-facing communication — defending a finding under skeptical questioning, walking a client through the IOC trail in a briefingMentorship — the discipline of teaching analyst interns the way the senior analyst was taught, with the same review cadence and the same expectationsDomain curiosity — political, healthcare, enterprise, the subject changes weekly and the analyst adapts
MISP (Malware Information Sharing Platform) — the cell’s primary IOC store and correlation engine, with the full operational stackMISP galaxy cluster model for threat-actor and campaign-taxonomy classificationPython 3.11 + pandas for IOC aggregation, pivot queries, and report automationMISP-feed integration — STIX/TAXII import pipelines and the feed-credibility scoring modelOSINT framework — Maltego for link analysis, Shodan-class exposure scanning, the cell’s custom monitoring stack
Depth of demonstrated skill in the specific role disciplineClassification and scope of the client engagement the role supportsUrgency and time-sensitivity of active project requirementsTrack record built across CryptoMize engagements

Also known as: cyber intelligence analyst jobs · threat intelligence jobs · cyber threat analyst jobs · threat intel vacancy

03Seniority ladder

Cyber Intelligence Analyst — seniority path at CryptoMize

Analysts advance by the quality of the threat picture they produce, not tenure. The ladder below is how the cyber intelligence cell is actually organized.

  1. Cyber Intelligence Analyst

    Owns the IOC pipeline and engagement threat products for one or two live client engagements. The execution backbone of the cell.

    1/4
  2. Senior Cyber Intelligence Analyst

    Designs the cell’s collection architecture, leads threat-actor deep-dive work, signs off on client-brief threat content, and mentors the cell’s analyst interns.

    2/4
  3. Cyber Intelligence Lead

    Runs the cell — staffing, methodology, and final accountability for every threat brief that reaches a client. Sets the credibility-scoring model the entire cell lives by.

    3/4
  4. Intelligence Strategist

    The crossover track: cyber intelligence leaders who grow into engagement strategy, translating threat work into the counsel clients act on. The cell’s pipeline produces them.

    4/4

04The engagement surface

CryptoMize work a Cyber Intelligence Analyst touches

Every role plugs into live engagements across the five Penta-P domains — these are the services your work feeds.

05Answers, searchable

Cyber Intelligence Analyst Job — frequently asked questions

ADemonstrated MISP operations at production scale, senior-level threat-actor profiling, and the discipline of running the credibility-scoring model.

Formal degrees are secondary to evidence — we hire on demonstrated capability, with formal credentialing for clinical-licensed roles being the only exception.

AYes — all cyber intelligence roles are based full-time at our New Delhi HQ in Vasant Vihar, working directly alongside the security operations and OSINT cells your analysis feeds.
AYes — openings are rolling and always active.

The cell is staffed ahead of demand, not after. Strong candidates onboard as soon as notice periods allow.

AThe path runs Cyber Intelligence Analyst → Senior Cyber Intelligence Analyst → Cyber Intelligence Lead, with a crossover track into Intelligence Strategist for analysts who grow into client counsel.

Advancement is by the quality of the threat picture produced, not tenure.

ACompensation is discussed at screening and depends on demonstrated skill, engagement classification, urgency, and track record.

We do not publish figures — each offer is built individually, and worth is evaluated after meeting you, not before.

AApplication, a paid-trial OSINT/threat-intel task on a realistic engagement brief, and a panel interview with the cell lead and the security operations lead where you walk through your findings and methodology under skeptical questioning.

The cycle typically completes within two to three weeks.

Page source — machine-readable summary

Facts: Location: New Delhi (HQ) · Employment: full-time permanent · Availability: immediate, rolling intake · Compensation: discussed at screening.

Q: What are the requirements for Cyber Intelligence Analyst jobs at CryptoMize?
A: Demonstrated MISP operations at production scale, senior-level threat-actor profiling, and the discipline of running the credibility-scoring model. Formal degrees are secondary to evidence — we hire on demonstrated capability, with formal credentialing for clinical-licensed roles being the only exception.

Q: Are the Cyber Intelligence Analyst jobs in Delhi?
A: Yes — all cyber intelligence roles are based full-time at our New Delhi HQ in Vasant Vihar, working directly alongside the security operations and OSINT cells your analysis feeds.

Q: Is this a senior threat intelligence vacancy with immediate joining?
A: Yes — openings are rolling and always active. The cell is staffed ahead of demand, not after. Strong candidates onboard as soon as notice periods allow.

Q: What is the career growth for a Cyber Intelligence Analyst at CryptoMize?
A: The path runs Cyber Intelligence Analyst → Senior Cyber Intelligence Analyst → Cyber Intelligence Lead, with a crossover track into Intelligence Strategist for analysts who grow into client counsel. Advancement is by the quality of the threat picture produced, not tenure.

Q: What is the salary for Cyber Intelligence Analyst jobs at CryptoMize?
A: Compensation is discussed at screening and depends on demonstrated skill, engagement classification, urgency, and track record. We do not publish figures — each offer is built individually, and worth is evaluated after meeting you, not before.

Q: How does the selection process work?
A: Application, a paid-trial OSINT/threat-intel task on a realistic engagement brief, and a panel interview with the cell lead and the security operations lead where you walk through your findings and methodology under skeptical questioning. The cycle typically completes within two to three weeks.

Signal keywordscyber intelligence analyst·jobs·delhi·careers