Job Description
Role Summary:
The L3 Threat Hunting, Red Team & Threat Modeling Lead owns the advanced hunting and proactive security assessment capability, driving standard and custom threat hunts, governing the quality of executive/detailed reporting, and leading threat modeling assessments using automated tooling such as ThreatModeler. This role provides technical leadership and escalation ownership, ensuring hunts and threat models produce measurable risk reduction outcomes and that red team insights translate into prioritized improvements
In Scope Tools & Skills
• Threat Hunting (TIP-driven): Feed recommendations, execution leadership for standard/custom hunts, executive + technical reporting
• Threat Modeling (Automated): ThreatModeler-based assessments (and governance of templates/patterns)
• Red Teaming (Advanced Adversary Simulation): Lead/support planning and execution oversight, ensuring safe operations and clear outputs
• Tuskira (Knowledge): Familiarity/working knowledge to leverage posture/exposure insights to prioritize hunts and validate control gaps (desired; not stated in SOW)
Key Responsibilities (L3)
1) Threat Hunting Leadership (Standard + Custom Hunts)
• Lead the execution and continuous improvement of standard threat analysis and hunts and custom hunts, ensuring repeatability and quality.
• Drive intelligence-led hunting by recommending threat intelligence inputs that best support hunt goals and operational priorities.
• Provide executive and detailed threat analysis and hunt reports with clear risk, impact, and recommended actions.
2) Threat Modeling Program (ThreatModeler)
• Own the approach and quality bar for threat modeling assessments using ThreatModeler, including consistent documentation and reusable patterns.
• Guide assessments for defined projects/apps and ensure findings are actionable, prioritized, and aligned to risk treatment practices.
• Drive standardization: templates, threat libraries, and control mapping to accelerate future assessments.
3) Red Teaming / Adversary Simulation Oversight
• Lead/oversee advanced adversary simulation (red team) activities, including planning support, risk controls, reporting expectations, and follow-through.
• Ensure red team findings translate into concrete improvements: hunt hypotheses, detection gaps, and prioritized remediation recommendations.
4) Exposure & Posture Insight
• Use exposure/posture insights (e.g., from Tuskira) to prioritize hunts, validate systemic control gaps, and inform improvement roadmaps.
5) Governance, Mentoring & Continuous Improvement
• Provide L3 escalation support for complex hunts, ambiguous findings, and high-risk threat model outputs.
• Mentor L2 analysts, review hunt quality, and strengthen playbooks/runbooks based on recurring themes.
Required Skills & Experience
• 8–12+ years in threat hunting, incident response, adversary simulation, or advanced security assessment roles
• Proven capability delivering both technical deep dives and executive-ready reporting for hunts and assessments
• Hands-on leadership or SME-level experience with ThreatModeler (or equivalent) threat modeling approach
• Strong experience with adversary simulation/red teaming concepts and translating results into defensive improvements
Preferred
• Familiarity with Tuskira and exposure-based prioritization approaches (desired)
͏
Areas of responsibility
Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards.
Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption
Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.
Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks.
Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance."
Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.
͏
͏
͏
Experience: 5-8 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.