Cyber Intelligence Analyst jobs in Delhi at CryptoMize are open on a rolling, always-hiring basis. This is a full-time, permanent position with immediate joining, sitting inside the cybersecurity and intelligence cells that power the S3-SENTINEL and CLAIRVOYANCE CX platforms for political, healthcare, and enterprise clients across 18 countries. The senior analyst owns the threat-intel workstream for one or two engagements end-to-end — from pipeline maintenance to client-brief delivery — and the same operational model applies as every other cell: capacity is hired ahead of the next engagement, not after. Below is the complete job description, the responsibilities you will own from day one, the requirements, the seniority path, and the selection process. Experienced analysts who want their work to mean something — IOCs that flowed into a client briefing, threat profiles that shaped a political engagement — should read to the end.
LOCATION New Delhi (HQ)
EMPLOYMENT Full-time · Permanent
AVAILABILITY Immediate · Rolling intake
COMPENSATION Discussed at screening
TRACKS ON THIS DESK35
CRAFT SKILLS NAMED13
TOOLS & SYSTEMS5
PATH STAGES4
01
01The actual work
What will you actually do as a Cyber Intelligence Analyst at CryptoMize?
01
Own the threat-intel workstream for one or two live client engagements — pipeline maintenance, IOC correlation, threat-actor profiling, and client-brief delivery
02
Set and maintain the cell’s credibility-scoring model — the discipline that separates real threats from noise across the client portfolio
03
Design the cell’s collection architecture for new engagements — feeds, OSINT coverage, dark-web monitors, and the bespoke tooling the engagement demands
04
Deliver the recurring threat products: daily situational reports, weekly cross-cell reviews, and quarter-scale threat-landscape narratives for client leadership
05
Mentor the analyst interns attached to your engagements — intern-to-analyst conversion is a hiring channel the cell directly strengthens
06
Sit in client briefings as the threat voice — when a client asks "is this real or noise," you answer with the IOC trail and the source stack
07
Work at the intelligence center of a portfolio that covers 18 countries, including political-campaign threats, healthcare-sector incidents, and brand-impersonation events — your analyst discipline becomes part of the engagement record the cell carries forward
ROLE RESPONSIBILITIES
As a Cyber Intelligence Analyst at CryptoMize you will own the threat-intel workstream for live client engagements end-to-end — pipeline maintenance, IOC correlation, threat-actor profiling, and client-brief delivery. The cell applies the same quality discipline as the analytics and engineering cells: every finding that goes to a client must be reconstructable line by line, and the credibility-scoring model is the discipline that makes that possible.
Senior analysts also carry the institution’s response posture — when a client engagement escalates, the senior is the cell’s point of accountability for the threat picture, the IOC trail, and the briefing that follows. The cell runs the same operational model as every other CryptoMize cell: capacity is hired ahead of the next engagement, not after, and the work that ships under the senior’s name in the program is the work that decides the next offer.
The cyber intelligence analyst review cycle records terminology discipline for Cyber Intelligence Analyst seats — in every review packet
02
02Capability profile
What skills and tools does a Cyber Intelligence Analyst need?
astro-island,astro-slot,astro-static-slot{display:contents}
Craft skills13 Tools & systems5 Offer standards4
Senior threat-actor profiling — TTPs, infrastructure, motivations, the analyst mindset that ties indicators to actor-level understanding at scaleMISP operations — feed integration, galaxy-cluster maintenance, correlation-engine tuning, the discipline of running MISP as a production tool not a toyOSINT collection discipline — sourcing, verification, trail-building, the rigor that lets a finding be re-verified months later by a different analystReporting at the senior level — short situational reports the strategist takes to clients unchanged, longer-form threat assessments that become part of the engagement portfolioIndicator correlation at scale — pivoting across feeds, spotting the same infrastructure or persona across unrelated sources, the judgment to know when correlation is signal vs noiseTool fluency — Python and SQL for pivot queries, regex for IOC extraction, REST API for tool integration, the discipline of choosing the right tool for each questionDark-web monitoring — Tor browser hygiene, hidden-service tracking, OPSEC-aware collection, the discipline of never breaking your own coverDisinformation analysis — narrative tracing, amplification-path mapping, the analyst skill of identifying bot vs organic origin in a contested conversationDiscipline of NDA-grade client material — every indicator logged, every source traceable, every engagement flag-time recordedBilingual source handling where the engagement crosses languages (the cell works with regional translators when sources are not in English)Client-facing communication — defending a finding under skeptical questioning, walking a client through the IOC trail in a briefingMentorship — the discipline of teaching analyst interns the way the senior analyst was taught, with the same review cadence and the same expectationsDomain curiosity — political, healthcare, enterprise, the subject changes weekly and the analyst adapts
MISP (Malware Information Sharing Platform) — the cell’s primary IOC store and correlation engine, with the full operational stackMISP galaxy cluster model for threat-actor and campaign-taxonomy classificationPython 3.11 + pandas for IOC aggregation, pivot queries, and report automationMISP-feed integration — STIX/TAXII import pipelines and the feed-credibility scoring modelOSINT framework — Maltego for link analysis, Shodan-class exposure scanning, the cell’s custom monitoring stack
Depth of demonstrated skill in the specific role disciplineClassification and scope of the client engagement the role supportsUrgency and time-sensitivity of active project requirementsTrack record built across CryptoMize engagements
Also known as: cyber intelligence analyst jobs · threat intelligence jobs · cyber threat analyst jobs · threat intel vacancy
03
03Seniority ladder
Cyber Intelligence Analyst — seniority path at CryptoMize
Analysts advance by the quality of the threat picture they produce, not tenure. The ladder below is how the cyber intelligence cell is actually organized.
Cyber Intelligence Analyst
Owns the IOC pipeline and engagement threat products for one or two live client engagements. The execution backbone of the cell.
1/4
Senior Cyber Intelligence Analyst
Designs the cell’s collection architecture, leads threat-actor deep-dive work, signs off on client-brief threat content, and mentors the cell’s analyst interns.
2/4
Cyber Intelligence Lead
Runs the cell — staffing, methodology, and final accountability for every threat brief that reaches a client. Sets the credibility-scoring model the entire cell lives by.
3/4
Intelligence Strategist
The crossover track: cyber intelligence leaders who grow into engagement strategy, translating threat work into the counsel clients act on. The cell’s pipeline produces them.
4/4
04
04The engagement surface
CryptoMize work a Cyber Intelligence Analyst touches
Every role plugs into live engagements across the five Penta-P domains — these are the services your work feeds.
Cyber Intelligence Analyst · Job Opening
This seat plugs into 5 live CryptoMize services across the five Penta-P domains — the work below is where yours lands.
5 SERVICESPENTA-P
OSINT
Strategic Intelligence
Predictive Intelligence
Cybersecurity
Threat Analysis
WHAT DOES CYBER INTELLIGENCE ANALYST COMPENSATION DEPEND ON?
Compensation is discussed during screening — never a fixed public figure, because it varies per person and per engagement. It depends on:
# OFFER CONSTRUCTION FACTOR
01 Depth of demonstrated skill in the specific role discipline
02 Classification and scope of the client engagement the role supports
03 Urgency and time-sensitivity of active project requirements
04 Track record built across CryptoMize engagements