Careers at Charles Schwab
Sr Manager Security Analytics & Operations Senior (Cyber Threat Intel Analyst)
Your opportunity
At Charles Schwab, our purpose is simple: we champion client’s goals with passion and integrity. Guided by honesty, mutual respect and a commitment to doing what’s right, we bring innovation, education, and service together to help shape financial futures. Our people are the foundation of our success – they approach their work with curiosity and collaboration, coming together to create solutions that make a meaningful impact for clients and communities. As we expand into India, we are bringing this same culture of inclusion, learning, and opportunity to new talent. Joining us means becoming part of a global team where your work matters and your future can take shape.
Our Hyderabad location is central to Schwab’s growth, bringing together talented people and technology to drive innovation, scale and efficiency. Here, you will work alongside teams who create solutions that support millions of clients every day. The work you do is more than daily operations – it’s a chance to experiment, learn, and build within a values-driven, supportive environment. This is a unique opportunity to be part of our early growth phase and shape something new, backed by the stability and strength of a Fortune 500 company. Your impact begins on day one, and your contributions will help define our future in the region.
The Cybersecurity Threat Intelligence Analyst is responsible for identifying, analyzing, and communicating cyber threats that could impact the organization's people, assets, operations, and customers. This role collects and analyzes strategic, operational, and tactical threat intelligence from internal and external sources to provide actionable intelligence that enables proactive defense. The analyst works closely with Security Operations Center (SOC), Incident Response, Threat Hunting, Vulnerability Management, Attack Surface Management, Digital Risk Protection, Fraud, and executive leadership to identify emerging threats, improve detection capabilities, reduce organizational risk, and support informed security decisions
Key Responsibilities
- Cyber Threat Intelligence
Collect, analyze, and disseminate actionable cyber threat intelligence from commercial, open-source, government, and industry intelligence feeds.
Monitor threat actor activity, malware campaigns, ransomware operations, vulnerabilities, and geopolitical events that may impact the organization.
Produce strategic, operational, and tactical intelligence reports for technical and executive audiences.
Maintain awareness of adversary tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework.
Identify indicators of compromise (IOCs), indicators of attack (IOAs), and behavioral analytics to improve detection capabilities.
Develop intelligence requirements and prioritize collection efforts based on organizational risk.
Perform attribution analysis on threat actors and campaigns where appropriate.
Maintain threat profiles, intelligence repositories, and knowledge bases. - Threat Hunting
Conduct proactive threat hunting across enterprise networks, cloud environments, endpoints, and identity platforms.
Develop and execute hypothesis-driven threat hunts based on intelligence reporting and adversary behaviors.
Identify previously undetected malicious activity using endpoint, network, identity, cloud, and log data.
Create new detection logic and use cases for SIEM, EDR, NDR, and cloud security platforms.
Validate detection coverage against MITRE ATT&CK techniques.
Collaborate with Incident Response teams during investigations and major security incidents.
Recommend improvements to detection engineering and monitoring capabilities based on hunt findings. - Digital Risk Protection
Monitor external digital assets for potential security risks affecting the organization's brand and reputation.
Identify phishing domains, typosquatting, brand impersonation, executive impersonation, and fraudulent websites.
Monitor dark web marketplaces, underground forums, messaging platforms, and criminal communities for emerging threats targeting the organization.
Identify exposed credentials, data leaks, compromised accounts, and unauthorized disclosures.
Coordinate takedown efforts for malicious domains, phishing campaigns, and fraudulent content.
Monitor social media and public platforms for cyber threats, disinformation campaigns, and brand abuse.
Assess third-party and supply chain cyber risks through external intelligence. - Collaboration
Partner with SOC analysts to improve detection and response capabilities.
Support Incident Response with intelligence during active investigations.
Collaborate with Vulnerability Management to prioritize remediation based on active exploitation.
Work with Attack Surface Management teams to identify externally exposed assets and emerging risks.
Brief leadership on emerging cyber threats and organizational risk.
Participate in tabletop exercises and incident simulations.
What you have
Required Qualifications:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Intelligence Studies, or related field (or equivalent experience).
- 7+ years of experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related cybersecurity disciplines.
- Experience analyzing sophisticated cyber adversaries including nation-state, ransomware, financially motivated, and insider threats.
- Strong understanding of the cyber kill chain and MITRE ATT&CK framework.
- Experience with SIEM platforms such as Google SecOps, Splunk, Microsoft Sentinel, or QRadar.
- Experience with EDR/XDR platforms such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or VMware Carbon Black.
- Experience working with threat intelligence platforms (TIPs).
- Experience analyzing malware, phishing campaigns, vulnerabilities, and indicators of compromise.
- Familiarity with cloud security across Microsoft Azure, AWS, and Google Cloud Platform.
Preferred Qualifications
- Experience with Threat Intelligence Platforms (TIPs) such as Recorded Future, ThreatConnect, MISP, Anomali, or EclecticIQ.
- Experience with Digital Risk Protection platforms.
- Experience monitoring the dark web and cybercriminal communities.
- Experience with SOAR automation platforms.
- Familiarity with Attack Surface Management technologies.
- Knowledge of intelligence lifecycle methodologies.
- Experience supporting regulated industries such as financial services, healthcare, or government
What’s in it for you
At Schwab India, you’re empowered to shape your future. We support your growth through meaningful work, continuous learning, and a culture rooted in trust and collaboration – so you can build the skills to make a lasting impact. Our benefits are designed to care for your wellbeing, your family, and your long-term financial security.
Our base benefits, wellbeing, and total rewards include:
- Competitive compensation and retirement programs including Employee Provident Fund (EPF), Gratuity, and optional National Pension System (NPS) contributions
- Robust Paid Time Off, including annual/privilege leave, sick and casual leave, public holidays, maternity/paternity leave, and more
- Education assistance for continued learning to help you grow
- Comprehensive medical insurance with Outpatient Department (OPD) services, including vaccination, pharmacy, dental, and vision coverage
- Annual reimbursement for health check-ups and mental health support through our Employee Assistance Program (EAP)
- Childcare (creche) reimbursement for eligible employees
- Transportation and meal benefits that support your day-to-day work
- Group life, personal accident, and critical illness insurance
Eligible Schwabbies receive
-
Medical, dental & vision benefits
-
Retirement programs & gratuity
-
Education assistance to keep developing your career
-
Childcare (creche) reimbursement & adoption/family building benefits
-
Transportation & meal benefits