Senior Cyber Threat Intelligence & Incident Response Specialist

Job Type:  Full Time
Category:  Technology & Digital Innovation

Overall Purpose of the Job

We are seeking a highly technical, hands-on cybersecurity professional to drive Threat Intelligence, Incident Response, and advanced threat detection. This role is suited for an experienced individual contributor who actively performs investigations, threat hunting, and security engineering, while contributing to continuous improvement of security controls.

As a senior technical individual contributor, the role is expected to take end-to-end technical ownership of the cybersecurity products and capabilities within its scope.

This role combines technical Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, and the ownership and continuous improvement of the security technologies required to support these capabilities.

The successful candidate is therefore also expected to manage the security technology lifecycle from identification of the requirement through to implementation, operational use, optimisation, renewal, replacement, and retirement; the individual is responsible for ensuring that the technology continues to meet the organisation’s technical and security requirements and for driving the relevant activities through to completion with the appropriate supporting functions.

Key Responsibilities

Threat Intelligence
•    Actively collect, analyse, and operationalise intelligence from OSINT, dark web, commercial feeds, and ISACs
•    Perform hands-on adversary tracking, campaign analysis, and TTP mapping (MITRE ATT&CK)
•    Translate intelligence into detection rules, hunting queries, and actionable use cases
•    Integrate intelligence into security tooling, including CrowdStrike, SIEM, and TIP platforms

Incident Response 
•    Lead and execute end-to-end incident response activities (triage, containment, eradication, recovery)
•    Perform hands-on investigations across endpoints, logs, network traffic, and cloud environments
•    Use EDR tools (e.g., CrowdStrike) for live response, forensic analysis, and threat hunting
•    Analyse malware behaviour, attacker persistence mechanisms, and lateral movement techniques
•    Produce detailed technical reports with clear root cause and remediation actions

Threat Hunting & Detection Engineering
•    Develop and execute proactive threat hunting across endpoint, identity, and cloud telemetry
•    Write and tune detection rules (SIEM, EDR, Sigma, KQL, Splunk, etc.)
•    Validate detections through simulation and adversary emulation
•    Continuously improve detection coverage based on intelligence and incident learnings

Cloud Security (Hands-On)
•    Investigate and respond to threats in AWS, Azure, and GCP environments
•    Analyse cloud logs (CloudTrail, Azure AD, GCP logs) for suspicious activity
•    Identify misconfigurations, privilege escalation paths, and identity-based attacks
•    Work directly with engineers to remediate security gaps

Brand Protection & Digital Threats
•    Investigate phishing campaigns, malicious domains, and impersonation attempts
•    Perform technical analysis of phishing kits, payloads, and infrastructure
•    Support takedown operations with actionable evidence

Vulnerability & Exposure Management
•    Correlate CVEs with real-world exploitation and internal exposure
•    Validate vulnerabilities (where applicable) and assess exploitability
•    Track and respond to zero-days and active exploitation campaigns
•    Work closely with system owners to ensure remediation

Security Control Improvement
•    Identify detection and response gaps through real incidents and hunting activities
•    Implement improvements across EDR, SIEM, and cloud security controls
•    Build automation scripts and workflows to improve response efficiency
•    Contribute directly to playbooks, runbooks, and technical standards

Required Qualifications

  • 5–8+ years of hands-on experience in Incident Response, Threat Hunting, or Threat Intelligence
  • Strong experience with EDR platforms such as CrowdStrike (querying, investigation, live response)
  • Proven ability to independently investigate and respond to real-world cyber incidents
  • Experience writing detection logic (KQL, SPL, Sigma, etc.)
  • Solid understanding of attacker techniques (lateral movement, persistence, C2, credential abuse)
  • Hands-on experience in cloud security investigations (AWS, Azure, or GCP)
  • Scripting skills (Python, PowerShell, or Bash)