Advanced Cyber Threat Analyst - M&G plc.

eFinancialCareers

Stirling

Hybrid

GBP 70,000 - 100,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

M&G is seeking an Advanced Cyber Threat Analyst to join Security Operations. The role focuses on identifying, investigating and responding to threats, while strengthening defensive capabilities across cloud, endpoint, identity, email and network technologies.

The analyst will work with Threat Intelligence, Security Operations Engineering and external providers to improve resilience and audit readiness. Flexible working arrangements are available.

Qualifications

  • Experience in a Security Operations environment.
  • Strong incident investigation and response skills.
  • Experience analysing activity across endpoint, identity, cloud, email or network security technologies.
  • Experience conducting structured, intelligence-led threat hunting.
  • Ability to develop, tune or validate security detections and analytical rules.
  • Understanding of how threat intelligence and adversary behaviours can inform investigations.

Responsibilities

  • Investigate complex security incidents across cloud, endpoint, identity, email and network environments.
  • Assess the potential business impact of incidents and recommend proportionate containment, remediation and recovery actions.
  • Maintain accurate investigative records, evidence and decision rationales throughout the incident lifecycle.
  • Conduct intelligence-led threat hunts based on adversary campaigns, behaviours, tactics, techniques and procedures.
  • Identify attack paths, security weaknesses, detection gaps and opportunities to strengthen M&G's security posture.
  • Translate investigation, threat hunting and threat intelligence findings into improved detections, controls and response processes.
  • Develop, tune and validate analytical rules to ensure they remain effective against evolving threats and reduce unnecessary alert activity.
  • Work with Security Operations Engineering to improve telemetry, data quality, detection coverage, tooling integrations and automated workflows.
  • Use AI-assisted analysis and advanced analytics to support triage, investigation, threat hunting, detection engineering and reporting.
  • Validate AI-generated outputs and retain accountability for analytical conclusions, response decisions and security recommendations.
  • Act as a technical escalation point for complex alerts and incidents requiring advanced investigation or specialist expertise.
  • Communicate complex threats, risks, decisions and recommendations clearly to both technical and non-technical stakeholders.
  • Collaborate with internal teams and external security service providers to coordinate effective investigation and response activity.
  • Identify and deliver practical improvements to Security Operations processes, procedures and defensive capabilities.
  • Maintain effective controls, documentation and audit evidence, supporting internal and external audit activity where required.

Skills

Security Operations
Incident investigation
Threat hunting
Detections development
Analytical thinking
Auditing & governance

Tools

Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
Microsoft Sentinel

Job description

At M&G, our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have a long history of innovation in savings and investments, combining asset management and insurance expertise to offer a wide range of solutions.

Our two distinct operating segments, Asset Management and Life, work together to provide access to balanced, long-term investment and savings solutions.

Through telling it like it is, owning it now and moving it forward together with care and integrity; we are creating an exceptional place to work for exceptional talent.

We will consider flexible working arrangements for any of our roles and offer workplace adjustments to ensure you have the support you need to succeed in your role.

Advanced Cyber Threat Analyst
The Role:

The Advanced Cyber Threat Analyst is a technical specialist within Security Operations. The role identifies, investigates and responds to cyber threats while continuously strengthening M&G's defensive capabilities.

The role combines advanced incident investigation, intelligence-led threat hunting, detection engineering and AI-assisted analysis. The analyst uses evidence and professional judgement to assess threat, coordinate and action proportionate response and translate investigative findings into lasting security improvements.

Working across cloud, endpoint, identity, email and network technologies, the role collaborates closely with Threat Intelligence, Security Operations Engineering, internal stakeholders and external security service providers to improve resilience and reduce cyber risk.

Main Responsibilities:
  • Investigate complex security incidents across cloud, endpoint, identity, email and network environments.
  • Assess the potential business impact of incidents and recommend proportionate containment, remediation and recovery actions.
  • Maintain accurate investigative records, evidence and decision rationales throughout the incident lifecycle.
  • Conduct intelligence-led threat hunts based on adversary campaigns, behaviours, tactics, techniques and procedures.
  • Identify attack paths, security weaknesses, detection gaps and opportunities to strengthen M&G's security posture.
  • Translate investigation, threat hunting and threat intelligence findings into improved detections, controls and response processes.
  • Develop, tune and validate analytical rules to ensure they remain effective against evolving threats and reduce unnecessary alert activity.
  • Work with Security Operations Engineering to improve telemetry, data quality, detection coverage, tooling integrations and automated workflows.
  • Use AI-assisted analysis and advanced analytics to support triage, investigation, threat hunting, detection engineering and reporting.
  • Validate AI-generated outputs and retain accountability for analytical conclusions, response decisions and security recommendations.
  • Act as a technical escalation point for complex alerts and incidents requiring advanced investigation or specialist expertise.
  • Communicate complex threats, risks, decisions and recommendations clearly to both technical and non-technical stakeholders.
  • Collaborate with internal teams and external security service providers to coordinate effective investigation and response activity.
  • Identify and deliver practical improvements to Security Operations processes, procedures and defensive capabilities.
  • Maintain effective controls, documentation and audit evidence, supporting internal and external audit activity where required.
Key Knowledge, Skills and Experience:
  • Essential: Practical experience working within a Security Operations environment.
  • Strong capability in cyber incident investigation and response.
  • Experience analysing activity across endpoint, identity, cloud, email or network security technologies.
  • Experience conducting structured, intelligence-led threat hunting.
  • Ability to develop, tune or validate security detections and analytical rules.
  • Understanding of how threat intelligence and adversary behaviours can inform investigations, threat hunts and detection improvements.
  • Experience using security data and evidence to assess risk and recommend proportionate actions.
  • Knowledge of Microsoft Azure security environments, including Entra and Microsoft Defender capabilities.
  • Sound judgement when operating with incomplete, conflicting or time-sensitive information.
  • Strong documentation, governance and audit discipline.
  • Knowledge of responsible AI-assisted security operations, including the need for human oversight and validation.
  • Desirable: Experience with Microsoft Sentinel, including log analysis, analytical rule management and playbook development.
  • Experience with Endpoint Detection and Response technologies, including Microsoft Defender for Endpoint.
  • Experience with Microsoft security technologies such as Entra, Defender for Identity and Defender for Cloud.
  • Experience developing investigation, enrichment or response automation.
  • Exp
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Advanced Cyber Threat Analyst
Advanced Cyber Threat Analyst

mgpru • Stirling

Hybrid
GBP 55,000 - 75,000
Advanced Cyber Threat Analyst
Advanced Cyber Threat Analyst

M&G • Stirling

Hybrid
GBP 65,000 - 105,000
Pension scheme
Share Save & Share Incentive Plan
38 days annual leave
+2
Advanced Cyber Threat Analyst | AI-Driven Response
Advanced Cyber Threat Analyst | AI-Driven Response

M&G • Stirling

Hybrid
GBP 65,000 - 105,000
Pension scheme
Share Save & Share Incentive Plan
38 days annual leave
+2
Advanced Cyber Threat Analyst AI-Driven Incident Response
Advanced Cyber Threat Analyst AI-Driven Incident Response

mgpru • Stirling

Hybrid
GBP 55,000 - 75,000
Advanced Cyber Threat Analyst — AI-Driven Security Operations
Advanced Cyber Threat Analyst — AI-Driven Security Operations

M&GPrudential • Stirling

Hybrid
GBP 65,000 - 90,000
Pension up to 18%
38 days annual leave
Private healthcare
Senior Cyber Threat Analyst – AI-Driven Incident Response
Senior Cyber Threat Analyst – AI-Driven Incident Response

eFinancialCareers • Stirling

Hybrid
GBP 70,000 - 100,000
Advanced Cyber Threat Analyst
Advanced Cyber Threat Analyst

M&GPrudential • Stirling

Hybrid
GBP 65,000 - 90,000
Pension up to 18%
38 days annual leave
Private healthcare
Security Consultant
Security Consultant

M&G plc • City of Edinburgh

Hybrid
GBP 70,000 - 110,000
Pension scheme 18%
Share Save
Share Incentive Plan
+1
Senior Operational Security Engineer
Senior Operational Security Engineer

Crown Agents Bank Ltd. • Greater London

On-site
GBP 70,000 - 90,000
SOC / Cyber Threat Detection Analyst – SANS/GIAC
SOC / Cyber Threat Detection Analyst – SANS/GIAC

Cyber UK • Wokingham

On-site
GBP 45,000 - 70,000
Excellent benefits and training