Job Search and Career Advice Platform

Enable job alerts via email!

Detection & Response Security Engineer, Threat Intelligence

Meta

City Of London

On-site

GBP 70,000 - 90,000

Full time

24 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading tech company in London is seeking a Threat Intelligence Investigator to enhance security against cyber threats. The role involves investigating threats, developing countermeasures, and collaborating with incident responders. Candidates should have over 5 years of experience in threat intelligence and a bachelor's degree in security. This position offers a competitive salary and the opportunity to work in a dynamic environment.

Qualifications

  • 5+ years threat intelligence experience.
  • Familiarity with threat modeling framework.
  • Ability to work with a geographically diverse team.
  • Experience with intelligence-driven hunting.
  • Coded or scripted experience in Python or PHP.

Responsibilities

  • Track threat clusters and implement countermeasures.
  • Investigate and forecast emerging technical trends.
  • Work closely with incident responders.
  • Improve threat tracking tooling.
  • Engage in cross-functional projects to enhance security.

Skills

Threat Intelligence
Cyber Threat Investigation
Communication Skills
Incident Response Collaboration
Network Security
Scripting Languages (Python, PHP)

Education

Bachelor's degree in Security or equivalent

Tools

MITRE ATT&CK framework
YARA
SQL
Job description
Summary

Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the gaps in current detections and preventions by long-term intelligence tracking and research, and working with cross‑functional stakeholders to improve Meta’s security posture.

Required Skills

Detection & Response Security Engineer, Threat Intelligence Responsibilities:

  1. Track threat clusters posing threats to Meta’s infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
  2. Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
  3. Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
  4. Improve the tooling of threat cluster tracking and intelligence data integration to existing systems
  5. Engage constructively in cross‑functional projects to improve the security posture of Meta’s infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions
Minimum Qualifications
  1. 5+ years threat intelligence experience
  2. Bachelor's degree or equivalent experience in Security
  3. Familiarity with campaign tracking techniques and converting the tracking results to long‑term countermeasures
  4. Familiarity with threat modeling framework, such as Diamond Model or/and MITRE ATT&CK framework
  5. Experience with intelligence‑driven hunting to spot suspicious activities in the network and identify potential risks
  6. Proven track record of managing and executing on short‑term and long‑term projects
  7. Ability to work with a team spanning multiple locations/time zones
  8. Ability to prioritize and execute tasks with minimal direction or oversight
  9. Ability to think critically and qualify assessments with solid communication skills
  10. Coding or scripting experience in one or more scripting languages such as Python or PHP
Preferred Qualifications
  1. Experience close collaborating with incident responders on incident investigations
  2. Familiarity with malware analysis or network traffic analysis
  3. Familiarity with nation‑state, sophisticated criminal, or supply chain threats
  4. Familiarity with file‑based or network‑based rules and signatures for detection and tracking of complex threats, such as YARA or Snort
  5. Experience in one or more query languages such as SQL
  6. Experience authoring production code for threat intelligence tooling
  7. Experience conducting large scale data analysis
  8. Experience working across the broader security community
Industry

Internet

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.