Hypothesis-Driven Threat Hunter — MITRE & Automation

NCC Group

Manchester

On-site

GBP 70,000 - 110,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible Working
Holiday allowance
Pension
Life Assurance
Share Save
Volunteer Programs
Green Car Scheme
Cycle to Work
Special Time Off
Family Planning

Job summary

NCC Group in Manchester is seeking a hands-on Threat Hunter to join our Cyber Services and Capabilities team. You will identify sophisticated threats across customer environments using hypothesis-driven analysis and our proprietary hunting framework.

As a Threat Hunter you will work with the SOC Analysts, Global Detection Engineers, Privacy Team and Engineering Team to mitigate risks, leveraging internal and open source threat intel and adopting a proactive, continuous improvement mindset.

Qualifications

  • Experience in threat hunting, red/blue team, incident response or threat intelligence.
  • Strong understanding of the MITRE ATT&CK framework and adversary emulation.
  • Ability to translate threat intel into actionable detection content and playbooks.
  • Comfort presenting findings to stakeholders and documenting methodologies.

Responsibilities

  • Use HITS Framework, threat intel, MITRE ATT&CK, and risk models to form hypotheses and validate through hunts.
  • Automate hunts and visualise results using GitLab, Sigma, Jupyter Notebooks, and other tools.
  • Collaborate with detection engineers to convert hunt findings into detections and content.
  • Operationalise detections using internal threat intel feeds and open source intel.
  • Map threat models to monitoring use cases with cross-team partnership.
  • Document hunting methodologies, tooling, and findings for continuous improvement.
  • Provide regular reports and presentations to stakeholders.

Skills

Hypothesis-driven hunting
TTP analysis
Cross-functional collaboration
Python scripting
KQL
SQL
PowerShell
MITRE ATT&CK familiarity
SIEM/EDR tools knowledge

Tools

Splunk
Microsoft
CrowdStrike
SentinelOne

Job description

NCC Group in Manchester is seeking a hands-on Threat Hunter to join our Cyber Services and Capabilities team. You will identify sophisticated threats across customer environments using hypothesis-driven analysis and our proprietary hunting framework.

As a Threat Hunter you will work with the SOC Analysts, Global Detection Engineers, Privacy Team and Engineering Team to mitigate risks, leveraging internal and open source threat intel and adopting a proactive, continuous improvement mindset.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hypothesis-Driven Threat Hunter
Hypothesis-Driven Threat Hunter

nccgroup • Manchester

On-site
GBP 60,000 - 90,000
Threat Hunter – Hypothesis-Driven Cyber Defense Expert
Threat Hunter – Hypothesis-Driven Cyber Defense Expert

NCC Group • Manchester

Hybrid
GBP 70,000 - 95,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+7
Threat Hunter
Threat Hunter

nccgroup • Manchester

On-site
GBP 60,000 - 90,000
Threat Hunter
Threat Hunter

NCC Group • Manchester

On-site
GBP 70,000 - 110,000
Flexible Working
Holiday allowance
Pension
+7
Cyber Threat Hunter & Incident Response Specialist
Cyber Threat Hunter & Incident Response Specialist

Cyber UK • Stevenage

Remote
GBP 83,000 - 120,000
Senior Threat Detection & Incident Response Engineer
Senior Threat Detection & Incident Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Cyber Threat Operations Lead: Threat Hunting & Detection
Cyber Threat Operations Lead: Threat Hunting & Detection

Morson Edge • Stevenage

On-site
GBP 65,000 - 90,000
Cyber Fusion Threat Hunter & Response Analyst
Cyber Fusion Threat Hunter & Response Analyst

Aplaro Ltd • United Kingdom

On-site
GBP 89,000 - 151,000
Senior Cyber Threat Intelligence Analyst Threat Hunting Lead
Senior Cyber Threat Intelligence Analyst Threat Hunting Lead

Cyber UK • City of Edinburgh

On-site
GBP 55,000 - 75,000
40 days annual leave
16% employer pension contribution
Private healthcare
+1
Cyber Threat Operations Lead – Threat Hunting & Detection
Cyber Threat Operations Lead – Threat Hunting & Detection

Morson Human Resources Limited • England

On-site
GBP 60,000 - 90,000