Threat Intelligence Analyst

DS Smith

City of Westminster

On-site

GBP 60,000 - 95,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

DS Smith is seeking a skilled Threat Intelligence Analyst to join our Information Security team. You will identify, analyse, and communicate cyber security threats to protect our operations and data across manufacturing and logistics.

You will work with Security Operations, Incident Response, and Infrastructure teams, using Microsoft Sentinel, Defender, DarkIQ, and OSINT to deliver actionable intelligence and drive improvements in detection and response.

Qualifications

  • Experience in cyber security with focus on threat intelligence, incident response, or security operations.
  • Proven hands-on experience managing security incidents through full IR lifecycle.
  • Strong understanding of cyber threats, threat actor behaviour, attack methodologies, and intelligence frameworks such as MITRE ATT&CK.

Responsibilities

  • Monitor global threat landscape for emerging cyber threats and act on threats relevant to DS Smith.
  • Analyse intelligence from OSINT, commercial feeds, industry sharing, and dark web sources.
  • Correlate external intelligence with internal security events using Microsoft Sentinel and Defender.
  • Develop advanced KQL queries to support threat hunting, detection engineering, and incident investigation.
  • Produce actionable threat intelligence reports, IoCs, and executive briefings.
  • Support incident response from triage through containment, eradication, and recovery.

Skills

Threat intelligence
Incident response
Security operations
MITRE ATT&CK
KQL
Microsoft Sentinel
Microsoft Defender
DarkIQ
OSINT
Threat hunting

Tools

DarkIQ
Microsoft Defender
Microsoft Sentinel

Job description

About the Role

We are looking for a skilled and proactive Threat Intelligence Analyst to join our Information Security team. This is an exciting opportunity to play a critical role in protecting DS Smith's operations, data, and infrastructure by identifying, analysing, and communicating cyber security threats. You will help strengthen our security posture through actionable threat intelligence, advanced threat hunting, and hands‑on incident response activities. Working closely with Security Operations, Incident Response, Infrastructure, and wider Technology teams, you will monitor the evolving threat landscape, investigate potential cyber threats, and support the continuous improvement of our detection and response capabilities. Leveraging Microsoft Sentinel, Microsoft Defender, DarkIQ, and other intelligence sources, you will provide timely intelligence that helps the business stay ahead of emerging threats. A core focus of the role is to transform threat intelligence into meaningful insights and practical actions, ensuring risks are understood and mitigated before they impact the organisation.

Key responsibilities include:
  • Monitoring the global threat landscape for emerging cyber threats, vulnerabilities, and threat actor activity relevant to DS Smith and the manufacturing sector
  • Analysing intelligence from multiple sources, including OSINT, commercial feeds, industry sharing platforms, and dark web monitoring tools
  • Correlating external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender
  • Developing and maintaining advanced KQL queries to support threat hunting, detection engineering, and incident investigation activities
  • Producing actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings
  • Supporting and participating in incident response activities, from initial triage through containment, eradication, recovery, and post-incident review
  • Conducting forensic investigations and providing threat context during live security incidents
  • Collaborating with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities
  • Contributing to the development of threat models, risk assessments, playbooks, and operational processes
  • Maintaining awareness of evolving cyber threats, attack techniques, and trends impacting the manufacturing and logistics sectors

This role offers an excellent opportunity to influence cyber security strategy while working as part of a collaborative team focused on protecting a global organisation.

About You

You're an experienced cyber security professional with a strong background in threat intelligence, incident response, and security operations.

We're looking for:
  • Experience in cyber security, with a focus on threat intelligence, incident response, or security operations
  • Proven hands‑on experience managing security incidents throughout the full incident response lifecycle
  • Strong understanding of cyber threats, threat actor behaviour, attack methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain
  • Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation
  • Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent
  • Strong analytical skills with the ability to identify patterns and draw meaningful conclusions from complex datasets
  • Knowledge of malware analysis, phishing investigations, and infrastructure security principles
  • Experience with scripting and automation using PowerShell, Python, or similar technologies
  • Excellent communication skills, with the ability to translate technical findings into clear business‑focused recommendations
  • A collaborative approach and desire to continuously improve security capabilities across the organisation
It would be advantageous if you also have:
  • Relevant industry certifications such as GCTI, GTIA, SC-200, or equivalent
  • Experience within manufacturing, logistics, or industrial environments
  • Knowledge of OT/ICS security and threats affecting operational technology environments
  • Familiarity with GDPR, NIS2, and other relevant cyber security regulations

We are DS Smith, together with International Paper, we are a global leader in sustainable packaging solutions and other fibre‑based products.We believe a better, more sustainable tomorrow is possible with the right people, who challenge and support one another to enact positive change. We employ more than 60,000 colleagues in North America and Europe, Middle East and Africa (EMEA), who are experts in innovation,manufacturing, design, sales, sustainability, supply chain, and much more. Together with our customers, we make the world safer and more productive, one sustainable packaging solution at a time. Become part of a world‑leading organisation and do your best work with us! As the journey continues of bringing together the strengths of both organisations, during your candidate experience you may engage with our colleagues from International Paper! You could visit an International Paper or DS Smith site or office.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Intelligence Analyst
Threat Intelligence Analyst

dssmith • Greater London

On-site
GBP 65,000 - 90,000
Threat Intelligence Analyst
Threat Intelligence Analyst

DS Smith Europe • City of Westminster

On-site
GBP 60,000 - 85,000
Threat Intelligence Analyst
Threat Intelligence Analyst

Jobtailor • Greater London

On-site
GBP 65,000 - 90,000
Threat Intelligence & Incident Response Specialist
Threat Intelligence & Incident Response Specialist

DS Smith Europe • City of Westminster

On-site
GBP 60,000 - 85,000
Threat Intelligence & Incident Response Analyst
Threat Intelligence & Incident Response Analyst

dssmith • Greater London

On-site
GBP 65,000 - 90,000
Senior Project Manager
Senior Project Manager

DS Smith • City of Westminster

On-site
GBP 70,000 - 110,000
Threat Intelligence Analyst - Detection & Incident Response
Threat Intelligence Analyst - Detection & Incident Response

DS Smith • City of Westminster

On-site
GBP 60,000 - 95,000
Logistics Lead
Logistics Lead

DS Smith • United Kingdom

Hybrid
GBP 60,000 - 90,000
Competitive salary
25 days holiday plus bank holidays
Pension scheme, life assurance and/ or
+4
Senior Manager Internal Audit
Senior Manager Internal Audit

DS Smith • Greater London

On-site
GBP 85,000 - 120,000
Competitive salary
Discretionary bonus
25 days holiday plus bank holidays
+5
Design & Innovation Manager
Design & Innovation Manager

DS Smith • Hinckley

On-site
GBP 90,000 - 130,000
Competitive salary
Discretionary bonus
25 days holiday + bank holidays
+7