Threat Intelligence Analyst

Jobtailor

Greater London

On-site

GBP 65,000 - 90,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor is seeking a Cyber Threat Analyst to monitor global threat landscapes, analyse intel from OSINT, dark web sources, and feeds, and support incident response for manufacturing and logistics sectors.

You will develop KQL queries for threat hunting, produce actionable reports, and collaborate with SOC teams to strengthen detection and response using Microsoft Sentinel and Defender.

Qualifications

  • Experience in cyber security with focus on threat intel, incident response, or security operations.
  • Hands-on experience managing security incidents lifecycle.
  • Strong knowledge of threat frameworks like MITRE ATT&CK, Diamond Model, and Cyber Kill Chain.
  • Advanced knowledge of Microsoft Sentinel, Defender, and KQL for threat hunting and investigation.
  • Experience with threat intel platforms and dark web monitoring solutions.
  • Strong analytical skills with ability to identify patterns from data.
  • Knowledge of malware analysis, phishing investigations, and infrastructure security.
  • Experience with scripting/automation (PowerShell, Python).
  • Excellent communication and collaboration to translate findings into business decisions.
  • Industry certifications: GCTI, GTIA, SC-200.

Responsibilities

  • Monitor global threat landscape for DS Smith and manufacturing sector.
  • Analyse intel from OSINT, feeds, platforms, and dark web tools.
  • Correlate intel with internal security events using Sentinel and Defender.
  • Develop and maintain advanced KQL queries for threat hunting and investigation.
  • Produce actionable threat intel reports, IoCs, and executive briefings.
  • Support incident response from triage to recovery and post-incident review.
  • Conduct forensic investigations and provide threat context during live incidents.
  • Collaborate with SOC teams, security architects, and stakeholders to strengthen detection.
  • Contribute to threat models, risk assessments, and playbooks.
  • Maintain awareness of evolving threats in manufacturing/logistics.

Skills

Threat intelligence
Incident response
Security operations
MITRE ATT&CK
KQL
Microsoft Defender
Microsoft Sentinel
Dark web monitoring
Scripting
Analytical skills
Communication

Education

GCTI
GTIA
SC-200

Tools

Microsoft Sentinel
Microsoft Defender
DarkIQ
Threat Intelligence Platforms
OSINT Tools
Dark Web Monitoring Tools

Job description

Responsibilities
  • Monitor the global threat landscape for emerging cyber threats, vulnerabilities, and threat actor activity relevant to DS Smith and the manufacturing sector
  • Analyse intelligence from OSINT, commercial feeds, industry sharing platforms, and dark web monitoring tools
  • Correlate external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender
  • Develop and maintain advanced KQL queries for threat hunting, detection engineering, and incident investigation
  • Produce actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings
  • Support and participate in incident response from initial triage through containment, eradication, recovery, and post-incident review
  • Conduct forensic investigations and provide threat context during live security incidents
  • Collaborate with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities
  • Contribute to threat models, risk assessments, playbooks, and operational processes
  • Maintain awareness of evolving cyber threats, attack techniques, and trends impacting manufacturing and logistics sectors
Requirements
  • Experience in cyber security, with a focus on threat intelligence, incident response, or security operations
  • Proven hands-on experience managing security incidents throughout the full incident response lifecycle
  • Strong understanding of cyber threats, threat actor behaviour, attack methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain
  • Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation
  • Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent
  • Strong analytical skills with the ability to identify patterns and draw meaningful conclusions from complex datasets
  • Knowledge of malware analysis, phishing investigations, and infrastructure security principles
  • Experience with scripting and automation using PowerShell, Python, or similar technologies
  • Excellent communication skills, with the ability to translate technical findings into clear business-focused recommendations
  • A collaborative approach and desire to continuously improve security capabilities across the organisation
  • Relevant industry certifications such as GCTI, GTIA, SC-200, or equivalent
  • Experience within manufacturing, logistics, or industrial environments
  • Knowledge of OT/ICS security and threats affecting operational technology environments
  • Familiarity with GDPR, NIS2, and other relevant cyber security regulations
Core Competencies

Demonstrates expertise in cyber security with a focus on threat intelligence, incident response, and security operations. Proficient in using Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation, while maintaining awareness of evolving cyber threats and attack methodologies.

Highest-signal resume keywords
  • Cyber Security Experience
  • Threat Intelligence Analysis
  • Incident Response Management
  • Microsoft Sentinel Proficiency
  • KQL Query Development
Hard Skills
  • Threat Intelligence
  • Incident Response
  • KQL
  • Malware Analysis
  • Phishing Investigation
  • Scripting
  • Automation
  • Data Analysis
  • Cyber Threat Frameworks
  • Forensic Investigation
Soft Skills
  • Analytical Skills
  • Communication Skills
  • Collaboration
  • Problem-Solving
  • Continuous Improvement
Certifications & Qualifications
  • GCTI
  • GTIA
  • SC-200
Industry Keywords
  • Manufacturing
  • Logistics
  • Operational Technology
  • ICS Security
  • GDPR
  • NIS2
Tools & Technologies
  • Microsoft Sentinel
  • Microsoft Defender
  • DarkIQ
  • Threat Intelligence Platforms
  • OSINT Tools
  • Dark Web Monitoring Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Intelligence Analyst
Threat Intelligence Analyst

DS Smith Europe • City of Westminster

On-site
GBP 60,000 - 85,000
Threat Intelligence Analyst
Threat Intelligence Analyst

dssmith • Greater London

On-site
GBP 65,000 - 90,000
Threat Intelligence Analyst
Threat Intelligence Analyst

DS Smith • City of Westminster

On-site
GBP 60,000 - 95,000
Cyber Threat Management Analyst, Specialist
Cyber Threat Management Analyst, Specialist

Jobtailor • Greater London

On-site
GBP 60,000 - 90,000
Threat Intelligence Analyst - Detection & Incident Response
Threat Intelligence Analyst - Detection & Incident Response

DS Smith • City of Westminster

On-site
GBP 60,000 - 95,000
Cyber Security Engineer
Cyber Security Engineer

Jobtailor • Greater London

Hybrid
GBP 70,000 - 110,000
Threat Intelligence & Incident Response Analyst
Threat Intelligence & Incident Response Analyst

dssmith • Greater London

On-site
GBP 65,000 - 90,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Intelligence Analyst
Intelligence Analyst

Jobtailor • Greater London

On-site
GBP 60,000 - 90,000
SOC Team Lead
SOC Team Lead

Jobtailor • Greater London

On-site
GBP 90,000 - 120,000