Senior Analyst - Tactical Intelligence

NCC Group

Rijswijk

On-site

EUR 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Working
Holiday Allowance
Medicash
Pension & Share Save
Volunteering Programmes
Green Car Scheme
Cycle to Work
Special Time Off
Family Planning

Job summary

NCC Group is seeking a Threat Intelligence Analyst to strengthen cyber defence by producing actionable intelligence for detection, response and strategic decision-making. You will transform complex findings into insights for both technical and non-technical stakeholders and contribute to intelligence-led security operations.

You will mentor analysts, publish research, and collaborate with SOC and incident response teams, driving improvements in tooling and feeds across the threat intelligence

Qualifications

  • Proven ability to turn fragmented intel into clear assessments.
  • Experience applying structured analytic techniques and confidence scoring.
  • Track record of producing insightful threat reports with risks and recommendations.
  • Background in cyber threat intelligence with threat actor tracking or APT research.
  • Hands-on analysis of malicious campaigns and infrastructure.
  • Familiarity with MITRE ATT&CK and structured intel formats (STIX/TAXII).
  • Broad networking knowledge and curiosity about geopolitics.

Responsibilities

  • Track threat actors and understand their operations, tools, and infrastructure.
  • Investigate campaigns and malicious infrastructure to map broader threats.
  • Assess risks for clients and communicate actionable recommendations.
  • Produce high-quality intelligence reports for technical and non-technical readers.
  • Map activity to industry formats so intel can be acted on consistently.
  • Generate threat-hunting hypotheses and feedback to sharpen analysis.
  • Create indicators to track adversary infrastructure pre-attack.
  • Respond to client and SOC requests with timely, useful analysis.
  • Improve tooling, platforms, and feeds used by the team.
  • Publish research and mentor colleagues across the team.

Skills

Analytical mindset
Structured analysis
Threat intelligence reporting
Threat actor tracking
Hands-on malware analysis
Scripting (Python)
Geopolitics interest

Tools

MITRE ATT&CK
STIX/TAXII
OpenCTI
MISP

Job description

UK (Manchester, Cheltenham or London), Spain (Madrid), the Netherlands (Rijswijk)

The purpose of this role is to strengthen the organisation’s cyber defence capabilities by generating high‑quality, actionable threat intelligence that informs detection, response, and strategic decision‑making. The position exists to proactively identify, analyse, and communicate emerging threats, including adversary behaviours, malware, and infrastructure, while ensuring intelligence outputs are operationally relevant, technically robust, and aligned to business and security priorities.

Operating across the full intelligence lifecycle, the role transforms complex technical findings into meaningful insights for both technical and non‑technical stakeholders, enabling the organisation to anticipate adversary activity, enhance detection engineering, support incident response, and advance intelligence‑led security operations. The role also contributes to continuous improvement through research, tooling development, collaboration with wider security teams, and active participation in the broader threat intelligence community.

What you'll be doing
  • Tracking threat actors and understanding how they operate, including their tools, techniques and infrastructure.
  • Investigating malicious infrastructure and emerging campaigns to build a picture of the wider threat landscape.
  • Assessing what a threat means for our clients, weighing confidence and likelihood, and setting out the risks and recommendations that follow.
  • Writing clear, high‑quality intelligence reports that give technical and non‑technical readers real insight, not just findings.
  • Mapping activity into industry‑standard formats and frameworks, so intelligence can be shared and acted on consistently.
  • Producing intelligence‑led hunt hypotheses for the threat hunting team, and maintaining a feedback loop on outcomes to sharpen future analysis.
  • Creating signatures to track and identify adversary infrastructure as it is being set up, so clients are protected before it is used in an attack.
  • Responding to requests for intelligence and threat context from clients, SOC and incident response teams, providing timely, useful analysis when it matters most.
  • Improving the tools, platforms and feeds our team relies on day to day.
  • Publishing blog posts and research that raise our profile in the threat intelligence community.
  • Mentoring other analysts and sharing your expertise across the team.
What we're looking for
  • An analytical mindset, able to take fragmented and often ambiguous information and turn it into a clear, well reasoned judgement about what it means and why it matters.
  • Skilled in structured analytical techniques, such as confidence levels and source reliability grading, to produce sound, defensible assessments.
  • A track record of producing reports that give readers real insight rather than a list of findings, with clear risks and recommendations attached.
  • A background in cyber threat intelligence analysis, ideally including threat actor tracking or APT research.
  • Practical experience tracking threat actor infrastructure and conducting hands‑on analysis of malicious campaigns, translating technical findings into actionable intelligence for detection, hunting and response teams.
  • Familiarity with MITRE ATT&CK and structured intelligence formats such as STIX/TAXII.
  • A broad understanding of networking and internet infrastructure, and how it is used and abused by threat actors.
  • Comfortable working alongside SOC or incident response teams.
  • Some scripting or programming ability, useful for automation and analysis, Python is a bonus.
  • Familiarity with threat intelligence platforms such as OpenCTI or MISP.
  • A genuine interest in geopolitics and how it shapes the cyber threat landscape.
  • Relevant certifications (e.g. SANS FOR578, CREST CRTIA) are a plus but not required.
Ways of working

Focusing on Clients and Customers.

Working as One NCC.

Being Inclusive and Respectful.

Delivering Brilliantly.

Our company

At NCC Group, our mission is to create a more secure digital future. That mission underpins everything we do, from our work with our incredible clients to groundbreaking research shaping our industry. Our teams' partner with clients across a multitude of industries, delving into, securing new products, and emerging technologies, as well as solving complex security problems. As global leaders in cyber and escrow, NCC Group is a people‑powered business seeking the next group of brilliant minds to join our ranks.

Our colleagues are our greatest asset, and NCC Group is committed to providing an inclusive and supportive work environment that fosters creativity, collaboration, authenticity, and accountability. We want colleagues to put down roots at NCC Group, and we offer a comprehensive benefits package, as well as opportunities for learning and development and career growth. We believe our people are at their brilliant best when they feel bolstered in all aspects of their well‑being, and we offer wellness programs and flexible working arrangements to provide that vital support.

What do we offer in return?

We have a high-performance culture which is balanced evenly with world‑class well‑being initiatives and benefits:

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco‑friendly car scheme.
  • Cycle Schem e: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.

Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process. This role being advertised will be subject to BS7858 screening as a mandatory requirement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst - Tactical Intelligence
Senior Analyst - Tactical Intelligence

Qabird • Rijswijk

Hybrid
EUR 60,000 - 80,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Senior Threat Intelligence Consultant
Senior Threat Intelligence Consultant

Qabird • Rijswijk

Hybrid
EUR 85,000 - 110,000
Flexible Working
Generous Holiday Allowance: 25 days +
Pension, Life Assurance & Share Save
+3
Technical Account Manager
Technical Account Manager

Qabird • Rijswijk

Hybrid
EUR 70,000 - 95,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Developer
Developer

Qabird • Rijswijk

Hybrid
EUR 50,000 - 70,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Cyber Security Consultant
Cyber Security Consultant

Qabird • Rijswijk

On-site
EUR 70,000 - 110,000
Flexible working
25 days annual leave
Medicash
+6
Senior Security Engineer
Senior Security Engineer

Qabird • Rijswijk

Hybrid
EUR 90,000 - 120,000
Flexible Working
25 days holiday
Medicash & Critical Illness Scheme
+3
Managing Security Consultant (Crisis Management)
Managing Security Consultant (Crisis Management)

Qabird • Rijswijk

Hybrid
EUR 90,000 - 120,000
Flexible Working
25 days holiday + bank holidays
Medicash & Critical Illness
+3
Executive (Delivery) Security Consultant
Executive (Delivery) Security Consultant

Qabird • Rijswijk

On-site
EUR 90,000 - 130,000
Flexible Working
25 days holiday + bank holidays + up‑p
Medicash & Critical Illness Scheme
+6
Senior Analyst - Tactical Intelligence
Senior Analyst - Tactical Intelligence

nccgroup • Rijswijk

On-site
EUR 60,000 - 90,000
Solution Architect
Solution Architect

Qabird • Rijswijk

On-site
EUR 90,000 - 130,000
Market-competitive salary
Pension scheme
Vacation days 26 + 4
+4