Threat Intelligence Analyst

DS Smith

Kraków

On-site

PLN 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

DS Smith is seeking a skilled Threat Intelligence Analyst to join its Information Security team in Kraków. You will identify, analyse, and communicate cyber threats to protect operations, data, and infrastructure, translating intelligence into actionable guidance for proactive defense.

The role involves monitoring the threat landscape, performing incident response activities, and collaborating with SOC and technology stakeholders to strengthen detection and response capabilities across the

Qualifications

  • Proven hands-on experience managing security incidents through the full incident response lifecycle.
  • Strong understanding of threat actor behaviour and threat intelligence frameworks such as MITRE ATT&CK.
  • Advanced knowledge of Microsoft Sentinel and Defender for threat hunting and investigation.
  • Experience with OSINT, dark web monitoring, and threat intel feeds.
  • Scripting and automation using PowerShell or Python.
  • Excellent communication skills to translate findings into business-focused recommendations.

Responsibilities

  • Monitor the global threat landscape relevant to DS Smith and the manufacturing sector.
  • Analyse intelligence from OSINT, commercial feeds, industry sharing platforms, and dark web monitoring tools.
  • Correlate external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender.
  • Develop and maintain advanced KQL queries to support threat hunting, detection engineering, and incident investigation.
  • Produce actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings.
  • Support and participate in incident response activities from initial triage through containment, eradication, recovery, and post-incident review.
  • Conduct forensic investigations and provide threat context during live security incidents.
  • Collaborate with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities.
  • Contribute to threat models, risk assessments, playbooks, and operational processes.
  • Maintain awareness of evolving cyber threats and trends affecting manufacturing and logistics.

Skills

Threat intelligence
Incident response
Threat hunting
KQL
PowerShell
Python
Microsoft Sentinel
Microsoft Defender
Dark web monitoring
MITRE ATT&CK
Security operations

Tools

DarkIQ
Microsoft Sentinel
Microsoft Defender

Job description

About The Role

We are looking for a skilled and proactive Threat Intelligence Analyst to join our Information Security team.

This is an exciting opportunity to play a critical role in protecting DS Smith's operations, data, and infrastructure by identifying, analysing, and communicating cyber security threats. You will help strengthen our security posture through actionable threat intelligence, advanced threat hunting, and hands-on incident response activities.

Working closely with Security Operations, Incident Response, Infrastructure, and wider Technology teams, you will monitor the evolving threat landscape, investigate potential cyber threats, and support the continuous improvement of our detection and response capabilities. Leveraging Microsoft Sentinel, Microsoft Defender, DarkIQ, and other intelligence sources, you will provide timely intelligence that helps the business stay ahead of emerging threats.

A core focus of the role is to transform threat intelligence into meaningful insights and practical actions, ensuring risks are understood and mitigated before they impact the organisation.

  • Monitoring the global threat landscape for emerging cyber threats, vulnerabilities, and threat actor activity relevant to DS Smith and the manufacturing sector
  • Analysing intelligence from multiple sources, including OSINT, commercial feeds, industry sharing platforms, and dark web monitoring tools
  • Correlating external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender
  • Developing and maintaining advanced KQL queries to support threat hunting, detection engineering, and incident investigation activities
  • Producing actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings
  • Supporting and participating in incident response activities, from initial triage through containment, eradication, recovery, and post-incident review
  • Conducting forensic investigations and providing threat context during live security incidents
  • Collaborating with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities
  • Contributing to the development of threat models, risk assessments, playbooks, and operational processes
  • Maintaining awareness of evolving cyber threats, attack techniques, and trends impacting the manufacturing and logistics sectors

This role offers an excellent opportunity to influence cyber security strategy while working as part of a collaborative team focused on protecting a global organisation.

About You

You're an experienced cyber security professional with a strong background in threat intelligence, incident response, and security operations.

We're Looking For
  • Experience in cyber security, with a focus on threat intelligence, incident response, or security operations
  • Proven hands-on experience managing security incidents throughout the full incident response lifecycle
  • Strong understanding of cyber threats, threat actor behaviour, attack methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain
  • Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation
  • Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent
  • Strong analytical skills with the ability to identify patterns and draw meaningful conclusions from complex datasets
  • Knowledge of malware analysis, phishing investigations, and infrastructure security principles
  • Experience with scripting and automation using PowerShell, Python, or similar technologies
  • Excellent communication skills, with the ability to translate technical findings into clear business-focused recommendations
  • A collaborative approach and desire to continuously improve security capabilities across the organisation
It Would Be Advantageous If You Also Have
  • Relevant industry certifications such as GCTI, GTIA, SC-200, or equivalent
  • Experience within manufacturing, logistics, or industrial environments
  • Knowledge of OT/ICS security and threats affecting operational technology environments
  • Familiarity with GDPR, NIS2, and other relevant cyber security regulations
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

DS Smith • Kraków

On-site
PLN 100,000 - 150,000
Senior Threat Intelligence Researcher
Senior Threat Intelligence Researcher

SentinelOne • Polska

On-site
PLN 180,000 - 300,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+6
Threat Intelligence & Incident Response Lead
Threat Intelligence & Incident Response Lead

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
Cyber Security Analyst
Cyber Security Analyst

Sigma Software • Poland

On-site
PLN 60,000 - 80,000
Cyber Security Risk Analyst
Cyber Security Risk Analyst

Euroclear • Poland

On-site
PLN 190,000 - 297,000
DFIR Analyst
DFIR Analyst

SentinelOne • Poland

On-site
PLN 120,000 - 180,000
RSUs
ESPP
Competitive leave benefits
+6
IAM Technical Lead (General)
IAM Technical Lead (General)

Mindbox SA • Warszawa

On-site
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
Cybersecurity Specialist
Cybersecurity Specialist

DCG • Warszawa

On-site
PLN 180,000 - 240,000
Private medical care
Co-financing for the sports card
Constant consultant support