An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Forensic Focus Limited is seeking a senior security professional to lead hands-on incident response, threat hunting, and threat intelligence across endpoints, identities and cloud. You will own investigations from triage to recovery and translate intelligence into practical security improvements.
The ideal candidate has 5–8+ years in IR, threat intel or hunting, expert use of CrowdStrike EDR, Splunk/KQL/Sigma, MITRE ATT&CK, and cloud logs on AWS, Azure, and GCP; plus scripting and automation
This senior individual contributor position centres on hands‑on incident response, threat hunting, and threat intelligence across endpoint, identity, and cloud environments. Day‑to‑day work includes leading investigations from triage to recovery, developing detection rules, analysing malware behaviour, and operationalising intelligence into actionable security improvements.
Candidates need five to eight or more years in incident response, threat hunting, or threat intelligence, with strong proficiency in CrowdStrike EDR, SIEM platforms (Splunk, KQL, Sigma), MITRE ATT&CK framework, and cloud log analysis across AWS, Azure, and GCP. Scripting and automation experience is also expected.
This role suits an experienced security professional comfortable operating independently on complex investigations without close supervision. Those with a background spanning incident response, detection engineering, and threat intelligence — particularly in enterprise or regulated environments — will find this role well matched to their skill set.