10 дней назад
Threat Intelligence Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Intelligence Analyst (Cybersecurity): Monitoring and analysing cyber threats, correlating intelligence with security events, and supporting incident response for a global manufacturing organisation with an accent on Microsoft Sentinel, Microsoft Defender, KQL, and dark web intelligence. Focus on developing threat-hunting queries, conducting forensic investigations, producing actionable intelligence, and strengthening detection and response capabilities.
Location: London
Company
is a global organisation operating across manufacturing and logistics, with a focus on protecting its operations, data, and infrastructure.
What you will do
- Monitor the global threat landscape, vulnerabilities, and threat actor activity affecting the organisation and manufacturing sector.
- Analyse OSINT, commercial intelligence feeds, industry-sharing platforms, and dark web monitoring data.
- Correlate external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender.
- Develop and maintain advanced KQL queries for threat hunting, detection engineering, and incident investigations.
- Produce threat intelligence reports, threat actor profiles, indicators of compromise, and executive briefings.
- Support the full incident response lifecycle, including triage, containment, eradication, recovery, forensic investigation, and post-incident review.
Requirements
- Experience in cybersecurity, threat intelligence, incident response, or security operations.
- Hands-on experience managing security incidents throughout the full incident response lifecycle.
- Strong knowledge of cyber threats, threat actor behaviour, attack methodologies, MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain.
- Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigations.
- Experience with threat intelligence platforms and dark web monitoring solutions such as DarkIQ or equivalent.
- Knowledge of malware analysis, phishing investigations, infrastructure security, and scripting or automation with PowerShell or Python.
Nice to have
- Relevant certifications such as GCTI, GTIA, SC-200, or equivalent.
- Experience in manufacturing, logistics, or industrial environments.
- Knowledge of OT/ICS security and operational technology threats.
- Familiarity with GDPR, NIS2, and other relevant cybersecurity regulations.
Culture & Benefits
- Collaborate with Security Operations, Incident Response, Infrastructure, and wider Technology teams.
- Contribute to cybersecurity strategy and the continuous improvement of detection and response capabilities.
- Work in a collaborative environment focused on protecting a global organisation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →