Cyber Threat Intelligence Analyst (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Threat Intelligence Analyst (AI): Conducting intelligence collection, monitoring threat infrastructure, analysing threat actors and investigating cyber campaigns with an accent on actionable intelligence, automation and AI-assisted analysis. Focus on tracking adversaries, examining indicators of compromise and building scalable intelligence workflows that support cyber defence operations.
Location: Hybrid in Bristol or Edinburgh, with at least two days per week or 40% of working time at an office site.
Salary: £48,987–£54,430 per year.
Company
is a major UK financial services organisation investing in people, technology and customer-focused financial services.
What you will do
- Collect intelligence and monitor threat actors, infrastructure, campaigns and emerging cyber threats.
- Analyse indicators of compromise, adversary tactics, techniques and procedures, phishing activity, malware campaigns and cybercriminal ecosystems.
- Assess technical threat information and communicate clear findings to support operational cyber defence decisions.
- Develop automated intelligence workflows, AI-assisted analysis capabilities and CTI tooling.
- Use APIs, data enrichment pipelines and intelligence data management practices to improve the speed and scalability of CTI operations.
- Apply OSINT techniques to produce actionable intelligence on threat actors, infrastructure and data breaches.
Requirements
- Understanding of cyber threat intelligence concepts, intelligence lifecycle management, threat actor monitoring, campaign evaluation and intelligence documentation.
- Experience examining threat infrastructure, indicators of compromise, adversary TTPs, phishing, malware or cybercrime activity.
- Strong analytical skills and the ability to communicate technical findings clearly.
- Understanding of APIs, data enrichment pipelines, workflow automation and intelligence data management.
- Experience applying OSINT in structured intelligence collection and analysis.
- Ability to work in a hybrid pattern from the Bristol or Edinburgh office, normally at least two days per week or 40% of working time.
Nice to have
- Knowledge of MITRE ATT&CK, the Diamond Model, Cyber Kill Chain, STIX/TAXII and structured analytic techniques.
- Experience building API-based enrichment or collection workflows.
- Experience with graph databases, knowledge graphs or relationship analysis platforms.
- Understanding of cloud-hosted infrastructure, adversary infrastructure abuse and cybercrime ecosystem monitoring.
Culture & Benefits
- Hybrid working with workplace adjustments available for colleagues with disabilities or long-term health conditions.
- Pension contribution of up to 15%.
- Annual performance-related bonus and share schemes including free shares.
- 28 days of holiday plus bank holidays.
- Wellbeing initiatives and generous parental leave policies.
- Flexible lifestyle benefits, including discounted shopping.
Hiring process
- Reasonable adjustments are available throughout the recruitment process.
- Eligible applicants with disabilities, long-term health conditions or neurodivergent conditions may receive an interview guarantee under the Disability Confident Scheme.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →