About this role
Salary: £36,000 - 76,000 per year
Requirements: A career background in Cyber Security.Security awareness in all areas of IT, primarily Network Security, Infrastructure, and secondarily Operating Systems and Applications.Demonstrable knowledge of YARA and Sigma rulesets.Knowledge of IT Security standard methodologies.Demonstrable understanding of the OSI Reference Model and network communication protocols, including DNS, HTTP/S, SSL, SMTP, FTP/S, and LDAP/S.Experience with Security Information Event Monitoring tools and/or Network Packet Capture tools.Experience with IDS/IPS technologies and threat hunting activities.Strong analytical mindset.Understanding of defensive cyber-attack methodologies and frameworks.Understanding of malware capabilities, attack vectors, propagation, and impact.Good communication skills, including liaising with the business and suppliers. Responsibilities: Support the Active Defence Incident Response Manager in helping us meet the challenges and demands of countering the cyber threat.Support the operational functions of the UK SOC.Work with other UK SOC members, including the UK InfoSec Team and the IM Domains.Carry out threat hunting, analysis, monitoring, optimising, reporting, alerting, and investigation activity across our security platforms.Utilize a wide variety of security platforms, including AI/ML and behavioural analytics, SIEM, Network Packet Capture, Anti Malicious Code, and threat detection technologies across our UK Network Perimeter.Conduct a range of analysis and assist the incident response team with investigations that need to be escalated to an embedded member of staff.Conduct proactive threat hunting in collaboration with the CTI function.Lead the threat detection engineering effort working with the ISR function.Assist with the maintenance of security technologies.Assist the Cyber Eng Team with project activity.Support incident responders with HR and InfoSec-related investigations.Attend routine security meetings. Technologies: AIEmbeddedHTTPSupportLDAPNetworkSecurity More:
An opportunity has arisen in our Active Defence Incident Response Team within Digital Excellence (DEX) for a Cyber Threat Operations specialist. We support a proactive ethos in an ever-changing cyber security environment and provide robust threat hunting, detection engineering, and analysis within a high-performing team environment. The role reports to the Active Defence & Incident Response Manager and works across the UK SOC, UK InfoSec Team, and IM Domains, using leading security technologies and platforms across our UK network perimeter.
last updated 37 week of 2026