Senior Analyst - Tactical Intelligence
Listed on 2026-03-11
-
IT/Tech
Cybersecurity, Data Security
Senior Analyst - Tactical Intelligence UK (Manchester, Cheltenham or London), Spain (Madrid), the Netherlands (Rijswijk)
The purpose of this role is to strengthen the organisation’s cyber defence capabilities by generating high‑quality, actionable threat intelligence that informs detection, response, and strategic decision‑making. The position exists to proactively identify, analyse, and communicate emerging threats, including adversary behaviours, malware, and infrastructure, while ensuring intelligence outputs are operationally relevant, technically robust, and aligned to business and security priorities.
Operating across the full intelligence lifecycle, the role transforms complex technical findings into meaningful insights for both technical and non‑technical stakeholders, enabling the organisation to anticipate adversary activity, enhance detection engineering, support incident response, and advance intelligence‑led security operations. The role also contributes to continuous improvement through research, tooling development, collaboration with wider security teams, and active participation in the broader threat intelligence community.
SummaryThreat Intelligence Analysis and Research
- Identify, track, and document threat actors, their TTPs, infrastructure, and indicators of compromise across the full intelligence lifecycle.
- Monitor and analyse Command and Control (C2) infrastructures, malicious domains, and emerging campaigns, providing context‑rich assessments that combine technical findings with geopolitical and regional context.
- Map observed threat activity to established frameworks (e.g., MITRE ATT&CK) and produce structured intelligence outputs using formats such as STIX/TAXII.
- Conduct technical analysis of malware samples to support intelligence assessments, including static and dynamic analysis to extract configurations, identify capabilities, and attribute activity to known threat actors.
- Stay current with the evolving threat landscape, proactively identifying emerging threats, novel attack vectors, and shifts in adversary tradecraft.
- Produce high‑quality finished intelligence products, including threat actor profiles, campaign analyses, and technical advisories, suitable for both technical and non‑technical audiences.
- Document and report on malware behaviour, TTPs, and indicators derived from technical analysis, leveraging internal TIP tooling to generate and disseminate IoCs.
- Contribute to external communications through blog posts, conference presentations, or published research that highlights significant threat intelligence findings.
- Respond to Requests for Information (RFIs) from internal and external stakeholders, delivering timely, actionable intelligence.
- Develop and maintain detection signatures such as YARA rules based on malware analysis and threat research. Identify network and host‑based detection opportunities.
- Manage and optimise threat intelligence platforms, sources, and feeds to improve analysis efficiency and intelligence output quality.
- Develop scripts and tooling to support analysis workflows, including automation of intelligence collection, enrichment, or dissemination tasks.
- Evaluate and recommend new tools or platforms to strengthen the team’s analytical capabilities.
- Support and mentor other analysts within the GTI team, providing guidance on analytical tradecraft and technical methodology.
- Work closely with DFIR and SOC teams to provide threat context, malware insights, and intelligence support during investigations and incidents.
- Generate detection leads from intelligence and malware analysis, maintaining a structured handoff process.
- Contribute to intelligence‑led threat hunting by producing targeted threat assessments and hypotheses for the threat hunting team, and maintaining a feedback loop on findings.
- Partner with external partners, information‑sharing communities, and industry forums to maintain situational awareness and contribute to collective defence.
- Demonstrated experience in Cyber Threat Intelligence analysis…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: