Threat Intelligence & Incident Response Lead
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Security Management & Operations
The role
The Threat Intelligence & Incident Response Lead shapes ANS proactive cyber defence through intelligence-led operations incident response threat hunting and CTEM.
Youll lead threat intelligence and incident response within the SOC turning emerging threats and customer risk into actionable detection and response.
Combining hands-on expertise with technical leadership youll drive the evolution of MDR and proactive security services while collaborating across Security teams customers and partners to strengthen overall capability.
What will I be doing
Threat Intelligence Leadership
Lead and mature threat intelligence embedding it across detection investigation hunting and protection.
Research emerging threats adversary tactics and vulnerabilities relevant to customers.
Translate intelligence into actionable detections automation and security improvements.
Produce customer and internal threat advisories.
Identify emerging risks across sectors and technologies.
Align with frameworks (e.g. MITRE ATT&CK).
Partner with Engineering and SOC to improve detection and response.
Incident Response Leadership
Lead technical response for high-priority incidents (P1/P2).
Own and enhance incident readiness playbooks and processes.
Drive post-incident reviews and continuous improvement.
Embed threat-informed improvements into detections and response.
Support containment eradication and recovery activities.
Coordinate escalations including external IR and forensics.
Lead incident response exercises.
Continuous Threat Exposure Management (CTEM)
Mature CTEM through threat-informed risk and exposure prioritisation.
Correlate vulnerabilities and telemetry with threat intelligence.
Support exposure validation security reviews and testing.
Provide recommendations to reduce risk and improve resilience.
Support proactive security improvements across services.
Threat Hunting & Detection Strategy
Develop hypothesis-led threat hunting aligned to threat landscape and risk.
Lead proactive hunts using telemetry intelligence and IoCs.
Collaborate to identify suspicious activity and attack patterns.
Turn hunt outcomes into improved detections and response.
Optimise detection through tuning and gap identification.
Enhance ATT&CK-aligned detection coverage.
Technical Leadership & Capability Ownership
Provide technical leadership across SOC activities.
Mentor analysts through coaching and knowledge sharing.
Drive maturity across IR hunting intelligence and detection.
Develop standards documentation and playbooks.
Act as escalation point for complex investigations.
Support service and capability development.
Customer & Stakeholder Engagement
Support customer discussions on incidents threats and risk.
Present technical findings in clear business terms.
Contribute to service improvement and maturity discussions.
Partner with Customer Success Service Owners and Pre-Sales to align services.
What will I bring to the role
Technical Experience
Experience in one or more of:
SOC MDR or MSSP environments
Threat intelligence and adversary analysis
Incident response and cyber coordination
Threat hunting and proactive investigations
Detection engineering and alert tuning
SOAR / security automation
CTEM vulnerability prioritisation or exposure management
Cloud and identity security (Microsoft / multi-cloud)
Strong understanding of:
SIEM/SOAR platforms (e.g. Chronicle Sentinel)
Microsoft Defender ecosystem
MITRE ATT&CK framework
IoCs and threat actor behaviour
Security telemetry and investigation workflows
Incident response lifecycle and containment
Soft Skills
Strong communication and stakeholder engagement
Ability to translate technical concepts into business language
Calm structured approach during incidents
Analytical and problem-solving mindset
Passion for cyber security and emerging threats
Collaborative and supportive technical leadership
Why work for ANS
At ANS weve created a place where everyone can be themselves and we empower our people to get the job done. Openness ambition honesty and passion are what drive us every day. We are bold courageous and innovative and we do it like no other. We invest in our training development health and more we give you the benefits and flexibility to maintain a happy work-life balance.
Were proud of the inclusive fun dynamic environment weve created. Its a safe space that works for dont have to be a techie to work in tech. Bring your authentic self and find your dream role here. Find out more atLinked
In pages.
Whats in it for you
With fantastic benefits an inclusive culture and a cool office space were your kind of workplace.
Company benefits
- As standard:25 days holiday plus you can buy up to5 moredays
- A little extra:well give you your birthday offand an extracelebration dayfor whatever you want!
Tying the knot
You get 5 days additional holiday in the year you get married. Oh and 5volunteer days! - Private health insurance
- Pension contribution match and 4 x life assurance
- Flexible workingandwork from anywhere for up to 30 days per year (some exceptions)
- Maternity: 16 weeks full pay Paternity: 3…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: