We are seeking an experienced and highly technical Cyber Threat Intelligence & Incident Response Specialist to strengthen our organisation's threat detection, incident response, and cyber defence capabilities. This is a hands-on individual contributor role suited for a cybersecurity professional who is comfortable independently leading complex investigations from initial detection through containment, eradication, recovery, and post-incident improvement. The successful candidate will spend a significant portion of their time conducting real-world investigations, proactive threat hunting, developing and tuning detections, analysing threat intelligence, and improving security controls across enterprise, endpoint, identity, network, and cloud environments.
Key Responsibilities:
Threat Intelligence
- Collect, analyse, and operationalise cyber threat intelligence from OSINT, commercial threat feeds, ISACs, dark-web sources, and other relevant intelligence channels.
- Conduct adversary tracking, campaign analysis, infrastructure analysis, and mapping of attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.
- Translate threat intelligence into actionable detection rules, threat-hunting queries, indicators, and security use cases.
- Integrate threat intelligence into security platforms including SIEM, EDR, Threat Intelligence Platforms (TIPs), and CrowdStrike.
- Monitor emerging threats, zero-day vulnerabilities, active exploitation campaigns, and changes in adversary behaviour.
Incident Response
- Lead and execute end-to-end cybersecurity incident response activities including triage, investigation, containment, eradication, recovery, and post-incident analysis.
- Perform investigations across endpoint telemetry, security logs, network traffic, identity systems, and cloud environments.
- Use EDR platforms such as CrowdStrike for investigation, live response, forensic analysis, and threat hunting.
- Investigate malware activity, credential compromise, attacker persistence, command-and-control activity, privilege escalation, and lateral movement.
- Determine root cause, attack paths, affected systems, and overall business impact.
- Produce detailed incident reports with clear technical findings, root-cause analysis, remediation actions, and recommendations.
Threat Hunting & Detection Engineering
- Develop and execute structured threat-hunting activities across endpoint, identity, network, and cloud telemetry.
- Develop, test, tune, and maintain security detections using technologies and languages such as KQL, SPL, Sigma, SIEM and EDR query languages.
- Map detection coverage against adversary techniques using MITRE ATT&CK.
- Validate detection effectiveness through security testing, attack simulation, and adversary-emulation exercises.
- Identify detection gaps from incidents and threat-intelligence findings and implement improvements.
- Drive improvements in security metrics including Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Cloud Security
- Investigate and respond to security threats affecting AWS, Microsoft Azure, and/or Google Cloud Platform (GCP) environments.
- Analyse cloud security telemetry including AWS CloudTrail, Microsoft Entra ID/Azure logs, and GCP audit logs.
- Identify suspicious authentication activity, privilege escalation, compromised credentials, identity-based attacks, and cloud misconfigurations.
- Work closely with infrastructure, cloud, and engineering teams to remediate identified security weaknesses.
Brand Protection & Digital Threats
- Investigate phishing campaigns, impersonation attempts, fraudulent websites, malicious domains, and other digital threats.
- Conduct technical analysis of phishing infrastructure, phishing kits, malicious payloads, URLs, and associated attacker infrastructure.
- Gather and document actionable evidence to support domain, website, or infrastructure takedown activities.
Vulnerability & Exposure Management
- Assess vulnerabilities in the context of real-world exploitation, threat intelligence, and organisational exposure.
- Correlate CVEs with active exploitation campaigns and internal technology assets.
- Validate vulnerabilities and assess exploitability where appropriate.
- Monitor and respond to zero-day vulnerabilities and emerging exploitation activity.
- Work with system owners and technical teams to prioritise and ensure timely remediation.
Security Control Improvement
- Identify security-control and detection gaps through incident investigations, threat hunting, and threat-intelligence analysis.
- Implement improvements across EDR, SIEM, cloud security, identity, and other security platforms.
- Develop automation scripts and workflows to improve investigation and incident-response efficiency.
- Contribute to the development and continuous improvement of incident-response playbooks, threat-hunting procedures, runbooks, and technical security standards.
- Support security improvements aligned with organisational and applicable regulatory requirements, including CSA and PDPC requirements where relevant.
Requirements
- 5-8+ years of relevant hands-on cybersecurity experience, particularly in Incident Response, Threat Hunting, Threat Intelligence, SOC operations, or Detection Engineering.
- Strong hands-on experience with EDR platforms such as CrowdStrike, including querying, investigation, threat hunting, and live-response capabilities.
- Demonstrated experience independently investigating and responding to complex real-world cybersecurity incidents.
- Experience developing and tuning detection logic using KQL, SPL, Sigma, or equivalent technologies.
- Strong understanding of attacker tactics and techniques including:
- Credential theft and abuse
- Persistence
- Privilege escalation
- Lateral movement
- Command and Control (C2)
- Defence evasion
- Data exfiltration
- Good knowledge of the MITRE ATT&CK framework and its application to threat intelligence, detection engineering, and threat hunting.
- Hands-on experience investigating security incidents within at least one major cloud platform such as AWS, Azure, or GCP.
- Strong understanding of endpoint, network, identity, authentication, and cloud-security concepts.
- Scripting or automation experience using Python, PowerShell, Bash, or equivalent technologies.
- Strong analytical and problem-solving skills with the ability to independently manage investigations from identification through resolution.
- Ability to clearly communicate complex technical findings to both technical and non-technical stakeholders.
Preferred Qualifications
- Hands-on experience with malware analysis, digital forensics, or forensic investigation tools.
- Experience with Threat Intelligence Platforms (TIPs), SOAR platforms, SIEM solutions, and security automation.
- Experience performing adversary emulation or attack simulation.
- Relevant professional certifications such as GCIH, GCFA, GNFA, GCTI, CISSP, or equivalent certifications.
- Previous experience working in regulated, financial services, critical infrastructure, government, or other high-risk environments.
Role Success Measures
- Success in this role will be demonstrated through measurable improvements in:
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Detection coverage across relevant MITRE ATT&CK techniques.
- Identification of previously undetected threats through proactive threat hunting.
- Effectiveness and accuracy of security detections.
- Reduction of recurring incidents through root-cause remediation.
- Continuous improvement of the organisation's overall threat detection and incident-response capability.
To apply,simply click the Apply button or send your updated profile to [Confidential Information]
EA Licence No.:18S9405 / EA Reg. No.:R1330864
Percept Solutions is expanding and actively seeking talented individuals. We encourage applicants to follow Percept Solutions on LinkedIn at https://www.linkedin.com/company/percept-solutions/to stay informed about new opportunities and events.