Latest Threat Intelligence Analyst Jobs

CrowdStrike logo

Sr. Intelligence Analyst, Recon+ , GBR)

This role involves delivering high-impact threat intelligence and digital risk monitoring services to protect customers from advanced cyber threats. The analyst will conduct dark web research, tailor intelligence to customer environments, and deliver actionable findings through briefings and reports. Collaboration across internal teams and direct engagement with stakeholders from SOC to CISO levels are key to driving customer success and improving threat-hunting capabilities.

CrowdStrike England
Remote Permanent
CrowdStrike logo

Sr. Intelligence Analyst, Recon+ , GBR)

This role involves delivering high-impact threat intelligence and digital risk monitoring services to protect customers from advanced cyber threats. The analyst will conduct dark web research, produce actionable intelligence, brief stakeholders from technical to executive levels, and guide customers through findings from Falcon Counter Adversary Recon. The position emphasizes customer partnership, technical analysis, and cross-team collaboration within CrowdStrike’s AI-native security platform.

CrowdStrike United Kingdom
Remote Permanent

Senior Threat Researcher (UK)

Develops high-fidelity threat detections by analyzing malware and web attacks using multi-source telemetry and threat intelligence. Translates research into actionable alerts across Sophos' security platform with a focus on reducing noise. Works closely with threat intelligence and product teams to enhance detection accuracy for endpoint, cloud, and network environments.

Sophos United Kingdom
Remote Permanent

Sr. AI Threat Researcher

A senior individual contributor role focused on researching how threat actors exploit AI across the attack lifecycle, including LLM-powered social engineering, AI-generated malware, and attacks on agentic AI systems. The role involves analyzing telemetry and OSINT to detect adversarial AI use, developing detection strategies, automating research workflows using AI, and producing actionable intelligence for internal and external dissemination. Works cross-functionally with threat researchers, malware analysts, and engineers to integrate findings into protections and operational systems.

Sophos United Kingdom
Remote Permanent

SOC Manager

Lead and oversee the strategic direction of a Cyber Security Operations Centre, managing incident response, threat intelligence, and security operations. This role involves high-level governance, coordination with external vendors and MSSPs, and leading teams during major security incidents. The position requires a strategic leader rather than a hands-on analyst, with a focus on crisis management and security operations leadership.

Randstad Technologies Recruitment London, City And County Of the City Of London, United Kingdom £600 – £700 pd
Remote Contract Clearance Required

SOC Manager

Lead and develop a Security Operations Centre within a public sector environment, defining strategy and operational roadmap while overseeing incident management, threat intelligence, and security monitoring. Manage cyber security tools, vendor relationships, and MSSP partnerships to strengthen national-level security operations. This role requires active SC clearance and experience in strategic SOC leadership.

NonStop Consulting Exeter, Devon, United Kingdom £800 – £850 pd

SOC Shift Lead

Leads a team of SOC analysts during assigned shifts, ensuring high-quality incident triage, investigation, and documentation. Oversees shift operations, conducts quality assurance, mentors junior staff, and drives process improvements in line with SLAs. Works closely with engineering and customer teams to enhance threat detection and response through rule tuning, reporting, and service refinement.

Claranet Leeds, United Kingdom

SOC Engineer

This role involves engineering and optimising security tools, telemetry, detections, and automation within a Cyber Security Operations Centre. The SOC Engineer will administer Microsoft Sentinel, develop SOAR workflows, tune detection rules, conduct threat hunting, and support incident response. The position requires strong scripting skills and experience with SIEM, SOAR, and security monitoring across hybrid environments.

Proactive Appointments Milton Keynes, United Kingdom £55,000 pa

Cyber Security Operations Manager

Lead and develop a security operations team while managing the full incident lifecycle from detection to resolution. Design and improve security monitoring strategies using SIEM, EDR, and SOAR tools, and integrate threat intelligence to enhance defensive capabilities. Work closely with MSSPs and internal stakeholders to strengthen the organisation's security posture through continuous improvement and strategic planning.

Tatton Recruitment Pinhoe, Devon, EX4 9EY, United Kingdom £800 pd

SOC Automation Engineer

As a SOC Automation Engineer, you will design, build, and maintain automation workflows to enhance the efficiency and scalability of SOC services. You will work across SIEM, EDR, and SOAR platforms, focusing on reducing analyst workload and improving incident response times. Collaboration with SOC and engineering teams to identify automation opportunities and support pre-sales activities is also a key part of the role.

Claranet Leeds, West Yorkshire, United Kingdom
On-site Permanent Clearance Required

Principal Professional Services Engineer

Lead strategic SOC transformation and XSIAM deployment programs for enterprise customers, guiding modernization from initial planning through operationalization. Design and implement advanced detection strategies, log ingestion frameworks, and automation workflows to enhance security outcomes. Serve as a technical advisor and mentor high-performing professional services teams while collaborating with product teams to influence roadmaps.

Palo Alto Networks London, United Kingdom
Hybrid Permanent Clearance Required

Senior Security Operations Analyst

This role involves leading threat detection, incident response, and security monitoring at scale within a UK fintech. The analyst will develop and tune SIEM rules, conduct threat hunting, manage EDR systems, and contribute to security policies and controls. Collaboration with infrastructure, network, and DevOps teams is key to investigating and remediating security incidents.

Forward Role Leeds, United Kingdom £54,000 – £65,000 pa
Hybrid Permanent

Cyber Security Engineer/Specialist

Cyber Security Engineer/SpecialistPermanent | Up to £80,000 (+ Benefits)Hybrid Working (2–3 days per week Onsite) | SurreyHelp Shape Enterprise Cyber Security on a Global ScaleWe're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is...

Exalto Consulting Surrey, United Kingdom £70,000 – £80,000 pa
Experis logo

Splunk SIEM Engineer

Role Title: Splunk SIEM EngineerDuration: contract to run until 30/11/2026Location: Knutsford. Hybrid, 3 days per week onsiteRate: up to £587.33 p/d Umbrella inside IR35Role purpose / summaryJoin us as Splunk SIEM Engineer where you must design, develop and improve software,...

Experis Knutsford, Cheshire, United Kingdom

SC Cleared Splunk SIEM Engineer

Design, develop, and enhance SIEM solutions using Splunk and Microsoft Sentinel within a secure enterprise environment. Manage data pipelines, develop correlation rules, and support security operations with strong focus on automation, incident response, and cross-platform integration. Work in a hybrid model with regular on-site presence in Cheshire.

Hays Technology Knutsford, Cheshire, United Kingdom £500 – £638 pd