Senior Security Specialist - Threat Hunting

Yolk Recruitment Ltd
Cardiff, UK
7 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Data Analysis Cloud Computing Cyber Security EHealth Intrusion Detection and Prevention Kusto Query Language Security Information and Event Management Data Logging Software Security Cybercrime Microsoft Sentinel Tools for Reporting

Job description

Support Digital Health and Care Wales in protecting critical systems, applications and sensitive data by leading proactive threat hunting, improving detection capabilities, and providing expert cyber security guidance. The role is a senior technical position within the Cyber Security Operations Centre (CSOC) and includes participation in the cyber on-call rota., * Lead proactive threat hunting using intelligence-led and hypothesis-driven approaches.

  • Investigate complex security incidents and provide technical escalation within the CSOC.
  • Develop and optimise SIEM detections, analytics, use cases and KQL queries to improve threat detection and reduce false positives.
  • Identify gaps in logging, monitoring and telemetry across cloud, identity, endpoint, network and application environments.
  • Analyse threat intelligence and emerging risks to improve cyber resilience.
  • Produce technical reports, recommendations and threat hunting outcomes.
  • Provide expert security advice and mentor colleagues through training and knowledge sharing.
  • Collaborate with technical teams and stakeholders to enhance cyber security capabilities across NHS Wales.

Requirements

  • Degree (or equivalent experience) in Cyber Security, IT or a related technical discipline.
  • Strong knowledge of cyber security operations, threat hunting, incident response and security monitoring.
  • Experience with SIEM platforms (ideally Microsoft Sentinel), KQL or similar analytics tools.
  • Good understanding of cloud, endpoint, identity, network and application security.
  • Knowledge of security frameworks such as NIST or ISO 27001.

Experience

  • Proven experience in cyber security operations, SOC, incident response or threat hunting within a complex environment.
  • Experience analysing security events and telemetry from multiple sources.
  • Experience improving detection capabilities, developing security use cases and tuning SIEM alerts.
  • Experience producing technical reports and security recommendations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all