Senior Threat Hunter (Specialist I - Information Security) - London

UST Global
London, UK
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Big Data Cyber Security Continuous Integration Data Normalization Linux Intrusion Detection and Prevention Python (Programming Language) Systems Development Life Cycle Azure Machine Learning
+9 more
Security Information and Event Management Jupyter Notebook Google Cloud Mitre Att&ck Cyber Threat Analysis Jupyter Pandas Cybercrime Microsoft Sentinel

Job description

We are looking for a Senior Threat Hunter with strong expertise in Python and Jupyter Notebooks to join our Managed Security Services team in London.This role combines advanced threat hunting with engineering capabilities, focusing on building scalable, automated, and repeatable threat hunting frameworks across large datasets in enterprise environments.Key ResponsibilitiesPerform proactive, hypothesis-driven threat hunting aligned to MITRE ATT&CKAnalyze and investigate security data across endpoint, network, and cloud environmentsIdentify indicators of compromise, suspicious activity, and emerging threatsDevelop and maintain Jupyter Notebook-based hunting frameworksBuild reusable Python modules, APIs, and automation toolsDesign and maintain data pipelines for telemetry and threat intelligence integrationAutomate hunting workflows using orchestration tools (e.g., Azure ML pipelines)Apply data normalization, validation, and correlation techniquesCollaborate with SOC, Threat Intelligence, and

Requirements

Detection Engineering teamsProduce clear and structured threat hunting reports and findingsRequired Skills & Experience5+ years of experience in Threat Hunting, Detection Engineering, or Incident ResponseStrong hands-on experience with: Python (Pandas preferred)Jupyter NotebooksExperience working with: SIEM / EDR / XDR platformsLarge-scale security telemetry and data analysisStrong understanding of: MITRE ATT&CK framework and attacker TTPsWindows and Linux operating systemsNetwork traffic and log analysisExperience in cloud threat hunting (AWS, Azure, GCP)Good understanding of: CI/CD pipelines, SDLC, and automation practicesPreferred QualificationsExperience with tools such as Microsoft Sentinel, Defender, CrowdStrike, CybereasonExperience building automation for detection validation, rule deployment, or telemetry pipelinesRelevant certifications such as GIAC, OSCP, or CEHWork ModelHybrid role based in LondonPermanent positionCollaboration with global teams

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:03 min

Accelerating pandas dataframes using cudf module plugins

Ankit Patel Ankit Patel · World Congress 2024

3:31 min

Producing candlestick visualization charts inside integrated Jupyter notebooks

Akmal Chaudhri Akmal Chaudhri · LIVE

2:35 min

Exploring diverse resources for continuous security learning

Stefania Chaplin · World Congress 2022

5:36 min

Building a data analysis stack with Python and Jupyter

Markus Harrer Markus Harrer · World Congress 2021

9:53 min

Developing programmatic training workflows using Python Jupyter Notebooks

Jose Luis Latorre Millas · LIVE

Videos

See all

Related articles

See all