NMC Senior Cyber Threat Hunter
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Lead and conduct advanced threat hunting activities across national policing infrastructure, identifying indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and emerging threat patterns.
- Profile cyber adversaries by analysing behavioural patterns, infrastructure, and motivations to inform strategic and tactical defence measures.
- Collaborate with national partners including NCSC and NCA, to share your findings and coordinate responses.
- Produce high-quality, actionable reports and briefings for a range of stakeholders, including technical teams, senior police leadership, and government departments.
- Correlate and disseminate intelligence from multiple sources (OSINT, SIGINT, internal telemetry, etc.) to build a comprehensive threat picture and drive proactive defence.
- Support and lead pre-incident planning, threat modelling, and attack surface reduction initiatives.
- Act as a senior point of contact and take a lead role during live incidents, providing both written and verbal updates during a managed cyber incident to senior policing stakeholders.
- Mentor and develop NMC colleagues, fostering a culture of continuous learning and analytical excellence.
- Step into a leadership role during the managerâs absence, overseeing team operations, prioritising workloads, and ensuring service continuity.
- Drive innovation in threat hunting practices, evaluating new tools, techniques, and methodologies to enhance capability.
- Engage with internal teams (Detect and Respond, Malware Analysis, Vulnerability Management, Threat Hunting) to ensure a threat hunting mentality is integrated across all cyber defence functions.
- Translate complex threat intelligence into clear, concise insights tailored to operational, strategic, and executive audiences.
- Contribute to the development of national cyber resilience strategies and support cross-force collaboration on threat hunting findings and practice.
- Present at various senior boards and forums (internal and external) on the benefits of establishing a healthy cyber security posture., At the NMC, you will benefit from hybrid working, getting the advantages of both face-to-face team engagement and home working. NMC employees have the opportunity to work in our modern office environment for in-person collaboration, however you will also get the opportunity to work from home 2 days a week.
All applicants must be eligible to undergo NPPV3 (Non Police Personnel Vetting Level 3) and SC vetting clearances. Successful applicants will require NPPV3 clearance to have been cleared before starting with PDS.
Please note, we may choose to close the advert early if we receive a high volume of applications for this role so please endeavour to complete your application as soon as possible.
We are proud supporters of Women in Data. Connect, engage and belong to the largest free female data community in the UK - visit: www.womenindata.co.uk to join our community.
Stay connected! Follow us on LinkedIn for updates on career opportunities and more.
Requirements
- Deep understanding of adversarial tactics and techniques as well as threat actor lifecycles.
- Ability to operate in high-pressure environments with proven experience of taking a technical lead role in support of the response to a cyber incident.
- Strong experience hunting and tracking targeted threats.
- Strong grasp of threat modelling and risk assessment frameworks.
- Skilled in OSINT collection and analysis.
- Demonstrated leadership in a threat hunting team, including mentoring and service development.
- Excellent communication skills - able to translate complex threats into clear insights.
- Ability to work independently and proactively as well as manage stakeholder relationships effectively.
- Experienced in managing and coordinating as a lead within a team.
- Excellent interpersonal skills and a collaborative mindset.
- Prepared to be flexible to meet the demands during a cyber incident.
- Eligible for SC and NPPV3 clearance.
- Relevant accreditations in Cyber Threat Hunting - eg DFIR, OSINT, CREST.
- Understanding of UK policing cyber environment and its threat landscape.
- Proven experience of mentoring/leading a team.
Benefits & conditions
- Balance is important and we want you to take time off to recharge - we offer 28 daysâ annual leave plus bank holidays, rising to 30 days after 5 years of service. Holiday purchase also available.
- Flexible working hours - We trust you to do your job and we appreciate that life doesnât always fit around a 9 to 5 workday. We operate core hours of 10 to 4, Monday to Friday (37-hour week).
- We care about your well-being - we have an EAP that offers not just welfare benefits but also retail discounts.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents
Dev Digest 134 - Where pixels sing?
Data Analyst Salary in the UK
IT Salaries in UK