> Markdown version of [/jobs/ext/3042770-threat-specialist](https://www.wearedevelopers.com/jobs/ext/3042770-threat-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Specialist - **Company:** Drw. - **Location:** London, UK - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Data Analysis, Apple Mac Systems, Bash Shell, Cloud Computing Security, Computer Programming, Linux, Digital Forensics, Perl (Programming Language), Event Logging, Github, Network Packet, Python (Programming Language), Open Source Technology, Windows PowerShell, Phishing, Ruby, Web Application Security, Security Information and Event Management, EndPointSecurity, In-Plane Switching (IPS), Computer Network Technologies, Malware, Security Orchestration, Automation & Response - **Published:** September 24, 2026 - **Apply:** https://startup.jobs/threat-specialist-drw-10164690 ## About the Role * A bachelor's degree, or equivalent experience for 1-3 years in industry * Interest in digital forensics and physical security * A passion for security and problem solving * Heightened attention to detail and forward thinking * Strong knowledge of either Windows, MacOS, or Linux with an interest in learning the details of platforms that you might not have experience with * Knowledge of the Incident Response Cycle * Knowledge of static & dynamic malware analysis, including network packet captures * Knowledge of core networking & cloud security concepts * Experience with Security Information and Event Management (SIEM) products * Experience with Endpoint Detection & Response (EDR) products * Experience with SOAR (Security Orchestration, Automation, and Response) products * Experience with data analysis of events in security related sources such as IPS, Web Security, Endpoint Protection, Event Logs * Experience working with GitHub * Experience with PowerShell, Bash, Python, Ruby, or Perl * Exceptional time management skills * Excellent verbal and written communication skills ## Description * Perform triage of global security alerts generated from various sources (including IPS, Web Security, Event Logs, Endpoint Protection, Brand Protection, Phishing) * Respond to any incidents identified from analysis of security alerts * Triage & route internal support tickets sent to the Security team * Creation & revision of threat detections * Perform SIEM product administration for event correlation and threat detection * Perform SOAR playbook/dashboard management and product administration * Provide insider threat investigation assistance to teams of internal stakeholders * Drive automated detection, response, and configuration through various scripting and programming languages * Evaluate commercial and open-source tools as needed * Collaborate with internal Infosec peers to continuously improve security posture * Contribute to internal documentation of standard processes & procedures * Educate users on security best practices * Assess security risks as they relate to new projects and initiatives * Attend security conferences, seminars, and regular training to stay ahead of the ever-changing security landscape ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)