> Markdown version of [/jobs/ext/324025-cyber-threat-intelligence-specialist](https://www.wearedevelopers.com/jobs/ext/324025-cyber-threat-intelligence-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Specialist - **Company:** Vodafone Limited - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Open Source Technology, Pattern Recognition, Software Vulnerability Management, Cyber Threat Analysis - **Published:** June 1, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=e5f9c4626bfda966 ## About the Role Do you have experience in Incident management?, * Strong understanding of active nation-state and financially motivated threat actors targeting telecoms, enterprise networks, and critical national infrastructure, with focus on actor tactics, techniques and procedures (TTP's). * Hands-on experience producing and applying operational threat intelligence, including indicator development, attack pattern analysis, and supporting detection, response, and remediation activities. * Ability to triage, correlate, and integrate multiple intelligence sources (telemetry, open source, vendor, and partner intelligence) into clear, actionable outputs. * Effective stakeholder engagement skills across SOC, Incident Management and cyber defence teams, with the ability to communicate threat information clearly to technical audiences under operational pressure. * Experience working with external intelligence communities and information-sharing groups to enrich situational awareness and support operational security outcomes. ## Description To reduce Vodafone's cyber risk exposure by delivering timely, actionable threat intelligence that directly supports day-to-day defence, incident response, and control decisions addressing current risks across the business. The Cyber Threat Intelligence Specialist operates at Group level, focusing on analysing threat activity and adversary behaviour to produce practical intelligence that enables effective detection, response, and mitigation across Vodafone's global footprint. * Deliver operational and tactical threat intelligence on active threat actors, campaigns, and techniques impacting Vodafone's networks, IT environment, and services, with a focus on supporting detection and mitigation of threats. * Support live incidents, investigations, and Threat Action Groups by monitoring adversary activity, providing timely intelligence updates, and maintaining situational awareness throughout operational events. * Analyse threat reporting, tooling, and external intelligence to identify actionable indicators, attack patterns, and detection opportunities, feeding directly into CSOC, Incident Management, and defensive teams. * Track intelligence outcomes by assessing whether intelligence contributed to detection improvements, response actions, vulnerability remediation, or threat disruption, and feed lessons learned back into operational processes. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Unlocking the potential of Digital & IT at Vodafone](https://www.wearedevelopers.com/videos/602-unlocking-the-potential-of-digital-it-at-vodafone) - [The shadows of reasoning – new design paradigms for a gen AI world](https://www.wearedevelopers.com/videos/1000-the-shadows-of-reasoning-new-design-paradigms-for-a-gen-ai-world) - [Embracing the Hybrid Cloud: Unlocking Success with Open Source Technologies](https://www.wearedevelopers.com/videos/883-embracing-the-hybrid-cloud-unlocking-success-with-open-source-technologies) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)