> Markdown version of [/jobs/ext/3281613-threat-intelligence-engineer](https://www.wearedevelopers.com/jobs/ext/3281613-threat-intelligence-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Intelligence Engineer - **Company:** Watches of Switzerland - **Location:** Narborough, UK - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Computer Telephony Integration, Intrusion Detection and Prevention, Open Source Intelligence, Security Information and Event Management, Cyber Threat Analysis, Microsoft Sentinel - **Published:** September 28, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4e34be11c720829e ## About the Role * Experience in building internal threat intelligence from the ground up. * Previous experience working within threat intelligence or similar cyber security roles. * Strong understanding of security controls, detection logic, identity systems and endpoint security. * Experience working directly with engineering teams (EDR, SIEM, Identity, Cloud, Networks) to embed intelligence into controls. * Proven ability to convert intelligence into detection logic, engineering requirements and hardening improvements. * Demonstrable experience analysing adversary TTP's, malware behaviour, exploit chains, and threat actor campaigns. * Hands on involvement providing intelligence during investigations, containment and post incident tuning. * Familiarity with threat intelligence platforms, OSINT tooling, CTI feeds, enrichment tools, and automated intelligence pipelines. * Ability to produce concise, actionable intelligence summaries for engineering and leadership. * Experience with Microsoft Sentinel SIEM/Defender automations and logic apps to support the engineering team. ## Description To begin with, the role will operate in a 60/40 split between engineering work and threat intelligence responsibilities, ensuring that immediate engineering priorities are met whilst progressively building out the organisations dedicated threat intelligence function. The ideal candidate will be responsible for identifying, analysing and operationalising cyber threat intelligence to support the organisations cyber engineering and SOC teams. This role will transform raw intelligence into technical engineering requirements, detection logic and hardening improvements, enabling the organisation to proactively defend against evolving threats and reduce risk through informed decisions.