> Markdown version of [/jobs/ext/3315653-cyber-threat-intelligence-analyst-gsoc](https://www.wearedevelopers.com/jobs/ext/3315653-cyber-threat-intelligence-analyst-gsoc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Analyst (GSOC) - **Company:** London Stock Exchange Group - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Computer Telephony Integration, Information Leak Prevention, Intelligence Analysis, Intrusion Detection and Prevention, Python (Programming Language), Open Source Technology, Open Source Intelligence, Windows PowerShell, Software Vulnerability Management, Scripting, Mitre Att&ck, Cyber Threat Analysis, Cybercrime - **Published:** September 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0237a1fcc6e9def8 ## About the Role * Solid understanding of the modern cyber threat landscape and adversary behaviours and TTPs. * Demonstrable knowledge of the MITRE ATT&CK framework and its application to CTI. * Understanding of attack pathways and the technologies, protocols and security controls associated with modern enterprise environments. * Ability to conduct effective open-source research and critically evaluate the reliability and credibility of information and sources. * Communicate sophisticated technical and threat information clearly to both technical and non-technical audiences. * Strong written analytical skills, including the ability to distinguish fact from assessment and communicate uncertainty using the appropriate intelligence lexicon. * A curiosity about geopolitical, technological and criminal developments and their potential influence on cyber threat activity., * Experience working within a CTI, security operations, incident response, threat hunting or related cyber-security function. * Experience developing intelligence-led threat hunting or detection hypotheses. * Familiarity with scripting or data analysis using languages such as Python or PowerShell. * Knowledge of intelligence-sharing standards and technologies such as STIX/TAXII. * Experience working with commercial intelligence providers, information-sharing communities or industry partnerships. * Knowledge of structured analytical techniques or recognised intelligence analysis methodologies., * Intellectual curiosity and an authentic interest in understanding how and why cyber adversaries operate. * Strong critical-thinking skills and the ability to challenge assumptions and draw measured conclusions from partial or sometimes contradictory information. * Excellent written and verbal communication skills, with the ability to adapt intelligence to different audiences. * Ability to prioritise optimally and deliver high-quality analysis in a fast-paced environment. * Collaborative approach and the ability to build effective relationships with technical teams, intelligence consumers and partners. * Willingness to continually develop technical knowledge and subject-matter expertise. ## Description LSEG Security Operations is a central function employing people, process and technology to continuously monitor and respond to cyber-security incidents. Security Operations spans multiple domains including cyber threat intelligence, cyber threat detection, data loss prevention and cyber incident response. This role sits within the Cyber Threat Intelligence (CTI) team, helping the organisation understand the cyber threats that matter most to LSEG and turn that understanding into action. As a CTI Analyst, you will research and assess cyber threats relevant to LSEG, track adversaries and their evolving tactics, techniques and procedures (TTPs), and produce timely, actionable intelligence for consumers across Cyber Security and the wider organisation. You will work across the intelligence lifecycle, combining information from internal telemetry, commercial and open-source intelligence, trusted intelligence-sharing communities and geopolitical reporting to identify emerging threats, answer intelligence requirements and provide assessments that support security decision-making. The role provides the opportunity to work across tactical, operational and strategic intelligence, supporting activities including adversary tracking, threat hunting, detection engineering, vulnerability management and incident response., * Research, analyse and assess cyber threats relevant to LSEG, its customers, people, technology and global operations. * Maintain awareness of threat actors, campaigns and emerging threats, identifying changes in adversary intent, capability, targeting and TTPs. * Produce clear, concise and actionable intelligence products for technical, operational and senior consumers. * Apply structured analytical techniques and intelligence tradecraft to develop evidence-based assessments, clearly presenting analytic confidence, assumptions and intelligence gaps. * Work across all stages of the intelligence lifecycle to understand consumer intelligence requirements, collect and evaluate relevant information, produce intelligence and assess its impact. * Identify emerging threats and changes in the threat landscape, including significant vulnerabilities, attack techniques and geopolitical developments with potential implications for LSEG. * Develop intelligence-led hypotheses and work with threat hunting and detection teams to identify previously unknown or undetected malicious activity. * Provide intelligence support to cyber incidents and investigations, helping intelligence consumers understand adversary behaviour, likely objectives, TTPs and potential next steps. * Find opportunities to translate adversary intelligence into improvements to LSEG's preventative and detective security controls. * Develop and maintain relationships with intelligence consumers, industry peers, intelligence-sharing communities and our partners. * Contribute to the continuous development of the CTI team's processes, methodologies, tooling and other capabilities. * Stay abreast of developments across the threat landscape and continually develop expertise in adversaries and threat areas. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)