Threat Hunting and Detection Engineering Analyst - Cheltenham
Role details
Job location
Tech stack
Job description
As a member of the SOC Content Team, you will be responsible for contributing to the creation, deployment, and tuning of threat detection content and delivery of proactive threat hunting. You will work in close partnership with client Lead Analysts, threat intelligence teams, and other SOC functions to help ensure that detection strategies are tailored to each client's threat profile and security objectives.
This role offers a balance of technical hands-on work, collaboration, and knowledge sharing, with a strong emphasis on continual learning and process improvement.
Why Accenture?
You'll work on complex and innovative cybersecurity projects, leveraging the latest technologies alongside a global network of experts. We provide access to industry-leading training, professional development, and opportunities to build a rewarding long-term career.
Key Responsibilities:
Threat Detection Use Case Development: design and implement detection logic aligned to specific threat scenarios, using industry frameworks such as MITRE ATT&CK. Maintain detection content throughout its lifecycle - from development and testing to deployment and tuning. Work with client Lead Analysts to ensure content relevance and effectiveness in detecting threats across various environments.
Proactive Threat Hunting: conduct hypothesis-driven threat hunts based on client telemetry, threat intelligence, and observed anomalies. Use available data sources and tools to identify suspicious or malicious activity that may bypass existing detections. Document and present findings in a clear and actionable format for both internal teams and clients.
Content QA and Maintenance: participate in the review and validation of detection content prior to deployment. Assist in updating runbooks, SOPs, and detection playbooks to reflect changes in tools, threats, or client requirements. Support efforts to maintain consistency, accuracy, and quality in all delivered content.
Collaboration & Knowledge Sharing: actively engage with the wider SOC, threat intelligence, and tooling teams to refine detection strategies. Share insights, findings, and improvements with team members through documentation, workshops, or informal sessions. Support cross-team initiatives and help drive a culture of continuous improvement and innovation.
Requirements
- Previous experience working in a SOC, Threat Hunting, Detection Engineering, or Cyber Security Operations environment.
- Experience developing, testing, and tuning threat detection use cases.
- Good understanding of the MITRE ATT&CK framework and common threat actor tactics, techniques, and procedures (TTPs).
- Experience conducting proactive threat hunting and analysing security telemetry.
- Strong analytical, investigation, and communication skills.
- Ability to collaborate effectively with SOC analysts, threat intelligence teams, and other security stakeholders.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk etc