Threat Hunting Specialist
Anson McCade
Cheltenham, United Kingdom
2 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Intermediate Compensation
£ 60KJob location
Remote
Cheltenham, United Kingdom
Tech stack
Intrusion Detection and Prevention
Kusto Query Language
Security Information and Event Management
Mitre Att&ck
Cyber Threat Analysis
Cybercrime
Microsoft Sentinel
Splunk
Requirements
- 3+ years' commercial experience in Threat Hunting, Detection Engineering, or a similar cybersecurity role
- Hands-on experience developing and tuning security use cases and detections
- Strong experience with Splunk Enterprise Security and writing complex SPL (Search Processing Language) queries
- Experience with Microsoft Sentinel and KQL
- Knowledge of SIEM technologies and security monitoring best practices
- Strong understanding of the MITRE ATT&CK framework
- Experience creating correlation searches, analytics rules and custom detections
- Familiarity with threat intelligence, IOC analysis and TTP-driven investigations
- Strong communication skills with the ability to explain technical concepts clearly
If you're passionate about proactive threat detection, and enjoy building security content that makes a measurable impact, we'd love to hear from you. Apply today, or reach out to Sarah McMahon for a confidential discussion.
Benefits & conditions
Salary: Up to £60,000 + package
This is an opportunity to play a key role in developing detection capabilities, proactively identifying threats, and enhancing security monitoring across complex enterprise environments.
What You'll Be Doing
- Develop, implement and maintain security detection use cases across SIEM platforms
- Create and optimise correlation rules, alerts and threat detection content
- Conduct proactive threat hunting activities to identify emerging threats and adversary behaviours
- Map detections and hunting activities to the MITRE ATT&CK framework
- Analyse threat intelligence and convert findings into actionable detections
- Continuously tune and improve detections to reduce false positives and improve coverage
- Investigate suspicious activity and support incident response where required
- Collaborate with security engineers, SOC analysts and stakeholders to mature detection capabilities
- Validate detections through attack simulation and adversary emulation techniques