Senior Threat Hunter (Specialist I - Information Security) - London

UST
London, UK
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Data Analysis Microsoft Azure Big Data Cloud Computing Cyber Security Computer Networks Continuous Integration Data Normalization Linux
+14 more
Intrusion Detection and Prevention Python (Programming Language) Log Analysis Network Forensics Systems Development Life Cycle Azure Machine Learning Security Information and Event Management Jupyter Notebook Google Cloud Mitre Att&ck Cyber Threat Analysis Pandas Cybercrime Microsoft Sentinel

Job description

We are looking for a Senior Threat Hunter with strong expertise in Python and Jupyter Notebooks to join our Managed Security Services team in London. This role combines advanced threat hunting with engineering capabilities, focusing on building scalable, automated, and repeatable threat hunting frameworks across large datasets in enterprise environments., * Perform proactive, hypothesis-driven threat hunting aligned to MITRE ATT&CK

  • Analyze and investigate security data across endpoint, network, and cloud environments
  • Identify indicators of compromise, suspicious activity, and emerging threats
  • Develop and maintain Jupyter Notebook-based hunting frameworks
  • Build reusable Python modules, APIs, and automation tools
  • Design and maintain data pipelines for telemetry and threat intelligence integration
  • Automate hunting workflows using orchestration tools (e.g., Azure ML pipelines)
  • Apply data normalization, validation, and correlation techniques
  • Collaborate with SOC, Threat Intelligence, and Detection Engineering teams
  • Produce clear and structured threat hunting reports and findings

Requirements

Do you have experience in Windows?, * 5+ years of experience in Threat Hunting, Detection Engineering, or Incident Response

  • Strong hands-on experience with:
  • Python (Pandas preferred)
  • Jupyter Notebooks
  • Experience working with:
  • SIEM / EDR / XDR platforms
  • Large-scale security telemetry and data analysis
  • Strong understanding of:
  • MITRE ATT&CK framework and attacker TTPs
  • Windows and Linux operating systems
  • Network traffic and log analysis
  • Experience in cloud threat hunting (AWS, Azure, GCP)
  • Good understanding of:
  • CI/CD pipelines, SDLC, and automation practices

Preferred Qualifications

  • Experience with tools such as Microsoft Sentinel, Defender, CrowdStrike, Cybereason
  • Experience building automation for detection validation, rule deployment, or telemetry pipelines
  • Relevant certifications such as GIAC, OSCP, or CEH, advanced persistent threat,threat hunting,jupyter notebook,python,network traffic analysis

About the company

UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact-touching billions of lives in the process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:03 min

Accelerating pandas dataframes using cudf module plugins

Ankit Patel Ankit Patel · WWC 2024

3:28 min

Defining big data and machine learning fundamentals

Ayon Roy · LIVE

2:35 min

Exploring diverse resources for continuous security learning

Stefania Chaplin · WWC 2022

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all