Alexander Ash Consulting Ltd
Threat Intelligence Analyst SC Required Overview We are seeking a skilled Threat Intelligence Analyst to join our Security team and work on a high-profile project with UK Central Government, a client frequently in the spotlight and responsible for safeguarding critical national infrastructure. This role offers a unique opportunity to contribute to the security of vital systems, gain exposure to high-stakes projects, and rapidly develop your career in a fast-paced, dynamic environment. As a Threat Intelligence Analyst, you will collaborate with Incident Responders, Security Operations, and other teams to define and prioritise cyber threat indicators. You will maintain a comprehensive understanding of the evolving threat landscape, enabling the team to provide high-level situational awareness and proactive warnings about emerging threats. Responsibilities Threat Monitoring & Analysis - Monitor and analyse various intelligence sources, including internal data, open-source reports, online databases, and restricted intelligence sources, to identify actionable areas of interest Research & Reporting - Conduct in-depth research and produce detailed reports on cybersecurity and threat intelligence topics, such as current threats, threat actors, vulnerabilities, and evolving trends in the threat landscape Indicators of Compromise (IoC) - Use IoCs such as files, IP addresses, and hashes to identify threat actors, understand their methods, and develop strategies to prevent future attacks Incident Support - Conduct investigations following the intelligence cycle, assist in handling and remediating security incidents, and support security-related programs through data analysis, assessments, and reporting Threat Modeling - Leverage common analysis techniques and frameworks, such as Kill Chain, Pyramid of Pain, MITRE ATT&CK, and Diamond Model, to enhance threat detection and response capabilities Intelligence Function Support - Contribute to the strategic, operational, and tactical components of the Intelligence function within the Threat Intelligence team, ensuring alignment with organizational security goals Why This Role Is Unique High-Profile Client - Work with a government client that is in the public eye, providing an exceptional opportunity to contribute to the security of critical national infrastructure Career Growth - The dynamic and high-stakes nature of this role offers unparalleled opportunities for professional development and hands-on experience in the cybersecurity domain Learning Opportunities - Collaborate with top-tier professionals and leverage cutting-edge tools and technologies to stay at the forefront of threat intelligence and cybersecurity Required Skills and Experience 1+ years of experience in Cybersecurity or a related field Strong understanding of threat intelligence concepts, frameworks, and methodologies Familiarity with tools and platforms used for threat intelligence and analysis, such as Recorded Future, OpenCTI, Cribl, and Splunk Knowledge of threat modelling techniques, including Kill Chain, Pyramid of Pain, MITRE ATT&CK, and Diamond Model Strong analytical and problem-solving skills with the ability to identify and prioritise actionable intelligence Active Security Clearance required Preferred Qualifications 1+ years of experience in a Threat Intelligence Analyst role Advanced certifications in cybersecurity or threat intelligence (eg, GCTI, CISSP, CEH, GIAC) Experience working with government or critical national infrastructure organizations Strong written and verbal communication skills, with the ability to produce high-quality intelligence reports and briefings
Threat Intelligence Analyst SC Required Overview We are seeking a skilled Threat Intelligence Analyst to join our Security team and work on a high-profile project with UK Central Government, a client frequently in the spotlight and responsible for safeguarding critical national infrastructure. This role offers a unique opportunity to contribute to the security of vital systems, gain exposure to high-stakes projects, and rapidly develop your career in a fast-paced, dynamic environment. As a Threat Intelligence Analyst, you will collaborate with Incident Responders, Security Operations, and other teams to define and prioritise cyber threat indicators. You will maintain a comprehensive understanding of the evolving threat landscape, enabling the team to provide high-level situational awareness and proactive warnings about emerging threats. Responsibilities Threat Monitoring & Analysis - Monitor and analyse various intelligence sources, including internal data, open-source reports, online databases, and restricted intelligence sources, to identify actionable areas of interest Research & Reporting - Conduct in-depth research and produce detailed reports on cybersecurity and threat intelligence topics, such as current threats, threat actors, vulnerabilities, and evolving trends in the threat landscape Indicators of Compromise (IoC) - Use IoCs such as files, IP addresses, and hashes to identify threat actors, understand their methods, and develop strategies to prevent future attacks Incident Support - Conduct investigations following the intelligence cycle, assist in handling and remediating security incidents, and support security-related programs through data analysis, assessments, and reporting Threat Modeling - Leverage common analysis techniques and frameworks, such as Kill Chain, Pyramid of Pain, MITRE ATT&CK, and Diamond Model, to enhance threat detection and response capabilities Intelligence Function Support - Contribute to the strategic, operational, and tactical components of the Intelligence function within the Threat Intelligence team, ensuring alignment with organizational security goals Why This Role Is Unique High-Profile Client - Work with a government client that is in the public eye, providing an exceptional opportunity to contribute to the security of critical national infrastructure Career Growth - The dynamic and high-stakes nature of this role offers unparalleled opportunities for professional development and hands-on experience in the cybersecurity domain Learning Opportunities - Collaborate with top-tier professionals and leverage cutting-edge tools and technologies to stay at the forefront of threat intelligence and cybersecurity Required Skills and Experience 1+ years of experience in Cybersecurity or a related field Strong understanding of threat intelligence concepts, frameworks, and methodologies Familiarity with tools and platforms used for threat intelligence and analysis, such as Recorded Future, OpenCTI, Cribl, and Splunk Knowledge of threat modelling techniques, including Kill Chain, Pyramid of Pain, MITRE ATT&CK, and Diamond Model Strong analytical and problem-solving skills with the ability to identify and prioritise actionable intelligence Active Security Clearance required Preferred Qualifications 1+ years of experience in a Threat Intelligence Analyst role Advanced certifications in cybersecurity or threat intelligence (eg, GCTI, CISSP, CEH, GIAC) Experience working with government or critical national infrastructure organizations Strong written and verbal communication skills, with the ability to produce high-quality intelligence reports and briefings
Alexander Ash Consulting Ltd
Security Operations Analyst SC Required Client & Project We are seeking a new talent to join the Security team, where you will have the opportunity to collaborate on a UK Central Government, a government entity focused on ensuring security and compliance. Key Responsibilities Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (eg cloud, endpoints, and networks) Collaborate with the extended security team to identify gaps in detection coverage, log ingestion and alerting based on business risks and threats Review and improve existing SecOps standards and capabilities, eg by highlighting requirements for additional logging, identifying incident or threat trends, and detection and business-as-usual optimisation opportunities Perform security monitoring, reviewing and triaging triggered alerts, and suggesting improvements (on a rota basis, 9am-5:30pm) Respond to and investigate identified cyber security incidents Act as a point of escalation for Junior Analysts, supporting them through mentorship and shadowing Operate as a technical subject matter expert on client engagements and be prepared to interact with, and present to, senior stakeholders in a consulting capacity Participate in alert testing and incident response tabletop exercises as required Remain up to date with the latest threat intelligence which may be of interest to our clients Additional Responsibilities (client dependent) Proactive threat hunting and tradecraft development Incident response and playbook development Change approvals (where applicable) Collection and interpretation of different sources of threat intelligence, and researching emerging threats and TTPs Vulnerability scanning, management and reporting On-Call Requirement This role requires approximately 1 week per month on-call availability for high-priority incident response. Please note there is additional compensation for this, and the frequency is client dependent. Desirable Attributes The successful candidate should have experience and skills in some of the following areas: Working knowledge of key threat intelligence concepts such as the Pyramid of Pain, Intelligence Preparation for the Cyber Environment (IPCE), and the Threat Intelligence Lifecycle Detection engineering and alert development Experience with Scripting and programming - eg Python/Bash/C/C++/Java Core cybersecurity concepts such as network security, cryptography, cloud security, forensics Understanding of network protocols and how they can be abused by attackers Up-to-date knowledge of the most prevalent APTs and their TTPs Knowledge of common analysis techniques associated with Windows and/or Linux
Security Operations Analyst SC Required Client & Project We are seeking a new talent to join the Security team, where you will have the opportunity to collaborate on a UK Central Government, a government entity focused on ensuring security and compliance. Key Responsibilities Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (eg cloud, endpoints, and networks) Collaborate with the extended security team to identify gaps in detection coverage, log ingestion and alerting based on business risks and threats Review and improve existing SecOps standards and capabilities, eg by highlighting requirements for additional logging, identifying incident or threat trends, and detection and business-as-usual optimisation opportunities Perform security monitoring, reviewing and triaging triggered alerts, and suggesting improvements (on a rota basis, 9am-5:30pm) Respond to and investigate identified cyber security incidents Act as a point of escalation for Junior Analysts, supporting them through mentorship and shadowing Operate as a technical subject matter expert on client engagements and be prepared to interact with, and present to, senior stakeholders in a consulting capacity Participate in alert testing and incident response tabletop exercises as required Remain up to date with the latest threat intelligence which may be of interest to our clients Additional Responsibilities (client dependent) Proactive threat hunting and tradecraft development Incident response and playbook development Change approvals (where applicable) Collection and interpretation of different sources of threat intelligence, and researching emerging threats and TTPs Vulnerability scanning, management and reporting On-Call Requirement This role requires approximately 1 week per month on-call availability for high-priority incident response. Please note there is additional compensation for this, and the frequency is client dependent. Desirable Attributes The successful candidate should have experience and skills in some of the following areas: Working knowledge of key threat intelligence concepts such as the Pyramid of Pain, Intelligence Preparation for the Cyber Environment (IPCE), and the Threat Intelligence Lifecycle Detection engineering and alert development Experience with Scripting and programming - eg Python/Bash/C/C++/Java Core cybersecurity concepts such as network security, cryptography, cloud security, forensics Understanding of network protocols and how they can be abused by attackers Up-to-date knowledge of the most prevalent APTs and their TTPs Knowledge of common analysis techniques associated with Windows and/or Linux