Threat Research Expertise
You are an experienced security analyst who operates well beyond alert-driven workflows. You can take a hypothesis, test it against real-world data, and drive investigations through to a clear, defensible outcome.
You have a deep understanding of adversary tactics, techniques, and procedures, and know how to apply that knowledge in practice. You recognise how attacks manifest across endpoint, network, identity, and cloud environments, and can translate that understanding into effective, evidence-based investigations.
Analytical Thinking
You are comfortable working with incomplete, ambiguous, or conflicting data. You can separate genuine threat activity from background noise, make sound judgements, and clearly articulate the reasoning behind your conclusions.
You approach investigations with structure and intent, combining critical thinking with curiosity to explore multiple angles. You are confident in your analysis, able to defend your decisions when challenged, and willing to reassess when new evidence emerges.
Tool Proficiency
You are highly proficient in querying and analysing large-scale security data. Whether using KQL, ES|QL, or similar, you can design and adapt complex queries and visualisations driven by your investigative hypotheses.
You are confident pivoting across multiple data sources, refining queries in real time, and extracting meaningful insight quickly. You do not rely on pre-built content, you understand how to build, optimise, and evolve your own queries to uncover activity others would miss.
Data Source Fluency
You are confident working across diverse telemetry, including endpoint, identity, network, and cloud data. You know how to pivot between these sources, quickly identifying where the signal is and how to join it up.
You can correlate activity across multiple datasets to build a clear, evidence-based view of attacker behaviour, uncovering patterns and relationships that would not be visible in a single source.
Collaborative Communication
Communicate your hypotheses, investigative approach, and findings clearly across technical and non-technical audiences. You can translate complex threat activity into concise, meaningful insights for SOC, Threat Intelligence, Incident Response, and senior stakeholders.
You work closely with cross-functional teams to embed threat hunting into day-to-day security operations, ensuring findings are understood, acted on, and drive measurable improvement. You are confident presenting your conclusions, challenging assumptions when needed, and ensuring the right decisions are made based on evidence.