Threat Intelligence & Analysis
- Research and analyse emerging cyber threats, vulnerabilities, and threat actor activity relevant to SCC customers
- Produce threat assessments and contextual intelligence on vulnerabilities, incidents, and campaigns
- Lead development of strategic, operational, and tactical threat intelligence outputs (e.g. landscape reports, advisories, digests)
- Map threats, TTPs, and campaigns to frameworks such as MITRE ATT&CK
Customer-Facing Intelligence & Reporting
- Produce and enhance customer-facing deliverables such as:
o Strategic threat landscape reports
o Threat briefings and advisories
o Technology-specific risk summaries
- Translate threat intelligence into business-relevant insights and recommendations
- Support stakeholder engagement by explaining threats in both technical and non-technical terms
Operational Integration with SOC
- Work with other SOC and threat analysts to convert intelligence into:
o Detection rules (SIEM / EDR)
o Threat hunting hypotheses
o Playbook improvements
- Provide intelligence-driven input into alert triage and incident investigations
- Support post-incident reviews with threat context and adversary insight
Vulnerability & Exposure Intelligence
- Analyse vulnerability data from Tenable and other scanning platforms to:
o Identify high-risk vulnerabilities relevant to current threat activity
o Prioritise remediation based on exploitability, exposure, and threat actor interest
- Correlate vulnerability findings with:
o Threat intelligence (active campaigns / exploitation in the wild)
o Customer environments and technology stacks
o Vulnerability threat advisories
o Risk-based prioritisation models for customers
- Work with SOC and engineering teams to ensure vulnerability intelligence informs:
o Detection use cases
o Threat hunting activities
o Customer remediation guidance
Defender & Endpoint Intelligence (MXDR Integration)
- Leverage Microsoft Defender (Endpoint, Identity, Cloud, Office) telemetry to:
o Identify emerging threat patterns and suspicious behaviours
o Support investigations with enriched threat intelligence context
- Correlate Defender alerts with known threat actor TTPs and campaigns
- Lead on:
o Identification of gaps in detection coverage
o Development of intelligence-led improvements to Defender use cases
o Exploitation techniques observed in real environments
o Trends across customer estates
Threat Monitoring & Tooling
o Dark web sources
o External attack surface exposure
o Vulnerability disclosures and exploitation trends
- Lead on evaluation and usage of threat intelligence platforms and tooling
- Maintain tracking of relevant:
o Indicators of Compromise (IOCs)
o Vulnerabilities and CVEs
o Threat actor campaigns
Service Development & Improvement
- Lead on development of SCC threat intelligence services and offerings
- Lead on refining use cases, playbooks, and detection logic based on emerging threats
- Support RFP responses, service design, and customer proposals for threat intelligence capabilities
Collaboration & Knowledge Sharing
• Work collaboratively with SOC, engineering, and solution teams
- Share threat insights across the SOC to improve collective awareness and response capability
- Maintain awareness of current and emerging threats affecting key sectors and customer environments
- Will mentor other more junior Threat Analysts