Overview
In this role you will lead proactive threat hunting within a security operations context, shaping detections and response across cloud and on-prem environments. You will work closely with incident response, SIEM, and threat intelligence to hunt, enrich alerts, and block malicious activity. You’ll translate findings into practical detections and improvements, aligning with a mature security program. This remote position offers strong compensation, benefits, and the chance to influence security outcomes at scale.
Pay / Benefits
- remote working
- bonus up to 15%
- private healthcare
- medicash
- income protection
- death in service x4 salary
Responsibilities
- Run threat hunting campaigns powered by threat intelligence to plan detections and block malicious infrastructure
- Support incident response processes and SIEM operations with structured, project-based work
- Develop and tune detections, including signal selection, thresholds, and documentation for operational handoff
- Interpret endpoint telemetry (process trees, PowerShell activity, registry changes) and connect to Defender alerts
- Work with Microsoft 365/Azure logs, Exchange Online, and related services for XDR incident pivots
- Translate red team findings into practical detection improvements and escalation pathways
- Perform efficient queries (KQL) on large datasets with performance-aware patterns
Key requirements
- Experience in cyber security threat hunting and incident response
- Knowledge of Windows security concepts, AD/Entra ID, and identity attack paths
- Familiarity with Microsoft cloud technologies (Azure, Microsoft 365) and cloud security basics
- Experience with threat intelligence-led hunting and detecting malicious activity
- Proficiency in interpreting endpoint telemetry and Defender alerts
- Strong SQL-like query skills (KQL) for large datasets and time-windowing
- Understanding of authentication flows (Kerberos/NTLM/OAuth) and MFA/Conditional Access
- Nice-to-have: CEH or related ethical hacking credentials
- Threat hunting
- Incident response
- SIEM
- Azure
- Microsoft 365
- Defender (Microsoft Defender)
…
