Overview
In this role you lead day-to-day threat intelligence, hunting and detection engineering within UCL’s Security Operations. You will translate intelligence and incident evidence into practical improvements for detections, playbooks and security controls, working with analysts, technical teams and stakeholders. You’ll shape UCL’s defensive posture through coaching, clear communication and evidence-based decisions. This is a chance to advance security capabilities in a leading university and influence how threats are detected and mitigated across the organization.
Pay / Benefits
- 41 days holiday (27 days annual leave, 8 bank holidays, 6 closure days)
- Defined benefit CARE pension
- Cycle to work scheme
- On-site gym
- On-site nursery
- Relocation scheme for certain posts
Responsibilities
- Lead day-to-day threat intelligence, threat hunting and detection engineering activities
- Maintain intelligence requirements and threat model; produce actionable intelligence
- Plan and conduct threat hunts; identify opportunities to improve detection coverage
- Turn intelligence, hunt findings and incident evidence into improvements to detections, playbooks, tooling and controls
- Provide coaching and direction to colleagues; communicate complex threat information clearly
- Support evidence-based decisions about UCL’s defensive posture
- Collaborate with analysts, technical teams, service providers and stakeholders across UCL
- Ensure actions are tracked, assigned and completed across teams
Key requirements
- Significant experience in cyber threat intelligence, threat hunting, detection engineering, SOC operations or related security work
- Strong knowledge of intelligence requirements, threat modelling and analytical methods
- Experience with hunt planning, telemetry analysis, detection coverage and false-positive management
- Experience using security tooling such as SIEM, TIP, SOAR, CTEM and related platforms
- Ability to translate threat findings into improved detections, reporting, playbooks and tooling
- Strong communication, both written and verbal, to technical and non-technical audiences
- Ability to organise multiple activities, maintain documentation and track actions
- Experience providing day-to-day leadership, coaching or technical direction
- Strong communication skills
- Leadership and coaching ability
- Organisational skills and prioritisation
- SIEM
- TIP
- SOAR
…
