Hiring.Camp

Cyber Threat Intelligence & Incident Response Specialist

Base Camp IT Recruiting

·

Jul 22, 2026

Type
Full-time
Department
Human Resources
Closing date
Today
Source
Vincere

Description

Senior Cyber Threat Intelligence & Incident Response Specialist

Overview
We are seeking a highly technical, hands-on cybersecurity professional to drive Threat Intelligence, Incident Response, and advanced threat detection. This role is suited for an experienced individual contributor who actively performs investigations, threat hunting, and
security engineering, while contributing to continuous improvement of security controls.
This role is suited for a senior individual contributor who is comfortable operating independently and leading complex investigations end-to-end.

Role Focus & Success Outcomes
● This is a hands-on, incident response and detection-focused role, where the majority of time will be spent on real-world investigations, threat hunting, and improving detection capabilities across enterprise and cloud environments.
● Act as a key technical contributor to strengthening the organisation’s end-to-end detection and response capability, from threat identification to containment and recovery.
● Drive measurable improvements in:

○ Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)

○ Detection coverage across key adversary techniques (e.g. mapped to MITRE ATT&CK)

○ Proactive threat discovery through structured hunting activities


● Contribute to building a resilient security posture aligned with organisational and regulatory expectations (e.g. CSA, PDPC where applicable)

Key Responsibilities

Threat Intelligence
• Actively collect, analyse, and operationalise intelligence from OSINT, dark web, commercial feeds, and ISACs
• Perform hands-on adversary tracking, campaign analysis, and TTP mapping (MITRE ATT&CK)
• Translate intelligence into detection rules, hunting queries, and actionable use cases
• Integrate intelligence into security tooling, including CrowdStrike, SIEM, and TIP platforms

Incident Response
• Lead and execute end-to-end incident response activities (triage, containment, eradication, recovery)
• Perform hands-on investigations across endpoints, logs, network traffic, and cloud environments
• Use EDR tools (e.g., CrowdStrike) for live response, forensic analysis, and threat hunting
• Analyse malware behaviour, attacker persistence mechanisms, and lateral movement techniques
• Produce detailed technical reports with clear root cause and remediation actions

Threat Hunting & Detection Engineering
• Develop and execute proactive threat hunting across endpoint, identity, and cloud telemetry
• Write and tune detection rules (SIEM, EDR, Sigma, KQL, Splunk, etc.)
• Validate detections through simulation and adversary emulation
• Continuously improve detection coverage based on intelligence and incident learnings

Cloud Security (Hands-On)
• Investigate and respond to threats in AWS, Azure, and GCP environments
• Analyse cloud logs (CloudTrail, Azure AD, GCP logs) for suspicious activity
• Identify misconfigurations, privilege escalation paths, and identity-based attacks
• Work directly with engineers to remediate security gaps

Brand Protection & Digital Threats
• Investigate phishing campaigns, malicious domains, and impersonation attempts
• Perform technical analysis of phishing kits, payloads, and infrastructure
• Support takedown operations with actionable evidence

Vulnerability & Exposure Management
• Correlate CVEs with real-world exploitation and internal exposure
• Validate vulnerabilities (where applicable) and assess exploitability
• Track and respond to zero-days and active exploitation campaigns
• Work closely with system owners to ensure remediation

Security Control Improvement
• Identify detection and response gaps through real incidents and hunting activities
• Implement improvements across EDR, SIEM, and cloud security controls
• Build automation scripts and workflows to improve response efficiency
• Contribute directly to playbooks, runbooks, and technical standards

Requirements
• 5–8+ years of hands-on experience in Incident Response, Threat Hunting, or Threat Intelligence
• Strong experience with EDR platforms such as CrowdStrike (querying, investigation, live response)
• Proven ability to independently investigate and respond to real-world cyber incidents
• Experience writing detection logic (KQL, SPL, Sigma, etc.)
• Solid understanding of attacker techniques (lateral movement, persistence, C2, credential abuse)
• Hands-on experience in cloud security investigations (AWS, Azure, or GCP)
• Scripting skills (Python, PowerShell, or Bash)

Preferred Qualifications
• Experience in malware analysis or digital forensics
• Familiarity with Threat Intelligence Platforms (TIPs) and SOAR
• Certifications such as GCIH, GCFA, GNFA, GCTI, CISSP, or equivalent
• Experience in regulated or high-risk environment

Skills

PythonAWSAzureGCPCybersecuritySIEMSplunkCISSP

Similar Jobs

30

Cyber Threat Intelligence Analyst (GSOC)

LSEG · GBR-London-5 Canada Square, United Kingdom

Yesterday

Senior Director, Cyber Threat Intelligence

Kroll · New York, NY, United States, US

Yesterday

Senior Cyber Threat Intelligence Analyst

Keybank · 4910 Tiedeman Road, Brooklyn, OH, United States of America +1 · Remote

2 days ago

The Cyber Threat Intelligence & Exposure Management Analyst

Job Listings · Austin (Oakhill, Office), United States of America

4 days ago

Cyber Threat Intelligence Principal

Cybcube · London Office +1 · Hybrid

6 days ago

Cyber Threat Intelligence Lead

Cybcube · London Office +1 · Hybrid

6 days ago

Cyber Threat Intelligence III

Avav · 10800 Gibson Boulevard Southeast, Albuquerque, NM, United States of America +9

6 days ago

Tier 3 Cyber Threat Intelligence Analyst

Leidos · 10160 Washington DC, United States of America +2

1 week ago

Cyber Threat Intelligence Analyst

Booz Allen Hamilton · USA, AL, Huntsville (4946 Fowler Rd), United States of America

1 week ago

Director - Cyber Threat Intelligence (CTI)

Target · 7000 Target Pkwy N,NCD-0375 Brooklyn Park,MN 55445, United States of America

1 week ago

Senior Cyber Threat Intelligence Analyst

Job Listings · Bangalore, India

1 week ago

Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor Technologies · Auckland, Auckland, New Zealand · Remote

1 week ago

Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor Technologies · Atlanta, GA, United States · Remote

1 week ago

Vice President, Cyber Threat Intelligence Analyst, Global Information Security, Sydney, Australia

Ghr · Sydney, Australia · Onsite

1 week ago

Cyber Threat Intelligence Analyst

Deloitte Netherlands · Amsterdam, NH, Netherlands · Hybrid

1 week ago

Principal Cyber Threat Intelligence Specialist

Umiami · Offsite Remote Work - UHealth IT, United States of America · Remote

2 weeks ago

Cyber Threat Intelligence Analyst

Booz Allen Hamilton · USA, MD, Fort Meade (6910 Cooper Ave), United States of America +1

2 weeks ago

Cyber Threat Intelligence Analyst

Deloitte Netherlands · Amsterdam, NH, Netherlands · Hybrid

2 weeks ago

Cyber Threat Intelligence Analyst, Mid

Booz Allen Hamilton · USA, MD, Bethesda (6555 Rock Spring Dr), United States of America

2 weeks ago

Senior Manager, Head of Cyber Threat Intelligence

Globe · NCR - WGC, Philippines

2 weeks ago

Associate Principal Cyber Threat Intelligence Analyst

Dragos · Norfolk, VA · Remote, Onsite

2 weeks ago

Senior Cyber Threat Intelligence (CTI) Analyst

Livenation · Remote - United Kingdom +1 · Remote

2 weeks ago

Jr Industrial Control System Cyber Threat Intelligence Analyst / Active Top Secret, SCI eligibility

Peraton · Arlington, VA, US · Onsite

3 weeks ago

Open‑Source Cyber Threat Intelligence Analyst

Peraton · Arlington, VA, US · Onsite

3 weeks ago

Cyber Threat Intelligence Engineer - Director - Cybersecurity Engineering

Ms · COMMERZ III, OBEROI GARDEN CITY, India

3 weeks ago

Cyber Threat Intelligence Engineer - Director - Cybersecurity Engineering

Morgan Stanley · Mumbai, MH,IN, IN

3 weeks ago

Cyber Threat Intelligence Analyst, Associate

Morgan Stanley · SG

3 weeks ago

Cyber Threat Intelligence Analyst, Associate

Ms · IOI Central Boulevard Towers, Singapore

3 weeks ago

Associate Principal Cyber Threat Intelligence Analyst

Dragos · Singapore

3 weeks ago

Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead

Aero · Colorado Springs, United States of America · Onsite

4 weeks ago