Hiring.Camp

Cyber Threat Intelligence & Incident Response Specialist

Base Camp IT Recruiting

·

3 days ago

Type
Full-time
Department
Human Resources
Closing date
Today
Source
Vincere

Description

Senior Cyber Threat Intelligence & Incident Response Specialist

Overview
We are seeking a highly technical, hands-on cybersecurity professional to drive Threat Intelligence, Incident Response, and advanced threat detection. This role is suited for an experienced individual contributor who actively performs investigations, threat hunting, and
security engineering, while contributing to continuous improvement of security controls.
This role is suited for a senior individual contributor who is comfortable operating independently and leading complex investigations end-to-end.

Role Focus & Success Outcomes
● This is a hands-on, incident response and detection-focused role, where the majority of time will be spent on real-world investigations, threat hunting, and improving detection capabilities across enterprise and cloud environments.
● Act as a key technical contributor to strengthening the organisation’s end-to-end detection and response capability, from threat identification to containment and recovery.
● Drive measurable improvements in:

○ Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)

○ Detection coverage across key adversary techniques (e.g. mapped to MITRE ATT&CK)

○ Proactive threat discovery through structured hunting activities


● Contribute to building a resilient security posture aligned with organisational and regulatory expectations (e.g. CSA, PDPC where applicable)

Key Responsibilities

Threat Intelligence
• Actively collect, analyse, and operationalise intelligence from OSINT, dark web, commercial feeds, and ISACs
• Perform hands-on adversary tracking, campaign analysis, and TTP mapping (MITRE ATT&CK)
• Translate intelligence into detection rules, hunting queries, and actionable use cases
• Integrate intelligence into security tooling, including CrowdStrike, SIEM, and TIP platforms

Incident Response
• Lead and execute end-to-end incident response activities (triage, containment, eradication, recovery)
• Perform hands-on investigations across endpoints, logs, network traffic, and cloud environments
• Use EDR tools (e.g., CrowdStrike) for live response, forensic analysis, and threat hunting
• Analyse malware behaviour, attacker persistence mechanisms, and lateral movement techniques
• Produce detailed technical reports with clear root cause and remediation actions

Threat Hunting & Detection Engineering
• Develop and execute proactive threat hunting across endpoint, identity, and cloud telemetry
• Write and tune detection rules (SIEM, EDR, Sigma, KQL, Splunk, etc.)
• Validate detections through simulation and adversary emulation
• Continuously improve detection coverage based on intelligence and incident learnings

Cloud Security (Hands-On)
• Investigate and respond to threats in AWS, Azure, and GCP environments
• Analyse cloud logs (CloudTrail, Azure AD, GCP logs) for suspicious activity
• Identify misconfigurations, privilege escalation paths, and identity-based attacks
• Work directly with engineers to remediate security gaps

Brand Protection & Digital Threats
• Investigate phishing campaigns, malicious domains, and impersonation attempts
• Perform technical analysis of phishing kits, payloads, and infrastructure
• Support takedown operations with actionable evidence

Vulnerability & Exposure Management
• Correlate CVEs with real-world exploitation and internal exposure
• Validate vulnerabilities (where applicable) and assess exploitability
• Track and respond to zero-days and active exploitation campaigns
• Work closely with system owners to ensure remediation

Security Control Improvement
• Identify detection and response gaps through real incidents and hunting activities
• Implement improvements across EDR, SIEM, and cloud security controls
• Build automation scripts and workflows to improve response efficiency
• Contribute directly to playbooks, runbooks, and technical standards

Requirements
• 5–8+ years of hands-on experience in Incident Response, Threat Hunting, or Threat Intelligence
• Strong experience with EDR platforms such as CrowdStrike (querying, investigation, live response)
• Proven ability to independently investigate and respond to real-world cyber incidents
• Experience writing detection logic (KQL, SPL, Sigma, etc.)
• Solid understanding of attacker techniques (lateral movement, persistence, C2, credential abuse)
• Hands-on experience in cloud security investigations (AWS, Azure, or GCP)
• Scripting skills (Python, PowerShell, or Bash)

Preferred Qualifications
• Experience in malware analysis or digital forensics
• Familiarity with Threat Intelligence Platforms (TIPs) and SOAR
• Certifications such as GCIH, GCFA, GNFA, GCTI, CISSP, or equivalent
• Experience in regulated or high-risk environment

Skills

PythonAWSAzureGCPCybersecuritySIEMSplunkCISSP

Similar Jobs

30

Senior Cyber Threat Intelligence Analyst

UltraViolet Cyber · Hyderabad · Onsite

Yesterday

Executive Officer, GT-TSS, Cyber Threat Intelligence MY

CIMB Group Malaysia · Malaysia, MY

2 days ago

Freelance Product Owner Cyber Threat Intelligence

Engiflex · Brussels

3 days ago

Senior Associate, Cyber Threat Intelligence

Pfizer · USA - PA - Collegeville, United States of America +1 · Hybrid

4 days ago

Lead Analyst, Cyber Threat Intelligence

Pfizer · GRC - Thessaloniki, Chortiatis, Greece · Hybrid

5 days ago

Lead Analyst, Cyber Threat Intelligence

Pfizer · GRC - Thessaloniki, Chortiatis, Greece · Hybrid

5 days ago

Cyber Threat Intelligence Analyst

Booz Allen Hamilton · USA, CO, Colorado Springs (745 Space Center Dr), United States of America +2

6 days ago

Security Intelligence Engineer, Amazon Cyber Threat Intelligence

Amazon

1 week ago

Senior Intelligence Analyst, Amazon Cyber Threat Intelligence

Amazon

1 week ago

Senior Cyber Threat Intelligence (CTI) Engineer (f/m)

Robert Bosch · Warszawa, Województwo mazowieckie, Poland · Hybrid

1 week ago

Senior Cyber Threat Intelligence Analyst – CMT (Industry Intelligence & Analysis)

Accenture · Singapore, Raffles City Tower

1 week ago

Tactical Operational Cyber Threat Intelligence Analyst

Search Jobs at Releady · Hybrid

1 week ago

Analyst, Cyber Threat Intelligence

S-RM · London +1

1 week ago

Freelance — Product Owner Cyber Threat Intelligence

Engiflex · Brussels

1 week ago

AOUSC - Cyber Threat Intelligence & Threat Hunting Lead

cFocus Software Incorporated · Washington, DC

1 week ago

Cyber Threat Intelligence Analyst Subject Matter Expert

Booz Allen Hamilton · USA, VA, Arlington (1110 N Glebe Rd), United States of America

1 week ago

Cyber Threat Intelligence (CTI) Analyst

Imri · Onsite

1 week ago

Cyber Threat Intelligence Analyst

Statestreet · Quincy, Massachusetts, United States of America

2 weeks ago

Cyber Threat Intelligence Analyst

Sixgeninc · Northern Virginia +1 · Remote

3 weeks ago

Cyber Threat Intelligence Analyst (CTI) (Day Shift, Hybrid, Cubao)

Accenture · Quezon City, Cyberpark Tower 1, Philippines

3 weeks ago

Cyber Threat Intelligence Analyst - Remote

CSAA Insurance Group · Arizona - Home Teleworkers, United States of America

1 month ago

Cyber Threat Intelligence Analyst

Blackbaud · Remote - Anywhere - USA, United States of America · Remote

1 month ago

Cyber Threat Intelligence Expert

Accenture · Assago, Via del Mulino 11a, Italy +5

1 month ago

Cyber Threat Intelligence Manager - EMEA

Bank Of America · London, United Kingdom +2 · Onsite

1 month ago

Cyber Threat Intelligence Analyst

Amgen is committed to unlocking · Portugal - ACC · Hybrid

1 month ago

Cyber Threat Intelligence Hunter

Leidos · 9397 Hickam Air Force Base HI, United States of America

1 month ago

Senior Vice President, Cyber Threat Intelligence – EMEA Lead

0101022-GIA PROD US LOS ANGELES · London, London, United Kingdom, GB

1 month ago

Lead Cyber Threat Intelligence Analyst

Usbank · Cincinnati, OH, United States of America +2

1 month ago

Cyber Threat Intelligence Specialist

Vanquis · Chatham, UK +3

1 month ago

Cyber Threat Intelligence (CTI) Lead

Gunnison Consulting Group, Inc. · Washington, DC

1 month ago
Cyber Threat Intelligence & Incident Response Specialist at Base Camp IT Recruiting | Hiring.Camp