freehire launches on Product Hunt on 26 August.

Follow →

Cyber Threat Intelligence & Incident Response Specialist

Summary

Hands-on Cyber Threat Intelligence & Incident Response Specialist leading end-to-end investigations, proactive threat hunting, and detection engineering across endpoint, network, identity, and cloud environments using CrowdStrike, SIEM, KQL/SPL, and AWS/Azure/GCP.

We are seeking an experienced and highly technical Cyber Threat Intelligence & Incident Response Specialist to strengthen our organisation’s threat detection, incident response, and cyber defence capabilities. This is a hands-on individual contributor role suited for a cybersecurity professional who is comfortable independently leading complex investigations from initial detection through containment, eradication, recovery, and post-incident improvement. The successful candidate will spend a significant portion of their time conducting real-world investigations, proactive threat hunting, developing and tuning detections, analysing threat intelligence, and improving security controls across enterprise, endpoint, identity, network, and cloud environments.

Key Responsibilities:

Threat Intelligence

  • Collect, analyse, and operationalise cyber threat intelligence from OSINT, commercial threat feeds, ISACs, dark-web sources, and other relevant intelligence channels.
  • Conduct adversary tracking, campaign analysis, infrastructure analysis, and mapping of attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.
  • Translate threat intelligence into actionable detection rules, threat-hunting queries, indicators, and security use cases.
  • Integrate threat intelligence into security platforms including SIEM, EDR, Threat Intelligence Platforms (TIPs), and CrowdStrike.
  • Monitor emerging threats, zero-day vulnerabilities, active exploitation campaigns, and changes in adversary behaviour.

Incident Response

  • Lead and execute end-to-end cybersecurity incident response activities including triage, investigation, containment, eradication, recovery, and post-incident analysis.
  • Perform investigations across endpoint telemetry, security logs, network traffic, identity systems, and cloud environments.
  • Use EDR platforms such as CrowdStrike for investigation, live response, forensic analysis, and threat hunting.
  • Investigate malware activity, credential compromise, attacker persistence, command-and-control activity, privilege escalation, and lateral movement.
  • Determine root cause, attack paths, affected systems, and overall business impact.
  • Produce detailed incident reports with clear technical findings, root-cause analysis, remediation actions, and recommendations.

Threat Hunting & Detection Engineering

  • Develop and execute structured threat-hunting activities across endpoint, identity, network, and cloud telemetry.
  • Develop, test, tune, and maintain security detections using technologies and languages such as KQL, SPL, Sigma, SIEM and EDR query languages.
  • Map detection coverage against adversary techniques using MITRE ATT&CK.
  • Validate detection effectiveness through security testing, attack simulation, and adversary-emulation exercises.
  • Identify detection gaps from incidents and threat-intelligence findings and implement improvements.
  • Drive improvements in security metrics including Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).

Cloud Security

  • Investigate and respond to security threats affecting AWS, Microsoft Azure, and/or Google Cloud Platform (GCP) environments.
  • Analyse cloud security telemetry including AWS CloudTrail, Microsoft Entra ID/Azure logs, and GCP audit logs.
  • Identify suspicious authentication activity, privilege escalation, compromised credentials, identity-based attacks, and cloud misconfigurations.
  • Work closely with infrastructure, cloud, and engineering teams to remediate identified security weaknesses.

Brand Protection & Digital Threats

  • Investigate phishing campaigns, impersonation attempts, fraudulent websites, malicious domains, and other digital threats.
  • Conduct technical analysis of phishing infrastructure, phishing kits, malicious payloads, URLs, and associated attacker infrastructure.
  • Gather and document actionable evidence to support domain, website, or infrastructure takedown activities.

Vulnerability & Exposure Management

  • Assess vulnerabilities in the context of real-world exploitation, threat intelligence, and organisational exposure.
  • Correlate CVEs with active exploitation campaigns and internal technology assets.
  • Validate vulnerabilities and assess exploitability where appropriate.
  • Monitor and respond to zero-day vulnerabilities and emerging exploitation activity.
  • Work with system owners and technical teams to prioritise and ensure timely remediation.

Security Control Improvement

  • Identify security-control and detection gaps through incident investigations, threat hunting, and threat-intelligence analysis.
  • Implement improvements across EDR, SIEM, cloud security, identity, and other security platforms.
  • Develop automation scripts and workflows to improve investigation and incident-response efficiency.
  • Contribute to the development and continuous improvement of incident-response playbooks, threat-hunting procedures, runbooks, and technical security standards.
  • Support security improvements aligned with organisational and applicable regulatory requirements, including CSA and PDPC requirements where relevant.

Requirements

  • 5–8+ years of relevant hands-on cybersecurity experience, particularly in Incident Response, Threat Hunting, Threat Intelligence, SOC operations, or Detection Engineering.
  • Strong hands-on experience with EDR platforms such as CrowdStrike, including querying, investigation, threat hunting, and live-response capabilities.
  • Demonstrated experience independently investigating and responding to complex real-world cybersecurity incidents.
  • Experience developing and tuning detection logic using KQL, SPL, Sigma, or equivalent technologies.
  • Strong understanding of attacker tactics and techniques including:
  1. Credential theft and abuse
  2. Persistence
  3. Privilege escalation
  4. Lateral movement
  5. Command and Control (C2)
  6. Defence evasion
  7. Data exfiltration
  • Good knowledge of the MITRE ATT&CK framework and its application to threat intelligence, detection engineering, and threat hunting.
  • Hands-on experience investigating security incidents within at least one major cloud platform such as AWS, Azure, or GCP.
  • Strong understanding of endpoint, network, identity, authentication, and cloud-security concepts.
  • Scripting or automation experience using Python, PowerShell, Bash, or equivalent technologies.
  • Strong analytical and problem-solving skills with the ability to independently manage investigations from identification through resolution.
  • Ability to clearly communicate complex technical findings to both technical and non-technical stakeholders.

Preferred Qualifications

  • Hands-on experience with malware analysis, digital forensics, or forensic investigation tools.
  • Experience with Threat Intelligence Platforms (TIPs), SOAR platforms, SIEM solutions, and security automation.
  • Experience performing adversary emulation or attack simulation.
  • Relevant professional certifications such as GCIH, GCFA, GNFA, GCTI, CISSP, or equivalent certifications.
  • Previous experience working in regulated, financial services, critical infrastructure, government, or other high-risk environments.

Role Success Measures

  • Success in this role will be demonstrated through measurable improvements in:
  • Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Detection coverage across relevant MITRE ATT&CK techniques.
  • Identification of previously undetected threats through proactive threat hunting.
  • Effectiveness and accuracy of security detections.
  • Reduction of recurring incidents through root-cause remediation.
  • Continuous improvement of the organisation’s overall threat detection and incident-response capability.

To apply,simply click the "Apply" button or send your updated profile to recruit@percept-solutions.com

EA Licence No.:18S9405 / EA Reg. No.:R1330864

Percept Solutions is expanding and actively seeking talented individuals. We encourage applicants to follow Percept Solutions on LinkedIn at https://www.linkedin.com/company/percept-solutions/to stay informed about new opportunities and events.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available