Point your AI agent at freehire and let it find you a job.

Get the CLI →

SPH Media

Senior Cyber Threat Intelligence & Incident Response Specialist

Posted Updated 1 view
Discussion

Threat Intelligence
• Actively collect, analyse, and operationalise intelligence from OSINT, dark web, commercial feeds, and ISACs
• Perform hands-on adversary tracking, campaign analysis, and TTP mapping (MITRE ATT&CK)
• Translate intelligence into detection rules, hunting queries, and actionable use cases
• Integrate intelligence into security tooling, including CrowdStrike, SIEM, and TIP platforms

Incident Response
• Lead and execute end-to-end incident response activities (triage, containment, eradication, recovery)
• Perform hands-on investigations across endpoints, logs, network traffic, and cloud environments
• Use EDR tools (e.g., CrowdStrike) for live response, forensic analysis, and threat hunting
• Analyse malware behaviour, attacker persistence mechanisms, and lateral movement techniques
• Produce detailed technical reports with clear root cause and remediation actions

Threat Hunting & Detection Engineering
• Develop and execute proactive threat hunting across endpoint, identity, and cloud telemetry
• Write and tune detection rules (SIEM, EDR, Sigma, KQL, Splunk, etc.)
• Validate detections through simulation and adversary emulation
• Continuously improve detection coverage based on intelligence and incident learnings

Cloud Security (Hands-On)
• Investigate and respond to threats in AWS, Azure, and GCP environments
• Analyse cloud logs (CloudTrail, Azure AD, GCP logs) for suspicious activity
• Identify misconfigurations, privilege escalation paths, and identity-based attacks
• Work directly with engineers to remediate security gaps

Brand Protection & Digital Threats
• Investigate phishing campaigns, malicious domains, and impersonation attempts
• Perform technical analysis of phishing kits, payloads, and infrastructure
• Support takedown operations with actionable evidence

Vulnerability & Exposure Management
• Correlate CVEs with real-world exploitation and internal exposure
• Validate vulnerabilities (where applicable) and assess exploitability
• Track and respond to zero-days and active exploitation campaigns
• Work closely with system owners to ensure remediation

Security Control Improvement
• Identify detection and response gaps through real incidents and hunting activities
• Implement improvements across EDR, SIEM, and cloud security controls
• Build automation scripts and workflows to improve response efficiency
• Contribute directly to playbooks, runbooks, and technical standards

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available