Cyber Threat Intelligence Analyst
<b>Requirements:</b>
<ul><li>2 to 3 years experience in cyber threat intelligence or threat hunting</li><li>Hands-on experience with Microsoft Sentinel and Defender XDR</li><li>Strong working knowledge of KQL</li><li>Good understanding of malware, attacker TTPs and threat actor behaviour</li><li>Experience mapping activity to MITRE ATT&CK</li><li>Strong written and verbal communication skills</li><li>Comfortable working in a client-facing environment</li><li>Analytical mindset with strong attention to detail</li><li>Desirable experience includes scripting (Python), threat intelligence platforms, OSINT research and MSP or consultancy backgrounds</li></ul>
<b>Responsibilities:</b>
<ul><li>Deliver proactive threat hunting using Microsoft Sentinel and Defender XDR</li><li>Investigate Indicators of Compromise and attacker behaviour</li><li>Analyse adversary techniques using the MITRE ATT&CK framework</li><li>Develop and maintain detection logic using KQL</li><li>Collect, validate and analyse cyber threat intelligence from multiple sources</li><li>Monitor emerging threats, vulnerabilities and attack trends</li><li>Produce actionable threat intelligence reports</li><li>Present findings in client meetings and briefings</li><li>Collaborate with SOC, incident response and engineering teams</li><li>Contribute to playbooks, automation and continuous improvement</li></ul>
<b>Technologies:</b>
<ul><li>Python</li><li>Azure</li><li>Cloud</li><li>Security</li></ul>
<p><b>More:</b></p>
<p>We are a leading Microsoft Partner in Scotland looking for a permanent Cyber Threat Intelligence Analyst. This role offers a salary between £50,000 and £60,000, depending on experience, along with a range of benefits including private healthcare, contributory pension, and flexible working arrangements. You will be part of a supportive team focused on professional development, with opportunities for training and long-term career growth. Our office is based in Edinburgh, but we prioritize the right candidate over rigid office attendance.</p>
<p>last updated 8 week of 2026</p>