Principal Threat Intelligence Analyst

Location
Remote
Salary
60000 - 70000 GBP Per Year
Contract type
Permanent
Published at
22nd September, 2026
Job ref
1418
James Gallen

James Gallen

Share job

About the Role

We are supporting a leading cyber security organisation in the search for a Principal Threat Intelligence Analyst to join their growing Security Operations function.

This is a senior technical position responsible for leading and developing Threat Intelligence capabilities across strategic, operational, tactical and technical intelligence disciplines. The successful candidate will play a key role in delivering actionable intelligence services, supporting customers across a range of industries, and providing technical leadership within an established cyber security team.

You will work closely with Security Operations, Incident Response, Threat Hunting and Detection Engineering teams, helping to identify emerging threats, assess risk and enhance customers' security postures through intelligence-led decision making.

Key Responsibilities

  • Lead the production, review and quality assurance of strategic, operational, tactical and technical threat intelligence.
  • Develop threat profiles, intelligence requirements and threat landscape assessments for a diverse customer base.
  • Monitor and assess cyber threat actors, ransomware groups, malware campaigns, vulnerabilities and wider geopolitical developments.
  • Lead vulnerability intelligence activities, applying threat-informed analysis to help prioritise cyber risks.
  • Oversee Digital Risk Protection activities, identifying external threats, exposures and risks affecting customers.
  • Conduct advanced OSINT investigations and threat actor research, leveraging frameworks such as MITRE ATT&CK and the Diamond Model.
  • Support Security Operations, Incident Response, Detection Engineering and Threat Hunting teams through intelligence-led analysis and enrichment.
  • Assess supply chain and third-party risks, including breaches, exposed credentials and indirect attack vectors.
  • Produce high-quality intelligence reports, advisories and briefings for both technical and executive audiences.
  • Manage Requests for Intelligence and ensure collection and analysis activities are aligned to customer requirements.
  • Maintain and improve intelligence methodologies, governance processes and reporting standards.
  • Provide mentoring, guidance and quality assurance support to Threat Intelligence Analysts.
  • Support the evaluation and development of threat intelligence platforms, tooling and service offerings.
  • Ensure all intelligence activities are delivered in line with legal, ethical and information handling requirements.

Skills & Experience

Essential

  • Significant experience within Cyber Threat Intelligence, cyber investigations or intelligence-led security operations.
  • Strong analytical and critical thinking skills with the ability to assess source reliability, threat relevance and confidence levels.
  • Excellent knowledge of cyber threat actors, cybercrime trends, ransomware, vulnerabilities and adversary tactics, techniques and procedures (TTPs).
  • Experience working with OSINT methodologies, threat intelligence platforms, Digital Risk Protection solutions and/or dark web intelligence.
  • Broad understanding of enterprise networks, cloud technologies, operating systems, identity services and cyber security controls.
  • Experience applying frameworks such as MITRE ATT&CK, the Diamond Model, Cyber Kill Chain and the intelligence lifecycle.
  • Excellent written and verbal communication skills, with the ability to engage technical, business and executive stakeholders.
  • Proven experience providing technical leadership, mentoring and quality assurance within a cyber security environment.
  • Eligible to obtain Security Clearance (SC).

Desirable

  • Professional certifications such as GIAC GCTI, CREST CRTIA/CPTIA, CTIA or equivalent.
  • Experience in Threat Hunting, Detection Engineering or intelligence-led Red/Purple Team activities.
  • Familiarity with platforms such as OpenCTI, MISP, Recorded Future, CrowdStrike, Mandiant, FortiRecon or similar technologies.
  • Exposure to malware analysis, incident response, digital forensics or adversary infrastructure tracking.
  • Experience delivering customer-facing Threat Intelligence services or consultancy engagements.
  • Knowledge of threat modelling methodologies and intelligence-led threat scenario development.

What's on Offer?

  • Opportunity to work with a highly capable cyber security team.
  • Exposure to complex and evolving threat landscapes.
  • A collaborative environment focused on innovation and continuous improvement.
  • The chance to influence and shape the development of Threat Intelligence capabilities and services.
  • Hybrid working and ongoing professional development opportunities
Apply today