Threat Intelligence Analyst

Threat Intelligence Analyst

Posted 1 day ago by BAE Systems

Negotiable
Undetermined
Hybrid
London, England, United Kingdom

Summary: The Threat Intelligence Analyst at BAE Systems Digital Intelligence is responsible for the operation and enhancement of a dedicated Security Operations Centre (SOC) to protect critical national infrastructure in the UK. This role involves producing threat assessments, maintaining threat data, and conducting analysis to understand and mitigate potential threats. The position requires existing security clearance and involves working in a shift-based, 24/7 environment. The role emphasizes collaboration and communication within a diverse team to address complex security challenges.

Key Responsibilities:

  • Produce and maintain threat assessments to understand the customer threat landscape.
  • Maintain the IoC database and ensure timely updates to detection systems.
  • Update threat profiles and modelling to detail detection and controls in place.
  • Gather and maintain TI requirements for monitoring and researching threats.
  • Oversee collection and validation of threat data from various sources.
  • Conduct analysis to identify threat groups' identities, motivations, and capabilities.

Key Skills:

  • Experience in developing threat intelligence products for diverse audiences.
  • Proficiency in malware analysis and reverse engineering.
  • Ability to conduct threat assessments and define intelligence requirements.
  • Advanced knowledge of Windows and Linux operating systems.
  • Understanding of core networking concepts and malware behavior.
  • Strong analytical skills and problem-solving capabilities.
  • Excellent written and verbal communication skills.
  • Experience in client-side consulting and stakeholder engagement.
  • Ability to lead and manage small technical teams.
  • Self-motivated with the ability to motivate others.

Salary (Rate): undetermined

City: London

Country: United Kingdom

Working Arrangements: hybrid

IR35 Status: undetermined

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

Location(s): UK, Europe & Africa : UK : London || UK, Europe & Africa : UK : Leeds

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

Job Title: Threat Intelligence Analyst

Requisition ID: 122576

Location: London – We offer a range of hybrid and flexible working arrangements – please speak to your recruiter about the options for this particular role.

Grade: GG11

Referral Bonus: £5,000

Threat Intelligence Analyst Role description

To undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure cloud platforms, with many systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC Analyst roles are ‘hands-on’ shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC’s SIEM and SOAR toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance. Due to timelines for the start of operations, it will not be possible to sponsor new clearances so candidates must have existing clearances.

Responsibilities

  • Produce and maintain threat assessments to provide a clear understanding of the customer threat landscape.
  • Maintain the IoC database tailored to the monitored environment and threats and ensure changes are pushed to the detection systems in a timely manner.
  • Maintain threat profiles and threat modelling and applicability to the monitored estate along with updating the modelling to detail what detection and controls are in place to mitigate the threats.
  • Gather and maintain a set of TI requirements that define the threats that will be monitored, tracked and researched by the TI Team.
  • Oversee the collection, collation and maintenance of threat data collected from open and closed sources and ensure it appropriately validated.
  • Conduct analysis and research to determine the identity, motivations, relationships, targets / victims, capabilities, tooling and infrastructure of threat groups relevant to customer.

Requirements

Technical

  • Working in a Threat Intelligence team developing threat intelligence products for technical and non-technical audiences.
  • Performing malware analysis and reverse engineering.
  • Conducting threat assessments and defining threat intelligence requirements.
  • Developing and maintaining threat data sources.
  • Advanced knowledge of Windows and Linux operating systems and use of the command line.
  • Advanced knowledge of core networking concepts and technologies e.g. TCP/IP.
  • Intermediate knowledge of malware behaviour and techniques employed by attackers to evade security controls.
  • Intermediate knowledge of malware analysis and reverse engineering techniques.

Non-technical

  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing)
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Team player and adept at working in multi-disciplinary and diverse teams
  • Proven analytical skills capable of solving new and complex technical problems.
  • Excellent written and verbal communication skills with the ability to communicate the impact and importance of detailed technical information to non-technical and senior audiences.
  • Leading and managing small teams of highly skilled technical people.
  • Managing and building relationships with customer and internal stakeholders.
  • Self-motivated and motivates others keeping morale and performance high.

Why BAE Systems ?

This is a place where you’ll be able to make a real difference. You’ll be part of an inclusive culture that values diversity, rewards integrity, and merit, and where you’ll be empowered to fulfil your potential. We welcome candidates from all backgrounds and particularly from sections of the community who are currently underrepresented within our industry, including women, ethnic minorities, people with disabilities and LGBTQ+ individuals. We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.

PLEASE NOTE : You're expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development. We know there may be individual circumstances that impact this, so please discuss this with your line manager or HR Business Partner (HRBP). If you don't feel you can talk to your line manager, you can contact your HRBP. Should you be invited for interview, you will be giving consent for the Recruitment team to contact you and your line manager regarding your application for this opportunity.

This vacancy is eligible for the UK Employee Referral Scheme. Amount: £5000

Life at BAE Systems Digital Intelligence

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we’re working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential.

Division overview: Government

At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Government contracts are an area we have many decades of experience in. Government and key infrastructure networks are critical targets to defend as the effects of these networks being breached can be devastating. As a member of the Government business unit, you will defend the connected world and ensure the protection of nations. We all have a role to play in defending our clients, and this is yours.