Threat Analyst
π° Β£35,000 plus large company benefits
π Hybrid - Birmingham, three days a week on site
Company & role
This role sits with a large, well established IT services provider that runs a busy managed security practice, delivering SOC and managed detection and response across public and private sector customers. They have invested heavily in their security operations centre and are building out the threat and vulnerability side of the service, which is where this role comes in.
This is a strong next step for a SOC analyst who wants to move into threat and vulnerability work properly. The focus is exposure, working with vulnerability data, working out what is genuinely high risk based on what is being exploited in the wild, and helping customers understand what to fix first.
You will sit alongside experienced analysts, get hands on with the tooling, and build real depth over time. You are not expected to arrive as a seasoned specialist. You are expected to have a solid SOC grounding and the appetite to grow into it.
Day to day you will work with vulnerability data from Tenable and telemetry from Microsoft Defender, using threat context to separate the noise from the risks that actually matter. Eligibility for UK Security Clearance is required.
Why This Role Stands Out
- A genuine route out of pure SOC monitoring and into threat and vulnerability work, with the support to actually make the move
- Real depth in vulnerability and exposure management, learning to prioritise what matters using live threat context rather than just chasing CVSS scores
- Hands on exposure to a strong tooling stack including Tenable and the full Microsoft Defender suite
- You will learn from experienced analysts rather than being thrown in alone, with proper support built into the role
- The backing of a large, stable business that has invested heavily in its security operations centre
- Clear scope to develop, the person who held this remit before progressed into engineering, so there is a visible path
Key Responsibilities
- Work with vulnerability data from Tenable to identify and prioritise high risk exposure across customer environments
- Use threat context, active campaigns and exploitation in the wild, to judge which vulnerabilities genuinely matter and in what order
- Work with CVEs and CVSS scoring, tracking new disclosures and exploitation trends and translating them into clear priorities
- Use Microsoft Defender telemetry across endpoint, identity, cloud and Office to spot emerging patterns and support investigations
- Map threats, TTPs and campaigns to frameworks such as MITRE ATT&CK
- Work closely with the wider SOC to feed findings into triage, detections and remediation, and build towards producing threat and vulnerability briefings for customers
Ideal Experience
- Experience working in a SOC, with a good understanding of the current threat landscape
- Exposure to vulnerability and threat tooling, ideally Tenable and Microsoft Defender or similar
- Solid working knowledge of CVEs, CVSS, MITRE ATT&CK and the common types of threats and data breaches
- Genuinely keen to move into threat and vulnerability work and develop into it
- A clear communicator who can explain technical detail in a way that makes sense to others
- Eligibility for UK Security Clearance is essential
If you are a SOC analyst ready to move into threat and vulnerability work, and you want to build real depth in exposure and prioritisation somewhere that has invested properly in its security operations, this is well worth a look.
Threat Analyst in Birmingham employer: Cloud People
Cloud People is an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. With opportunities for professional growth and the flexibility of hybrid work, employees can thrive in a supportive environment while contributing to cutting-edge AI solutions for the finance sector. The unique blend of working in London with travel to the UAE enhances both personal and professional experiences, making it a rewarding place to build your career.