Job Information
Functional title: Cyber Threat Intelligence Senior Analyst
Department: IT Security
Corporate level: Vice President
Report to: Executive Director, Head of CTI
Location: London
Job purpose:
CLS is seeking a highly motivated, self-driven Cyber Threat Intelligence Senior Analyst to join a global threat intelligence team. The position involves technical and strategic research and intelligence analysis of threats relevant to our industry, business, and related technologies. The ideal candidate will be aware of industry trends and frameworks and how they could impact our business, including threat actor groups, their TTPs, intrusion activities, and geopolitical relevance. The candidate will also interact with industry and government partners daily to share intelligence and mentor others on the team.
Responsibilities
- Collect, process, and disseminate cyber threat intelligence from varying sources, including open-source reports, information sharing partners, and vendor reports to create actionable results for internal stakeholders.
- Coordinate and produce strategic, operational, and tactical intelligence products for business units, technical teams, and executive stakeholders.
- Provide situational awareness on current threat landscape and maintain knowledge of adversary activities, including geopolitical implications and TTPs, to brief varying teams.
- Assess emerging threats against our operational environment and work in partnership with our security teams for detection, mitigation, and remediation efforts.
- Perform trend and correlation of cyber intelligence for recommendation-based countermeasures.
- Support and engage in incident response investigations.
- Perform basic network security analysis in support of intrusion detection operations, including the development and enrichment of indicators used to enhance network security posture.
- Review other analysts’ work and provide mentorship and guidance.
- Actively support external intelligence sharing engagements with other financial institutions and government partners.
Experience
- 6–10+ years of direct cyber threat intelligence experience.
- 5+ years of progressive experience in information security (cyber security) field, preferable in Threat Intelligence, Security Operations, or Incident Response roles.
- Understanding of intelligence lifecycle and risk management.
- Knowledge of fundamentals of threat actors’ TTP.
- Understanding of IOC validation practices and sources.
- Familiarity with MITRE ATT&CK framework and mapping.
- Geopolitical knowledge and potential impacts to the financial sector.
- Excellent interpersonal and relationship management skills.
- Individual contributor whilst also contributing to a small team.
- Self‑motivated with ability to work with minimal supervision.
- Demonstrated strong writing skills; ability to convey complex technical and non‑technical concepts.
Qualifications & Certifications
- Bachelor’s Degree in Cybersecurity studies, Intelligence Studies, International Relations, Economics, Computer Science, or related discipline.
- Security certification such as SANS GIAC (or equivalent) ideally GCTI or working towards certification (or equivalent).
- Experience with threat intelligence and SOC/CIRT interaction.
- Splunk experience.
- Experience with Threat Intelligence Platforms like ThreatConnect, ThreatQ, or Filigran.
- Experience with SIEM and other cyber security tools.
- Experience with threat intelligence vendors.
- Ability to work on‑site at least twice a week in London and/or participate in local intelligence sharing groups.
Desired Skills
- Financial sector experience.
- Developing Threat Intelligence related automations.