Threat Intelligence Analyst in London

Threat Intelligence Analyst in London

London Full-Time 63000 - 77000 £ / year (est.) No working from home possible
D

At a Glance

  • Tasks: Monitor and analyse cyber threats to protect our operations and data.
  • Company: Join a global leader in manufacturing with a strong focus on security.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative team environment with a focus on continuous improvement and innovation.
  • Why this job: Make a real impact by shaping our cyber security strategy and protecting vital infrastructure.
  • Qualifications: Experience in cyber security, threat intelligence, and incident response is essential.

The predicted salary is between 63000 - 77000 £ per year.

We are looking for a skilled and proactive Threat Intelligence Analyst to join our Information Security team. This is an exciting opportunity to play a critical role in protecting DS Smith's operations, data, and infrastructure by identifying, analysing, and communicating cyber security threats. You will help strengthen our security posture through actionable threat intelligence, advanced threat hunting, and hands‑on incident response activities. Working closely with Security Operations, Incident Response, Infrastructure, and wider Technology teams, you will monitor the evolving threat landscape, investigate potential cyber threats, and support the continuous improvement of our detection and response capabilities. Leveraging Microsoft Sentinel, Microsoft Defender, DarkIQ, and other intelligence sources, you will provide timely intelligence that helps the business stay ahead of emerging threats. A core focus of the role is to transform threat intelligence into meaningful insights and practical actions, ensuring risks are understood and mitigated before they impact the organisation.

Key responsibilities include:

  • Monitoring the global threat landscape for emerging cyber threats, vulnerabilities, and threat actor activity relevant to DS Smith and the manufacturing sector
  • Analysing intelligence from multiple sources, including OSINT, commercial feeds, industry sharing platforms, and dark web monitoring tools
  • Correlating external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender
  • Developing and maintaining advanced KQL queries to support threat hunting, detection engineering, and incident investigation activities
  • Producing actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings
  • Supporting and participating in incident response activities, from initial triage through containment, eradication, recovery, and post-incident review
  • Conducting forensic investigations and providing threat context during live security incidents
  • Collaborating with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities
  • Contributing to the development of threat models, risk assessments, playbooks, and operational processes
  • Maintaining awareness of evolving cyber threats, attack techniques, and trends impacting the manufacturing and logistics sectors

This role offers an excellent opportunity to influence cyber security strategy while working as part of a collaborative team focused on protecting a global organisation.

About You

You're an experienced cyber security professional with a strong background in threat intelligence, incident response, and security operations. We're looking for:

  • Experience in cyber security, with a focus on threat intelligence, incident response, or security operations
  • Proven hands‑on experience managing security incidents throughout the full incident response lifecycle
  • Strong understanding of cyber threats, threat actor behaviour, attack methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain
  • Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation
  • Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent
  • Strong analytical skills with the ability to identify patterns and draw meaningful conclusions from complex datasets
  • Knowledge of malware analysis, phishing investigations, and infrastructure security principles
  • Experience with scripting and automation using PowerShell, Python, or similar technologies
  • Excellent communication skills, with the ability to translate technical findings into clear business-focused recommendations
  • A collaborative approach and desire to continuously improve security capabilities across the organisation

It would be advantageous if you also have:

  • Relevant industry certifications such as GCTI, GTIA, SC-200, or equivalent
  • Experience within manufacturing, logistics, or industrial environments
  • Knowledge of OT/ICS security and threats affecting operational technology environments
  • Familiarity with GDPR, NIS2, and other relevant cyber security regulations

Threat Intelligence Analyst in London employer: dssmith

At DS Smith, we pride ourselves on being an excellent employer, offering a dynamic work culture that fosters innovation and collaboration. Our London-based team enjoys a hybrid working model, competitive benefits, and ample opportunities for professional growth, making it an ideal environment for those looking to make a meaningful impact in the field of intellectual property within a sustainable manufacturing context.

D

Contact Details:

dssmith Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Threat Intelligence Analyst in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including dssmith, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through dssmith

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at dssmith. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Threat Intelligence Analyst in London

Threat Intelligence
Incident Response
Security Operations
Microsoft Sentinel
Microsoft Defender
KQL
OSINT

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at dssmith insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to dssmith that you’re committed to staying ahead in the game.

How to prepare for a job interview at dssmith

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at dssmith to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at dssmith.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.