- LSEG Security Operations is a central function employing people, process and technology to continuously monitor and respond to cyber-security incidents
- Security Operations spans multiple domains including cyber threat intelligence, cyber threat detection, data loss prevention and cyber incident response
- This role sits within the Cyber Threat Intelligence (CTI) team, helping the organisation understand the cyber threats that matter most to LSEG and turn that understanding into action
- As a CTI Analyst, you will research and assess cyber threats relevant to LSEG, track adversaries and their evolving tactics, techniques and procedures (TTPs), and produce timely, actionable intelligence for consumers across Cyber Security and the wider organisation
- You will work across the intelligence lifecycle, combining information from internal telemetry, commercial and open-source intelligence, trusted intelligence-sharing communities and geopolitical reporting to identify emerging threats, answer intelligence requirements and provide assessments that support security decision-making
- The role provides the opportunity to work across tactical, operational and strategic intelligence, supporting activities including adversary tracking, threat hunting, detection engineering, vulnerability management and incident response
- Research, analyse and assess cyber threats relevant to LSEG, its customers, people, technology and global operations
- Maintain awareness of threat actors, campaigns and emerging threats, identifying changes in adversary intent, capability, targeting and TTPs
- Produce clear, concise and actionable intelligence products for technical, operational and senior consumers
- Apply structured analytical techniques and intelligence tradecraft to develop evidence-based assessments, clearly presenting analytic confidence, assumptions and intelligence gaps
- Work across all stages of the intelligence lifecycle to understand consumer intelligence requirements, collect and evaluate relevant information, produce intelligence and assess its impact
- Identify emerging threats and changes in the threat landscape, including significant vulnerabilities, attack techniques and geopolitical developments with potential implications for LSEG
- Develop intelligence-led hypotheses and work with threat hunting and detection teams to identify previously unknown or undetected malicious activity
- Provide intelligence support to cyber incidents and investigations, helping intelligence consumers understand adversary behaviour, likely objectives, TTPs and potential next steps
- Find opportunities to translate adversary intelligence into improvements to LSEG’s preventative and detective security controls
- Develop and maintain relationships with intelligence consumers, industry peers, intelligence-sharing communities and our partners
- Contribute to the continuous development of the CTI team’s processes, methodologies, tooling and other capabilities
- Stay abreast of developments across the threat landscape and continually develop expertise in adversaries and threat areas
Ability to conduct effective open-source research and critically evaluate the reliability and credibility of information and sourcesCommunicate sophisticated technical and threat information clearly to both technical and non-technical audiencesUnderstanding of attack pathways and the technologies, protocols and security controls associated with modern enterprise environmentsA curiosity about geopolitical, technological and criminal developments and their potential influence on cyber threat activitySolid understanding of the modern cyber threat landscape and adversary behaviours and TTPsStrong written analytical skills, including the ability to distinguish fact from assessment and communicate uncertainty using the appropriate intelligence lexiconDemonstrable knowledge of the MITRE ATT&CK framework and its application to CTIExcellent written and verbal communication skills, with the ability to adapt intelligence to different audiencesAbility to prioritise optimally and deliver high-quality analysis in a fast-paced environmentWillingness to continually develop technical knowledge and subject-matter expertiseStrong critical-thinking skills and the ability to challenge assumptions and draw measured conclusions from partial or sometimes contradictory informationCollaborative approach and the ability to build effective relationships with technical teams, intelligence consumers and partnersIntellectual curiosity and an authentic interest in understanding how and why cyber adversaries operateExperience working within a CTI, security operations, incident response, threat hunting or related cyber-security functionFamiliarity with scripting or data analysis using languages such as Python or PowerShellExperience developing intelligence-led threat hunting or detection hypothesesExperience working with commercial intelligence providers, information-sharing communities or industry partnershipsKnowledge of intelligence-sharing standards and technologies such as STIX/TAXIIKnowledge of structured analytical techniques or recognised intelligence analysis methodologies
#J-18808-Ljbffr
Cyber Threat Intelligence Analyst (GSOC) in London employer: London Stock Exchange
The London Stock Exchange Group is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration within the Global Security Operations team. Employees benefit from comprehensive professional development opportunities, a strong commitment to work-life balance, and the chance to contribute to cutting-edge cybersecurity initiatives in one of the world's leading financial hubs. Join us to be part of a culture that values expertise and encourages growth while making a meaningful impact in the security landscape.