Cyber Threat Intelligence Specialist

Cyber Threat Intelligence Specialist

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Mews

At a Glance

  • Tasks: Build a cutting-edge Cyber Threat Intelligence service from the ground up.
  • Company: Join Mews, a transformative tech company in the hospitality industry.
  • Benefits: Enjoy unlimited holiday, flexible working, and a generous learning budget.
  • Other info: Dynamic, remote-first environment with strong team collaboration and growth opportunities.
  • Why this job: Make a real impact in cybersecurity while working with innovative technology.
  • Qualifications: Experience in threat intelligence and a passion for building impactful solutions.

The predicted salary is between 63000 - 77000 £ per year.

Help make the world more hospitable. The hospitality industry is uniquely human, and it deserves technology that’s just as inspiring as the people behind it. At Mews, we’re transforming the industry with a platform that helps hotels run smarter, move faster and create better guest experiences. You’ll work with smart, curious people who care deeply about what they do. You’ll have autonomy and the trust to make good decisions and move quickly. And you’ll enjoy a real sense of purpose as you see the impact of what we’re building.

If you’re motivated by ownership, curiosity and meaningful impact, and are driven to deliver consistent high performance, you’ll feel at home here.

About the role: Building a threat intelligence capability from scratch is genuinely rare: most security roles inherit someone else's tooling, someone else's playbooks, someone else's definition of what 'good' looks like. This one doesn't. As Mews' first Cyber Threat Intelligence Specialist, you will design and operationalise the CTI function within our Security Operations team, setting the intelligence requirements, the collection and analysis approach, and the feedback loops that will shape how the whole team detects and responds to threats. The hospitality industry is a specific and underserved target for credential phishing, account takeover, and ransomware, and Mews processes data for thousands of properties globally. There is real risk here, and real opportunity to reduce it.

You will join a Security Operations team that operates as a product security function, not a traditional IT security shop. Your work feeds directly into detection engineering, threat hunting, and incident response, and as the program matures you will help shape how intelligence can be surfaced to Mews customers as a trust capability. You will work closely with Security Engineering, Platform Engineering, Legal, and Product teams, and you will report to Roger Ribas, the Director of Security Operations.

What you would do:

  • Design and implement Mews' CTI service end-to-end: intelligence requirements, lifecycle management, collection, enrichment, dissemination, and continuous improvement.
  • Track threat actors, campaigns, and TTPs (tactics, techniques, and procedures) relevant to SaaS platforms and the hospitality and payments ecosystem.
  • Convert raw intelligence into actionable outcomes for detection engineers, threat hunters, and incident responders, with a strong bias toward intelligence that changes decisions rather than just informs them.
  • Act as a trusted intelligence partner during security incidents, providing attacker context, likely objectives, and forward-looking risk assessments.
  • Identify opportunities to automate and enrich intelligence workflows, including applying AI-assisted techniques where they meaningfully improve speed or coverage.

AI Fluency Level 3: In this role, that means you have gone beyond using AI tools for your own productivity. You have redesigned how threat intelligence work gets done: building AI-assisted workflows that others on the team can adopt (for example, automated enrichment pipelines, AI-assisted TTP classification, or LLM-supported threat landscape summaries that are rigorously checked and validated before distribution). You actively interrogate what AI gives you, apply your own judgment to catch errors, and document your approaches so they can be replicated and improved.

What you would bring:

  • Hands-on CTI experience in SaaS, cloud, or technology-centric environments, with a track record of building or significantly evolving a CTI program rather than just operating within one.
  • Experience tracking threat actors, campaigns, and TTPs relevant to online platforms and identity-centric attacks (credential phishing, account takeover, API abuse).
  • Demonstrated ability to translate intelligence into operational outcomes: detection rules, hunting hypotheses, IR support, control improvements.
  • Intelligence lifecycle management from requirements to feedback, with the ability to define priority intelligence requirements (PIRs) aligned to business context and risk.
  • AI Fluency Level 3, or equivalent hands-on experience redesigning workflows with AI and building approaches others can follow.

Nice to have:

  • Working knowledge of Russian for threat actor tracking and underground ecosystem monitoring.
  • Experience with MISP, threat intelligence platforms, or integrating IOC/TTP feeds into Splunk or similar SIEM.
  • Familiarity with RH-ISAC (the Retail and Hospitality Information Sharing and Analysis Centre).

Life at Mews: We’re an equal opportunities employer. We value teams that reflect the diversity of the customers and communities we serve. Different perspectives make better ideas, stronger products and a more welcoming company. We also believe transparency is important when deciding if you're the right fit. Mews is an ambitious, high-pressure environment of continuous learning and high standards. Success here requires resilience, adaptability and a willingness to solve difficult problems.

A few things that define how we work:

  • High autonomy means high responsibility. People are expected to take ownership and drive outcomes.
  • Change is constant. We’re growing quickly and adapting as we scale.
  • We’re remote-first, not relationship-free. Flexibility is core to how we work, but strong relationships still matter.
  • AI is an integral part of our processes. It’s not here to steal people’s jobs, but to amplify efficiency and productivity.

If there's anything we can do to support you during the application process, let us know. We don't discriminate on the basis of race, religion, colour, nationality, gender, sexual orientation, age, marital status, veteran status, disability or any other protected characteristic.

If Mews sounds like the kind of environment where you'd thrive, we'd love to hear from you.

Cyber Threat Intelligence Specialist employer: Mews

At Mews, we pride ourselves on being an exceptional employer that fosters a culture of innovation and collaboration. Our team is made up of passionate individuals who are empowered to make impactful decisions, ensuring that every employee has the opportunity for personal and professional growth. Located in a vibrant industry, we offer unique advantages such as autonomy in your role, a commitment to meaningful work, and the chance to shape the future of hospitality technology.

Mews

Contact Details:

Mews Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Threat Intelligence Specialist

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Mews, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Mews

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Mews. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Threat Intelligence Specialist

Cyber Threat Intelligence (CTI)
Threat Actor Tracking
Tactics, Techniques, and Procedures (TTPs) Analysis
Intelligence Lifecycle Management
Operational Outcome Translation
AI Fluency Level 3
Automation of Intelligence Workflows

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Mews insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Mews that you’re committed to staying ahead in the game.

How to prepare for a job interview at Mews

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Mews to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Mews.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.