Overview
In this role you will lead proactive threat hunting within a security operations context, shaping detections and response across cloud and on-prem environments. You will work closely with incident response, SIEM, and threat intelligence to hunt, enrich alerts, and block malicious activity. Youβll translate findings into practical detections and improvements, aligning with a mature security program. This remote position offers strong compensation, benefits, and the chance to influence security outcomes at scale.
Pay / Benefits
- remote working
- bonus up to 15%
- private healthcare
- medicash
- income protection
- death in service x4 salary
Responsibilities
- Run threat hunting campaigns powered by threat intelligence to plan detections and block malicious infrastructure
- Support incident response processes and SIEM operations with structured, project-based work
- Develop and tune detections, including signal selection, thresholds, and documentation for operational handoff
- Interpret endpoint telemetry (process trees, PowerShell activity, registry changes) and connect to Defender alerts
- Work with Microsoft 365/Azure logs, Exchange Online, and related services for XDR incident pivots
- Translate red team findings into practical detection improvements and escalation pathways
- Perform efficient queries (KQL) on large datasets with performance-aware patterns
Key requirements
- Experience in cyber security threat hunting and incident response
- Knowledge of Windows security concepts, AD/Entra ID, and identity attack paths
- Familiarity with Microsoft cloud technologies (Azure, Microsoft 365) and cloud security basics
- Experience with threat intelligence-led hunting and detecting malicious activity
- Proficiency in interpreting endpoint telemetry and Defender alerts
- Strong SQL-like query skills (KQL) for large datasets and time-windowing
- Understanding of authentication flows (Kerberos/NTLM/OAuth) and MFA/Conditional Access
- Nice-to-have: CEH or related ethical hacking credentials
- Threat hunting
- Incident response
- SIEM
- Azure
- Microsoft 365
- Defender (Microsoft Defender)
Cyber Security Threat Hunter β 11832SR1 in Hampshire employer: Proactive Appointments
Join a dynamic team as an IT Support Analyst in the vibrant area near Stamford, where you will benefit from a supportive work culture that prioritises employee growth and development. With a competitive salary and an impressive benefits package including hybrid working options, private medical and dental care, and a subsidised gym membership, this role offers a fulfilling and rewarding career path in a company that values its employees.