At a Glance
- Tasks: Hunt cyber threats and protect networks using cutting-edge security tools.
- Company: Join a forward-thinking company dedicated to cybersecurity excellence.
- Benefits: Competitive salary, flexible work options, and opportunities for growth.
- Other info: Dynamic team environment with a focus on innovation and collaboration.
- Why this job: Make a real difference in the fight against cybercrime while developing your skills.
- Qualifications: Experience in security operations and familiarity with Microsoft security tools.
The predicted salary is between 63000 - 77000 £ per year.
Job Details: Cyber Security Threat Hunter
Full details of the job.
- Vacancy Name
- Vacancy Name Cyber Security Threat Hunter
- Vacancy No
- Vacancy No VN903
- Location Country
- Work Location
As a Cyber Security Threat Hunter, you will protect Utmost’s networks and systems from cyber threats and unauthorised access.
You will monitor and investigate security events, assess their impact, and either resolve issues or elevate them based on severity.
This role blends proactive threat hunting with authorised adversary simulation to strengthen detection and response across endpoints, identities, email and cloud environments.
You will emulate real-world techniques, investigate suspicious activity using Microsoft security platforms, and turn findings into actionable recommendations and improved detections.
- Core responsibilities
- Threat hunting and investigation: Proactively identify and investigate suspicious behaviours across endpoint, identity, email and cloud telemetry using Microsoft Defender XDR and Advanced Hunting (KQL).
- Detection content ownership: Convert hunt outcomes into operational detections (e. g., Sentinel analytics rules, Defender custom detections, watchlists/workbooks) and continuously tune to improve signal quality and reduce noise.
- Adversary simulation: Emulate modern threat actors (including APT-style behaviours) to test security resilience and validate detections.
- Covert authorised testing: Execute time-bound, approved exercises to identify detection gaps and response friction (including attempts to bypass controls where authorised).
- Governance and rules of engagement: Follow documented approvals and scope constraints; operate safely, record actions taken, and preserve evidence for audit and incident follow-up.
- Vulnerability assessment and controlled exploitation: Conduct scoped assessments and vulnerability scans and, where authorised, safely demonstrate impact to support prioritised remediation.
- Lateral movement and post-compromise testing: Assess internal segmentation and privilege boundaries by attempting controlled movement after initial access.
- Social engineering: Conduct approved phishing and other social engineering techniques to assess human-layer controls and awareness.
- XDR and SIEM operations: Use Microsoft Sentinel for log analytics/correlation and Defender for Cloud to support securing cloud assets (Azure and multi-cloud where applicable).
- Telemetry correlation: Correlate Microsoft signals with key third-party telemetry (e. g., firewall, proxy, DNS, VPN, Saa S) and validate data quality to close coverage gaps.
- Threat intelligence leverage: Use Microsoft Defender Threat Intelligence to understand adversary infrastructure and behaviours and to inform hunts, simulations, and blocking actions.
- Hunt lifecycle and deliverables: Own the hunt cycle (hypothesis validate data execute document improve) and publish repeatable hunt packages (queries, rationale, expected results, tuning notes).
- Reporting and remediation: Document objectives, evidence and prioritised recommendations; partner with teams to remediate and tune detections.
- Incident response support: Support containment and recovery activities, assist with root-cause analysis, and capture lessons learned to improve future response.
The role holder is expected to deputise for the Information Security Officers in the security team when required, and to attend regular departmental meetings and other meetings relevant to the role.
Key Responsibilities
- Cyber Risk
- Oversight, management, and reporting on all risks pertaining to information security, including all forms of cyber risk and all risks relating to the protection of personal data throughout the business in all locations.
- Developing and monitoring Key Risk Indicators (KRI) and Key Performance Indicators (KPI), relating to the information security controls of the business.
- Assist in the assessment of risk to the security of information, assets and personnel.
- Assist in management of cyber risk including risk reviews and mitigation planning.
- Customer Management
- Commits to exceeding expectations and needs to internal/external customers, possesses “customer first” mind set.
- Ensures that work is accurate and well presented, that customer care is given priority above all else and that in both areas effort is made to exceed the minimum standard required.
- Shows concern for detail no matter how small.
- Takes a pride in doing a job well.
Skills
- Windows and identity fundamentals: Strong understanding of Windows security concepts and Microsoft identity (Active Directory and Entra ID), including authentication and token flows (Kerberos/NTLM/OAuth), device join states, MFA/Conditional Access concepts, and common identity attack paths.
- Endpoint telemetry literacy: Ability to interpret process trees and command lines, Power Shell activity, scheduled tasks/services, registry and file changes, WMI usage, persistence techniques, and LOLBins and to connect these artifacts to Defender alerts and timelines.
- Microsoft 365 and cloud security foundations: Familiarity with email security and message flow (Exchange Online), and investigation pivots across Share Point/One Drive/Teams activity and Azure logs where relevant to XDR incidents.
- Detection engineering mindset: Experience translating hunts and red team findings into practical detections and improvements (signal selection, tuning, suppression/thresholding, entity mapping, documentation, and operational handoff).
- KQL depth and query performance: Comfortable using joins/unions, parsing, time-windowing, summarisation, baselining, and performance-aware query patterns for large datasets.
- Log onboarding and data quality (Sentinel): Understanding of data connectors, schema/field consistency, normalisation, time sync considerations, and how missing/low-quality telemetry impacts detections.
- Incident response operations: Ability to scope incidents, preserve evidence, choose containment actions, and collaborate with stakeholders on remediation and lessons learned.
- Automation: Practical skills in scripting and basic automation concepts (e. g., enrichment and response workflows) to make hunts and investigations repeatable.
- Ability to work effectively under pressure during a security incident.
- Process mapping and data analysis skills
- Analytical skills – Interprets quantitative and qualitative information to achieve objective and produces effective solutions to problems.
- Ability to work in tight deadlines and delivering solutions within defined time periods.
- Demonstrated experience in incident response, cybersecurity, or digital forensics, and the ability to write clear, concise technical reports.
- Experience working in a complex operational environment
- Effective verbal and written communication skills and strong interpersonal skills, good at reporting
- Behaviours
- A proactive mindset to anticipate and address potential threats.
- Being cooperative, flexible, adaptable, and persistent.
- Diligence - Being careful about detail and through in completing work
- Integrity - Being honest and ethical
- Independence – developing one’s own ways of doing things, guiding oneself with little or no supervision, depending on oneself to get things done.
- Must be willing to travel occasionally between offices in all Utmost territories where required (infrequent)
- Key Tasks
- Key Requirements
As a Cyber Security Threat Hunter, you’ll need
- Hands-on security operations experience: Working knowledge of SOC workflows including triage, investigation, containment, and improvement of detections.
- Microsoft security tooling: Experience investigating and hunting in Microsoft Defender XDR and leveraging Microsoft Sentinel for broader log analytics.
- KQL proficiency: Write and refine Advanced Hunting queries (KQL) to analyse endpoint, email and identity telemetry (e. g., Device Events, Device File Events, Email Events).
- Cloud security fundamentals: Familiarity with securing cloud workloads and assets using Microsoft Defender for Cloud (Azure and multi-cloud environments).
- Red team / offensive fundamentals: Practical experience with penetration testing concepts, exploitation workflows, and post-exploitation tradecraft in controlled environments.
- Networking and OS knowledge: Strong understanding of common protocols (e. g., DNS, HTTP) and operating system internals and telemetry.
- Forensics fundamentals: Comfortable with host triage, timeline building, and evidence handling concepts to support investigations and root-cause analysis.
- Tools: Comfort with common security tooling such as Kali Linux, Metasploit, and Wireshark.
- Scripting/programming: Ability to automate tasks and build custom tooling using Python, Power Shell, or Golang.
- SOAR and repeatability: Create repeatable investigation workflows (playbooks/runbooks) and use automation where appropriate (e. g., Sentinel automation rules/Logic Apps).
- Adversary tradecraft knowledge: Understanding of MITRE ATT&CK tactics/techniques and how to map observations and simulations to that framework.
- Threat modelling and prioritisation: Ability to prioritise hunts using business risk, crown-jewel assets, attack paths, recent intelligence, and MITRE coverage gaps.
- Knowledge
• Experience or qualifications
• At least 3 years’ hands-on experience in
- Incident response processes/methodologies and SIEM operations.
- Security tooling, reporting, and delivering work in a structured/project-based way.
- IT/networking/security fundamentals including operating systems, networking and digital forensics.
- Microsoft Azure and Microsoft 365 cloud technologies.
- Threat intelligence-driven hunting: Demonstrated use of threat intelligence to plan hunts, enrich detections, and block malicious infrastructure.
- Bachelor's degree in cybersecurity, computer science, or IT is desirable.
- Management experience that encompasses information systems or information security experience.
- Relevant certification is preferred: Microsoft
Certified: Security Operations Analyst Associate (SC-200) or equivalent demonstrated experience, Comp TIA Cybersecurity Analyst (Cy SA+), GIAC Certified Incident Handler (GCIH), ISACA Certified Cybersecurity Operations Analyst(CCOA).
- Copilot for Security: Experience using AI-assisted investigation workflows such as the Security Analyst Agent in Microsoft Defender to accelerate triage and deep investigations.
- #J-18808-Ljbffr
Cyber Security Threat Hunter employer: Utmost Group
As an Investment Analyst (Credit) in the United Kingdom, you will thrive in a dynamic work culture that prioritises collaboration and professional growth. Our commitment to employee development is reflected in our comprehensive training programmes and opportunities for advancement within the financial sector. With a focus on innovation and excellence, we offer a supportive environment where your analytical skills can shine, making us an exceptional employer for those seeking meaningful and rewarding careers.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Threat Hunter
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Utmost Group, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Utmost Group
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Utmost Group. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Security Threat Hunter
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Utmost Group insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Utmost Group that you’re committed to staying ahead in the game.
How to prepare for a job interview at Utmost Group
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Utmost Group to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Utmost Group.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.