Sobre esta vaga de Threat Intelligence Analyst na DS Smith
About the Role
We are looking for a skilled and proactive Threat Intelligence Analyst to join our Information Security team.
This is an exciting opportunity to play a critical role in protecting DS Smith's operations, data, and infrastructure by identifying, analysing, and communicating cyber security threats. You will help strengthen our security posture through actionable threat intelligence, advanced threat hunting, and hands-on incident response activities.
Working closely with Security Operations, Incident Response, Infrastructure, and wider Technology teams, you will monitor the evolving threat landscape, investigate potential cyber threats, and support the continuous improvement of our detection and response capabilities. Leveraging Microsoft Sentinel, Microsoft Defender, DarkIQ, and other intelligence sources, you will provide timely intelligence that helps the business stay ahead of emerging threats.
A core focus of the role is to transform threat intelligence into meaningful insights and practical actions, ensuring risks are understood and mitigated before they impact the organisation.
Key responsibilities include:
Monitoring the global threat landscape for emerging cyber threats, vulnerabilities, and threat actor activity relevant to DS Smith and the manufacturing sector
Analysing intelligence from multiple sources, including OSINT, commercial feeds, industry sharing platforms, and dark web monitoring tools
Correlating external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender
Developing and maintaining advanced KQL queries to support threat hunting, detection engineering, and incident investigation activities
Producing actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings
Supporting and participating in incident response activities, from initial triage through containment, eradication, recovery, and post-incident review
Conducting forensic investigations and providing threat context during live security incidents
Collaborating with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities
Contributing to the development of threat models, risk assessments, playbooks, and operational processes
Maintaining awareness of evolving cyber threats, attack techniques, and trends impacting the manufacturing and logistics sectors
This role offers an excellent opportunity to influence cyber security strategy while working as part of a collaborative team focused on protecting a global organisation.
About You
You're an experienced cyber security professional with a strong background in threat intelligence, incident response, and security operations.
We're looking for:
Experience in cyber security, with a focus on threat intelligence, incident response, or security operations
Proven hands-on experience managing security incidents throughout the full incident response lifecycle
Strong understanding of cyber threats, threat actor behaviour, attack methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain
Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation
Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent
Strong analytical skills with the ability to identify patterns and draw meaningful conclusions from complex datasets
Knowledge of malware analysis, phishing investigations, and infrastructure security principles
Experience with scripting and automation using PowerShell, Python, or similar technologies
Excellent communication skills, with the ability to translate technical findings into clear business-focused recommendations
A collaborative approach and desire to continuously improve security capabilities across the organisation
It would be advantageous if you also have:
Relevant industry certifications such as GCTI, GTIA, SC-200, or equivalent
Experience within manufacturing, logistics, or industrial environments
Knowledge of OT/ICS security and threats affecting operational technology environments
Familiarity with GDPR, NIS2, and other relevant cyber security regulations