Talent.com
ANS Group Limited
Threat Intelligence & Incident Response LeadANS Group Limited • Manchester, England, UK
No longer accepting applications
Threat Intelligence & Incident Response Lead

Threat Intelligence & Incident Response Lead

ANS Group Limited • Manchester, England, UK
30+ days ago
Job type
  • Full-time
Job description

The role

The Threat Intelligence & Incident Response Lead shapes ANS proactive cyber defence through intelligence-led operations incident response threat hunting and CTEM.

Youll lead threat intelligence and incident response within the SOC turning emerging threats and customer risk into actionable detection and response.

Combining hands-on expertise with technical leadership youll drive the evolution of MDR and proactive security services while collaborating across Security teams customers and partners to strengthen overall capability.

What will I be doing

Threat Intelligence Leadership
Lead and mature threat intelligence embedding it across detection investigation hunting and protection.
Research emerging threats adversary tactics and vulnerabilities relevant to customers.
Translate intelligence into actionable detections automation and security improvements.
Produce customer and internal threat advisories.
Identify emerging risks across sectors and technologies.
Align with frameworks (e.g. MITRE ATT&CK).
Partner with Engineering and SOC to improve detection and response.

Incident Response Leadership
Lead technical response for high-priority incidents (P1/P2).
Own and enhance incident readiness playbooks and processes.
Drive post-incident reviews and continuous improvement.
Embed threat-informed improvements into detections and response.
Support containment eradication and recovery activities.
Coordinate escalations including external IR and forensics.
Lead incident response exercises.

Continuous Threat Exposure Management (CTEM)
Mature CTEM through threat-informed risk and exposure prioritisation.
Correlate vulnerabilities and telemetry with threat intelligence.
Support exposure validation security reviews and testing.
Provide recommendations to reduce risk and improve resilience.
Support proactive security improvements across services.

Threat Hunting & Detection Strategy
Develop hypothesis-led threat hunting aligned to threat landscape and risk.
Lead proactive hunts using telemetry intelligence and IoCs.
Collaborate to identify suspicious activity and attack patterns.
Turn hunt outcomes into improved detections and response.
Optimise detection through tuning and gap identification.
Enhance ATT&CK-aligned detection coverage.

Technical Leadership & Capability Ownership
Provide technical leadership across SOC activities.
Mentor analysts through coaching and knowledge sharing.
Drive maturity across IR hunting intelligence and detection.
Develop standards documentation and playbooks.
Act as escalation point for complex investigations.
Support service and capability development.

Customer & Stakeholder Engagement
Support customer discussions on incidents threats and risk.
Present technical findings in clear business terms.
Contribute to service improvement and maturity discussions.
Partner with Customer Success Service Owners and Pre-Sales to align services.

What will I bring to the role

Technical Experience
Experience in one or more of:
SOC MDR or MSSP environments
Threat intelligence and adversary analysis
Incident response and cyber coordination
Threat hunting and proactive investigations
Detection engineering and alert tuning
SOAR / security automation
CTEM vulnerability prioritisation or exposure management
Cloud and identity security (Microsoft / multi-cloud)

Strong understanding of:
SIEM/SOAR platforms (e.g. Chronicle Sentinel)
Microsoft Defender ecosystem
MITRE ATT&CK framework
IoCs and threat actor behaviour
Security telemetry and investigation workflows
Incident response lifecycle and containment

Soft Skills
Strong communication and stakeholder engagement
Ability to translate technical concepts into business language
Calm structured approach during incidents
Analytical and problem-solving mindset
Passion for cyber security and emerging threats
Collaborative and supportive technical leadership

Why work for ANS

At ANS weve created a place where everyone can be themselves and we empower our people to get the job done. Openness ambition honesty and passion are what drive us every day. We are bold courageous and innovative and we do it like no other. We invest in our training development health and more we give you the benefits and flexibility to maintain a happy work-life balance.

Were proud of the inclusive fun dynamic environment weve created. Its a safe space that works for dont have to be a techie to work in tech. Bring your authentic self and find your dream role here. Find out more atLinkedIn pages.

Whats in it for you
With fantastic benefits an inclusive culture and a cool office space were your kind of workplace.

Company benefits

  • As standard:25 daysholiday plus you can buy up to5 moredays
  • A little extra:well give you yourbirthday offand an extracelebration dayfor whatever you want!Tying the knotYou get 5 days additional holiday in the year you get married. Oh and 5volunteer days!
  • Private health insurance
  • Pension contribution match and 4 x life assurance
  • Flexible workingandwork from anywherefor up to 30 days per year (some exceptions)
  • Maternity: 16 weeks full pay Paternity: 3 weeks full pay Adoption: 16 weeks full pay
  • Company social events get ready for a jam-packed calendar
  • Electric car scheme
  • 12 days of personal growth development time

ANS are an equal opportunities employer. We encourage diversity and anyone applying for a role at our organisation can be assured that their application will be treated fairly regardless of age disability gender reassignment gender expression marriage and civil partnership pregnancy and maternity race religion or belief and sex or sexual orientation. We sometimes ask for information relating to individuals for equal opportunities monitoring purposes only.

The Benefits

Employee Assistance Programme

State of the art IT equipment

Volunteer
days

The Benefits

Work from anywhere

Private Medical

Pension Scheme

Life Assurance

Volunteer Days

Electric Vehicle Scheme

Personal Development Days

Ride to Work Scheme

Documents


Employment Type : Full Time
Experience: years
Vacancy: 1

Create a job alert for this search

Threat Intelligence & Incident Response Lead • Manchester, England, UK

Similar jobs

Global Director, DFIR & Incident Response Leadership

NCC GroupGreater Manchester, England, United Kingdom
Full-time

NCC Group in Manchester invites an experienced Director to lead the global Digital Forensics and Incident Response capability, shaping strategy, and delivering a scalable service that protects clie... Show more

 • Promoted

Information Security Lead Auditor

CogniboxManchester, England, GB
Permanent

Information Security Lead Auditor.At ISOQAR, we draw on our experience, knowledge, and ambition to empower organisations to achieve their highest potential.Through our robust portfolio of progressi... Show more

 • Promoted

Senior SOC Analyst

NexGen AssociatesStoke-on-Trent, England, GB
Full-time

From £52,000 + shift allowance.DV required (UK Sole National).You will lead medium to high-severity investigations, support incident containment and remediation, and act as the escalation point for... Show more

 • Promoted

Fire Risk Assessor

Ranger Services Holdings LimitedBolton, GB
Full-time

Total Fire Group, part of the wider Ranger Group, is expanding, and were looking for skilled Fire Risk Assessors to join one of the North Wests most respected, UKAS-accredited fire safety consultan... Show more

 • Promoted

Senior Major Incident Leader - On-Site Preston

CapgeminiManchester, England, GB
Full-time

Capgemini is seeking a Major Incident Manager Lead to oversee incident management for high-profile clients in Preston.This full-time role requires strong expertise in ITIL processes and excellent l... Show more

 • Promoted

Field Loss Prevention Investigator - Retail Security Pro

WaterstonesManchester, England, GB
Full-time

A major retail bookshop in Manchester seeks a Loss Prevention Investigator to protect staff and customers while reducing risks of theft.The role involves investigating incidents, advising on loss p... Show more

 • Promoted

Cyber Security Starter Course (Bolton)

ITonlinelearning RecruitmentBolton, ENG, GB
Part-time

Trainee Cyber Security Course Programme – Job Guarantee Included.Complete online training designed to take you from zero experience to your first Cyber Security role.Study part-time, build fu... Show more

 • Promoted

Senior DFIR Consultant: Incident Response Leader

NCC GroupManchester, England, GB
Full-time

A cybersecurity company in Manchester is seeking a Senior Consultant to lead incident response efforts and collaborate with diverse teams.The role requires 4 to 6 years of experience in security op... Show more

 • Promoted

Security Engineer – Incident Response & Compliance

Digital WaffleManchester, England, GB
Full-time

A leading cybersecurity firm based in Manchester seeks a skilled Security Engineer.This on-site role is pivotal in safeguarding systems and ensuring compliance with security standards.The successfu... Show more

 • Promoted

Senior SOC Analyst — Incident Response & Threat Hunting

NexGen AssociatesStoke-on-Trent, England, GB
Full-time

A renowned cybersecurity firm based in Stoke-on-Trent is seeking a Senior SOC Analyst to lead medium to high-severity investigations and support incident management.The ideal candidate will have 1-... Show more

 • Promoted

Critical Incident Leader - Hybrid MSP

Hamilton Barnes?Manchester, England, GB
Full-time

A leading managed services provider in Manchester is seeking an experienced Major Incident Manager to oversee Priority 1 and 2 incidents.This role requires coordinating teams and maintaining custom... Show more

 • Promoted

Major Incident Manager

Hamilton Barnes?Manchester, England, GB
Full-time

Major Incident Manager | Manchester (Hybrid).Join a leading managed services provider who are looking to hire an experienced Major Incident Manager to join their Operational Support Centre in Manch... Show more

 • Promoted

UK Information Security Leader - Strategy & Risk

CDW UKManchester, England, GB
Full-time

A leading technology provider is seeking a Head of Information Security in Manchester.This role involves overseeing security across UK&I, ensuring compliance, and cultivating a cybersecurity cultur... Show more

 • Promoted

Cyber Security Starter Course (Blackburn)

ITonlinelearning RecruitmentBlackburn, ENG, GB
Part-time

Trainee Cyber Security Course Programme – Job Guarantee Included.Complete online training designed to take you from zero experience to your first Cyber Security role.Study part-time, build fu... Show more

 • Promoted

Lakehouse Data Architect - Platform & Governance Lead

Leonard CurtisBury, England, United Kingdom
Full-time

Leonard Curtis is seeking a Data Warehouse Architect to establish and optimise a unified enterprise data platform that enables data‑driven decisions.You will bridge raw data to business insight, de... Show more

 • Promoted

Trainee Intelligence Analyst - no experience required

ArmyManchester, ENG, GB
Full-time

Become a military intelligence expert.As a full-time soldier, entry-level Intelligence Operative, youll:.Become a subject matter expert in a country or enemy threat.Patrol with the infantry to gath... Show more

 • Promoted

Senior DFIR / Incident Response / Digital Forensics

慨正橡扯Knutsford, England, GB
Full-time

DFIR Lead Cyber Operations Analyst.VP-level role at the centre of the bank’s cyber defence, delivering advanced digital forensics and incident response.You will analyse malware, malicious samples a... Show more

 • Promoted

Senior DFIR Incident Response Lead & Mentor

NCC Group plcManchester, England, GB
Full-time

NCC Group plc is seeking a DFIR Managing Consultant to lead incident response engagements and manage a team of DFIR consultants.The role requires extensive experience in incident response and digit... Show more

 • Promoted

Director, Digital Forensics & Incident Response (Global)

NCC GroupGreater Manchester, England, United Kingdom
Full-time

Director, Digital Forensics & Incident Response (Global).Cyber Services and Capabilities.GBR Manchester Hardman Boulevard.Open to Associate Director with progression path to Director).The purpose o... Show more

 • Promoted

Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UKManchester, England, GB
Full-time

As a Technical Incident Responder you will be focused on Cyber Incident Response within Technology and Transformation, you will typically have responsibility for:.Your creative mindset will enable ... Show more