Threat Intelligence & Incident Response Lead
Manchester - UK
Job Summary
The role
The Threat Intelligence & Incident Response Lead shapes ANS proactive cyber defence through intelligence-led operations incident response threat hunting and CTEM.
Youll lead threat intelligence and incident response within the SOC turning emerging threats and customer risk into actionable detection and response.
Combining hands-on expertise with technical leadership youll drive the evolution of MDR and proactive security services while collaborating across Security teams customers and partners to strengthen overall capability.
What will I be doing
Threat Intelligence Leadership
Lead and mature threat intelligence embedding it across detection investigation hunting and protection.
Research emerging threats adversary tactics and vulnerabilities relevant to customers.
Translate intelligence into actionable detections automation and security improvements.
Produce customer and internal threat advisories.
Identify emerging risks across sectors and technologies.
Align with frameworks (e.g. MITRE ATT&CK).
Partner with Engineering and SOC to improve detection and response.
Incident Response Leadership
Lead technical response for high-priority incidents (P1/P2).
Own and enhance incident readiness playbooks and processes.
Drive post-incident reviews and continuous improvement.
Embed threat-informed improvements into detections and response.
Support containment eradication and recovery activities.
Coordinate escalations including external IR and forensics.
Lead incident response exercises.
Continuous Threat Exposure Management (CTEM)
Mature CTEM through threat-informed risk and exposure prioritisation.
Correlate vulnerabilities and telemetry with threat intelligence.
Support exposure validation security reviews and testing.
Provide recommendations to reduce risk and improve resilience.
Support proactive security improvements across services.
Threat Hunting & Detection Strategy
Develop hypothesis-led threat hunting aligned to threat landscape and risk.
Lead proactive hunts using telemetry intelligence and IoCs.
Collaborate to identify suspicious activity and attack patterns.
Turn hunt outcomes into improved detections and response.
Optimise detection through tuning and gap identification.
Enhance ATT&CK-aligned detection coverage.
Technical Leadership & Capability Ownership
Provide technical leadership across SOC activities.
Mentor analysts through coaching and knowledge sharing.
Drive maturity across IR hunting intelligence and detection.
Develop standards documentation and playbooks.
Act as escalation point for complex investigations.
Support service and capability development.
Customer & Stakeholder Engagement
Support customer discussions on incidents threats and risk.
Present technical findings in clear business terms.
Contribute to service improvement and maturity discussions.
Partner with Customer Success Service Owners and Pre-Sales to align services.
What will I bring to the role
Technical Experience
Experience in one or more of:
SOC MDR or MSSP environments
Threat intelligence and adversary analysis
Incident response and cyber coordination
Threat hunting and proactive investigations
Detection engineering and alert tuning
SOAR / security automation
CTEM vulnerability prioritisation or exposure management
Cloud and identity security (Microsoft / multi-cloud)
Strong understanding of:
SIEM/SOAR platforms (e.g. Chronicle Sentinel)
Microsoft Defender ecosystem
MITRE ATT&CK framework
IoCs and threat actor behaviour
Security telemetry and investigation workflows
Incident response lifecycle and containment
Soft Skills
Strong communication and stakeholder engagement
Ability to translate technical concepts into business language
Calm structured approach during incidents
Analytical and problem-solving mindset
Passion for cyber security and emerging threats
Collaborative and supportive technical leadership
Why work for ANS
At ANS weve created a place where everyone can be themselves and we empower our people to get the job done. Openness ambition honesty and passion are what drive us every day. We are bold courageous and innovative and we do it like no other. We invest in our training development health and more we give you the benefits and flexibility to maintain a happy work-life balance.
Were proud of the inclusive fun dynamic environment weve created. Its a safe space that works for dont have to be a techie to work in tech. Bring your authentic self and find your dream role here. Find out more atLinkedIn pages.
Whats in it for you
With fantastic benefits an inclusive culture and a cool office space were your kind of workplace.
Company benefits
- As standard:25 daysholiday plus you can buy up to5 moredays
- A little extra:well give you yourbirthday offand an extracelebration dayfor whatever you want!Tying the knotYou get 5 days additional holiday in the year you get married. Oh and 5volunteer days!
- Private health insurance
- Pension contribution match and 4 x life assurance
- Flexible workingandwork from anywherefor up to 30 days per year (some exceptions)
- Maternity: 16 weeks full pay Paternity: 3 weeks full pay Adoption: 16 weeks full pay
- Company social events get ready for a jam-packed calendar
- Electric car scheme
- 12 days of personal growth development time
ANS are an equal opportunities employer. We encourage diversity and anyone applying for a role at our organisation can be assured that their application will be treated fairly regardless of age disability gender reassignment gender expression marriage and civil partnership pregnancy and maternity race religion or belief and sex or sexual orientation. We sometimes ask for information relating to individuals for equal opportunities monitoring purposes only.
The Benefits
The Benefits
Work from anywhere
Private Medical
Pension Scheme
Life Assurance
Volunteer Days
Electric Vehicle Scheme
Personal Development Days
Ride to Work Scheme
Documents