Hybrid/ Remote Working
Private Medical Care
Pension Scheme

Threat Intelligence & Incident Response Lead

Salary
Location Manchester/Hybrid
{Mergefield Value}
{Mergefield Value}

This is a , Full Time vacancy that will close in {x} days at {xx:xx} BST.

The role

The Threat Intelligence & Incident Response Lead shapes ANS’ proactive cyber defence through intelligence-led operations, incident response, threat hunting, and CTEM.

You’ll lead threat intelligence and incident response within the SOC, turning emerging threats and customer risk into actionable detection and response.

Combining hands-on expertise with technical leadership, you’ll drive the evolution of MDR and proactive security services, while collaborating across Security teams, customers, and partners to strengthen overall capability.

What will I be doing?

Threat Intelligence Leadership
• Lead and mature threat intelligence, embedding it across detection, investigation, hunting, and protection.
• Research emerging threats, adversary tactics, and vulnerabilities relevant to customers.
• Translate intelligence into actionable detections, automation, and security improvements.
• Produce customer and internal threat advisories.
• Identify emerging risks across sectors and technologies.
• Align with frameworks (e.g. MITRE ATT&CK).
• Partner with Engineering and SOC to improve detection and response.

Incident Response Leadership
• Lead technical response for high-priority incidents (P1/P2).
• Own and enhance incident readiness, playbooks, and processes.
• Drive post-incident reviews and continuous improvement.
• Embed threat-informed improvements into detections and response.
• Support containment, eradication, and recovery activities.
• Coordinate escalations, including external IR and forensics.
• Lead incident response exercises.

Continuous Threat Exposure Management (CTEM)
• Mature CTEM through threat-informed risk and exposure prioritisation.
• Correlate vulnerabilities and telemetry with threat intelligence.
• Support exposure validation, security reviews, and testing.
• Provide recommendations to reduce risk and improve resilience.
• Support proactive security improvements across services.

Threat Hunting & Detection Strategy
• Develop hypothesis-led threat hunting aligned to threat landscape and risk.
• Lead proactive hunts using telemetry, intelligence, and IoCs.
• Collaborate to identify suspicious activity and attack patterns.
• Turn hunt outcomes into improved detections and response.
• Optimise detection through tuning and gap identification.
• Enhance ATT&CK-aligned detection coverage.

Technical Leadership & Capability Ownership
• Provide technical leadership across SOC activities.
• Mentor analysts through coaching and knowledge sharing.
• Drive maturity across IR, hunting, intelligence, and detection.
• Develop standards, documentation, and playbooks.
• Act as escalation point for complex investigations.
• Support service and capability development.

Customer & Stakeholder Engagement
• Support customer discussions on incidents, threats, and risk.
• Present technical findings in clear business terms.
• Contribute to service improvement and maturity discussions.
• Partner with Customer Success, Service Owners, and Pre-Sales to align services.

What will I bring to the role?

Technical Experience
Experience in one or more of:
• SOC, MDR or MSSP environments
• Threat intelligence and adversary analysis
• Incident response and cyber coordination
• Threat hunting and proactive investigations
• Detection engineering and alert tuning
• SOAR / security automation
• CTEM, vulnerability prioritisation or exposure management
• Cloud and identity security (Microsoft / multi-cloud)

Strong understanding of:
• SIEM/SOAR platforms (e.g. Chronicle, Sentinel)
• Microsoft Defender ecosystem
• MITRE ATT&CK framework
• IoCs and threat actor behaviour
• Security telemetry and investigation workflows
• Incident response lifecycle and containment

Soft Skills
• Strong communication and stakeholder engagement
• Ability to translate technical concepts into business language
• Calm, structured approach during incidents
• Analytical and problem-solving mindset
• Passion for cyber security and emerging threats
• Collaborative and supportive technical leadership

At ANS, we’ve created a place where everyone can be themselves, and we empower our people to get the job done. Openness, ambition, honesty, and passion are what drive us every day. We are bold, courageous, and innovative – and we do it like no other. We invest in our people. In training, development, health and more – we give you the benefits and flexibility to maintain a happy work-life balance.

We’re proud of the inclusive, fun, dynamic environment we’ve created. It’s a safe space that works for all. You don’t have to be a techie to work in tech. Bring your authentic self and find your dream role here. Find out more at LinkedIn pages.

What’s in it for you?
With fantastic benefits, an inclusive culture, and a cool office space, we’re your kind of workplace. 

Company benefits

  • As standard: 25 days’ holiday, plus you can buy up to 5 more days
  • A little extra: we’ll give you your birthday off, and an extra celebration day for whatever you want! Tying the knot? You get 5 days’ additional holiday in the year you get married. Oh, and 5 volunteer days!
  • Private health insurance
  • Pension contribution match and 4 x life assurance
  • Flexible working and work from anywhere for up to 30 days per year (some exceptions)
  • Maternity: 16 weeks’ full pay, Paternity: 3 weeks’ full pay, Adoption: 16 weeks’ full pay
  • Company social events – get ready for a jam-packed calendar
  • Electric car scheme
  • 12 days of personal growth development time

ANS are an equal opportunities employer. We encourage diversity and anyone applying for a role at our organisation can be assured that their application will be treated fairly, regardless of age, disability, gender reassignment, gender expression, marriage and civil partnership, pregnancy and maternity, race, religion or belief and sex or sexual orientation. We sometimes ask for information relating to individuals for equal opportunities monitoring purposes only.

Work from anywhere

Private Medical

Pension Scheme

Life Assurance

Volunteer Days

Electric Vehicle Scheme

Personal Development Days

Ride to Work Scheme

Alternatively, please sign in with...


Published

Not Published

Closing

in X days

{Expiry}