About this role
We are actively building diverse teams and welcome applications from everyone.
Role: Thread Analyst
Hours: 9.00 am – 5.30 pm Monday – Friday
Interview Process: 2-stage process
Why SCC?
- An inclusive workplace
- Excellent package: solid basic and company benefits
- Hybrid working & core hours in line with role requirements
- Career development and life-long learning opportunities
- Opportunity to join Europe's largest privately-owned IT Company
Role purpose: The Threat Analyst will lead SCC Cyber’s threat intelligence capability by analysing emerging threats, vulnerabilities, and adversary activity, and translating these into actionable insights for SOC operations and customers.
The role bridges strategic, operational, and tactical threat intelligence—supporting the development of customer-facing reporting, detection use cases, and proactive security improvements. The analyst will work closely with SOC analysts, engineers, and stakeholders to ensure threat intelligence is embedded into monitoring, detection, and response activities.
A key focus of the role is the application of threat intelligence to vulnerability exposure (Tenable / MVAS) and Defender telemetry, ensuring risks are identified, prioritised, and operationalised effectively.
Key Responsibilities
Threat Intelligence & Analysis
- Research and analyse emerging cyber threats, vulnerabilities, and threat actor activity relevant to SCC customers
- Produce threat assessments and contextual intelligence on vulnerabilities, incidents, and campaigns
- Lead development of strategic, operational, and tactical threat intelligence outputs (e.g. landscape reports, advisories, digests)
- Map threats, TTPs, and campaigns to frameworks such as MITRE ATT&CK
Customer-Facing Intelligence & Reporting
- Produce and enhance customer-facing deliverables such as:
oStrategic threat landscape reports
oThreat briefings and advisories
oTechnology-specific risk summaries
- Translate threat intelligence into business-relevant insights and recommendations
- Support stakeholder engagement by explaining threats in both technical and non-technical terms
Operational Integration with SOC
- Work with other SOC and threat analysts to convert intelligence into:
oDetection rules (SIEM / EDR)
oThreat hunting hypotheses
oPlaybook improvements
- Provide intelligence-driven input into alert triage and incident investigations
- Support post-incident reviews with threat context and adversary insight
Vulnerability & Exposure Intelligence
- Analyse vulnerability data from Tenable and other scanning platforms to:
oIdentify high-risk vulnerabilities relevant to current threat activity
oPrioritise remediation based on exploitability, exposure, and threat actor interest
- Correlate vulnerability findings with:
oThreat intelligence (active campaigns / exploitation in the wild)
- Support development of:
oVulnerability threat advisories
oRisk-based prioritisation models for customers
- Work with SOC and engineering teams to ensure vulnerability intelligence informs:
oDetection use cases
oThreat hunting activities
Defender & Endpoint Intelligence (MXDR Integration)
- Leverage Microsoft Defender (Endpoint, Identity, Cloud, Office) telemetry to:
oIdentify emerging threat patterns and suspicious behaviours
oSupport investigations with enriched threat intelligence context
- Correlate Defender alerts with known threat actor TTPs and campaigns
- Lead on:
*o*Identification of gaps in detection coverage
oDevelopment of intelligence-led improvements to Defender use cases
- Be the SME for :
oExploitation techniques observed in real environments
oTrends across customer estates
Threat Monitoring & Tooling
- Lead monitoring of:
oDark web sources
oExternal attack surface exposure
oVulnerability disclosures and exploitation trends
- Lead on evaluation and usage of threat intelligence platforms and tooling
- Maintain tracking of relevant:
oIndicators of Compromise (IOCs)
oVulnerabilities and CVEs
oThreat actor campaigns
Service Development & Improvement
- Lead on development of SCC threat intelligence services and offerings
- Lead on refining use cases, playbooks, and detection logic based on emerging threats
- Support RFP responses, service design, and customer proposals for threat intelligence capabilities
Collaboration & Knowledge Sharing
- Work collaboratively with SOC, engineering, and solution teams
- Share threat insights across the SOC to improve collective awareness and response capability
- Maintain awareness of current and emerging threats affecting key sectors and customer environments
- Will mentor other more junior Threat Analysts
Skills And Experience
- Eligibility to get Security Clearance.
- Experience in researching and analysing threats within a SOC environment
- Detail-oriented with strong analytical thinkingAble to translate threat intelligence into practical outcomes
- Collaborative and team-focused
- Committed to continuous learning in cyber security
- Good understanding of cyber security principles and threat landscape shown through experience and certifications.
- Experience of using vulnerability prioritisation and exploit intelligence within a security team
- Experience working with and troubleshooting Tenable, Defender, or equivalent tooling
- Knowledge of frameworks such as MITRE ATT&CK
- Understanding and experience of threat intelligence lifecycle and structured analysis techniques
- Experience producing reports, briefings, or customer-facing outputs
About Us
SCC is Europe's largest privately-owned IT business, based out of the new £7m HQ office in Birmingham and we help clients succeed through IT transformation and exceptional customer experiences. We are a business where innovation is greater as we combine unique ideas, people and disciplines. We are a global company that is passionate about IT and where we look to simplify the complex.
We are an equal opportunities employer
SCC is committed to providing equal opportunities and a proactive and inclusive approach to equality and diversity in employment. No applicant or employee will be treated less favourably than another on the grounds of a protected characteristic which are defined as sex, sexual orientation, age, disability, gender reassignment, trade union membership or non-membership, marriage and civil partnership, pregnancy and maternity, race and religion or belief.
If you are selected for interview, and need any reasonable adjustments made for your interview, please let the SCC Talent Acquisition team know, at the point of scheduling.
Diversity & Inclusion at SCC - https://www.scc.com/diversity-and-inclusion/
Sustainability at SCC - https://www.scc.com/sustainability-at-scc/
Life at SCC - https://www.linkedin.com/company/scc/life
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Birmingham →Why this fits a police background
- Police experience explicitly valued
- Evidence & case files
- Intelligence & OSINT
- Investigative casework
- Risk & threat assessment
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |