Skip to main content
AfterDuty

Threat Analyst

SCC · Birmingham, West Midlands

Type
Full-time
Posted
Today

Overview

Your background in intelligence analysis and threat assessment from policing maps directly to producing structured threat intelligence deliverables. You are used to researching hostile actors, evaluating sources, and writing concise briefings for different audiences, which is exactly what this role demands. Your incident response experience and disciplined approach to evidence and reporting would let you contribute from day one, while any gaps in specific tooling can be trained.

About this role

We are actively building diverse teams and welcome applications from everyone.

Role: Thread Analyst

Hours: 9.00 am – 5.30 pm Monday – Friday

Interview Process: 2-stage process

Why SCC?

  • An inclusive workplace
  • Excellent package: solid basic and company benefits
  • Hybrid working & core hours in line with role requirements
  • Career development and life-long learning opportunities
  • Opportunity to join Europe's largest privately-owned IT Company

Role purpose

Key responsibilities

Threat Intelligence & Analysis

  • **Research and analyse emerging cyber threats, vulnerabilities, and threat actor activity relevant to SCC customers
  • Produce threat assessments and contextual intelligence on vulnerabilities, incidents, and campaigns
  • Lead development of strategic, operational, and tactical threat intelligence outputs (e.g. landscape reports, advisories, digests)
  • Map threats, TTPs, and campaigns to frameworks such as MITRE ATT&CK

Customer-Facing Intelligence & Reporting

  • **Produce and enhance customer-facing deliverables such as:

o Strategic threat landscape reports

o Threat briefings and advisories

o Technology-specific risk summaries

  • Translate threat intelligence into business-relevant insights and recommendations
  • Support stakeholder engagement by explaining threats in both technical and non-technical terms

Operational Integration with SOC

  • **Work with other SOC and threat analysts to convert intelligence into:

o Detection rules (SIEM / EDR)

o Threat hunting hypotheses

o Playbook improvements

  • Provide intelligence-driven input into alert triage and incident investigations
  • Support post-incident reviews with threat context and adversary insight

Vulnerability & Exposure Intelligence

  • **Analyse vulnerability data from Tenable and other scanning platforms to:

o Identify high-risk vulnerabilities relevant to current threat activity

o Prioritise remediation based on exploitability, exposure, and threat actor interest

  • Correlate vulnerability findings with:

o Threat intelligence (active campaigns / exploitation in the wild)

o Customer environments and technology stacks

  • Support development of:

o Vulnerability threat advisories

o Risk-based prioritisation models for customers

  • Work with SOC and engineering teams to ensure vulnerability intelligence informs:

o Detection use cases

o Threat hunting activities

o Customer remediation guidance

Defender & Endpoint Intelligence (MXDR Integration)

  • Leverage Microsoft Defender (Endpoint, Identity, Cloud, Office) telemetry to:

o Identify emerging threat patterns and suspicious behaviours

o Support investigations with enriched threat intelligence context

  • Correlate Defender alerts with known threat actor TTPs and campaigns
  • Lead on:

*o***Identification of gaps in detection coverage

o Development of intelligence-led improvements to Defender use cases

  • Be the SME for :

o Exploitation techniques observed in real environments

o Trends across customer estates

Threat Monitoring & Tooling

  • **Lead monitoring of:

o Dark web sources

o External attack surface exposure

o Vulnerability disclosures and exploitation trends

  • Lead on evaluation and usage of threat intelligence platforms and tooling
  • Maintain tracking of relevant:

o Indicators of Compromise (IOCs)

o Vulnerabilities and CVEs

o Threat actor campaigns

Service Development & Improvement

  • **Lead on development of SCC threat intelligence services and offerings
  • Lead on refining use cases, playbooks, and detection logic based on emerging threats
  • Support RFP responses, service design, and customer proposals for threat intelligence capabilities

Collaboration & Knowledge Sharing

• Work collaboratively with SOC, engineering, and solution teams

  • Share threat insights across the SOC to improve collective awareness and response capability
  • Maintain awareness of current and emerging threats affecting key sectors and customer environments
  • Will mentor other more junior Threat Analysts

Skills and experience

  • Experience in researching and analysing threats within a SOC environment
  • Detail-oriented with strong analytical thinkingAble to translate threat intelligence into practical outcomes
  • Collaborative and team-focused
  • Committed to continuous learning in cyber security
  • Good understanding of cyber security principles and threat landscape shown through experience and certifications.
  • Experience of using vulnerability prioritisation and exploit intelligence within a security team
  • Experience working with and troubleshooting Tenable, Defender, or equivalent tooling
  • Knowledge of frameworks such as MITRE ATT&CK
  • Understanding and experience of threat intelligence lifecycle and structured analysis techniques
  • Experience producing reports, briefings, or customer-facing outputs*

About Us

SCC is Europe's largest privately-owned IT business, based out of the new £7m HQ office in Birmingham and we help clients succeed through IT transformation and exceptional customer experiences. We are a business where innovation is greater as we combine unique ideas, people and disciplines. We are a global company that is passionate about IT and where we look to simplify the complex.

We are an equal opportunities employer

SCC is committed to providing equal opportunities and a proactive and inclusive approach to equality and diversity in employment. No applicant or employee will be treated less favourably than another on the grounds of a protected characteristic which are defined as sex, sexual orientation, age, disability, gender reassignment, trade union membership or non-membership, marriage and civil partnership, pregnancy and maternity, race and religion or belief.

If you are selected for interview, and need any reasonable adjustments made for your interview, please let the SCC Talent Acquisition team know, at the point of scheduling.

Diversity & Inclusion at SCC -**https://www.scc.com/diversity-and-inclusion/

Sustainability at SCC -**https://www.scc.com/sustainability-at-scc/

Life at SCC****-**https://www.linkedin.com/company/scc/life

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Birmingham

Why this fits a police background

  • Evidence & case files
  • Intelligence & OSINT
  • Investigative casework
  • Risk & threat assessment
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Digital Media Examiner - Counter Terrorism Policing

    West Midlands Police · Birmingham

    Full-time

    £44,700 – £50,949Estimated

    Across the Counter Terrorism Policing (CTP) network, we have specialist officers and staff dedicated to stopping those who seek to do us harm. We work closely with partners and with the Crown Prosecution Service to put compelling evidence before the courts.

    Posted 8 days ago

  • Cyber Incident Responder

    CYFOR · Manchester

    Full-time

    £40,000 – £50,000Estimated

    Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

    Posted Yesterday

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday