Open roleExternal
Threat Vulnerability Lead
- london, england, United Kingdom
- £120 - £160 Per Day
Job Description
Lead the enterprise threat intelligence program, overseeing the end-to-end collection, analysis, enrichment, and dissemination of actionable intelligence to executive leadership, Technology, Security Operations, and Cybersecurity stakeholders.
Job Responsibilities
- Serve as the primary owner and administrator of the organisation's ThreatConnect Threat Intelligence Platform (TIP) , ensuring effective integration, maintenance, and optimisation.
- Develop and maintain ThreatConnect workflows, playbooks, dashboards, and intelligence‑sharing processes to improve threat visibility and response capabilities.
- Integrate ThreatConnect with SIEM, SOAR, incident response, and vulnerability management platforms to automate intelligence sharing, enrichment, prioritisation, and reporting.
- Leverage ThreatConnect to manage threat feeds, indicators of compromise (IOCs), threat actor profiles, campaigns, and TTPs aligned to the MITRE ATT&CK framework.
- Continuously improve threat intelligence ingestion, enrichment, correlation, reporting, and operationalisation through ThreatConnect automation and orchestration capabilities.
Desired Skills and Experience
- At least 10 years of experience in cybersecurity engineering or operations roles, with at least 5 years of hands‑on experience in Threat Intelligence and Vulnerability Management.
- Strong experience across the threat intelligence lifecycle, including collection, analysis, enrichment, correlation, and dissemination of actionable intelligence.
- Hands‑on administration and operational experience with ThreatConnect (or similar Threat Intelligence Platforms), including platform configuration, workflow development, feed management, integrations, and reporting.
- Experience integrating ThreatConnect with SIEM, SOAR, incident response, ticketing, and vulnerability management tools.
- Strong understanding of cyber threat intelligence methodologies, threat actor tracking, IOC management, threat feed ingestion, and intelligence‑sharing frameworks.
- Experience working with technologies such as ThreatConnect, Splunk, Microsoft Sentinel, QRadar, ServiceNow, Swimlane, Palo Alto XSOAR, Qualys, Tenable, and Defender TVM.
- Experience automating security workflows using Python, PowerShell, APIs, or similar technologies.
- Strong knowledge of MITRE ATT&CK, NIST CSF, OWASP Top 10, CVEs, and vulnerability risk management best practices.


