Cloud People
Threat Intelligence Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Threat Intelligence Analyst
Full-time
Permanent
💰 £40,000 to £50,000
📍 UK based remote with very occasional travel to Scotland HQ office
Company & Role
This opportunity sits with a long established Microsoft partner delivering consultancy and managed services to clients across the public and private sectors.
Security is a growing part of what they deliver, and this hire is about strengthening the threat side of that capability. You will be hunting across customer environments built on the Microsoft security stack, turning intelligence into detection, and giving the wider team a clearer picture of what is actually being aimed at their clients.
It is a hands-on analyst role in a team small enough that what you find gets acted on rather than filed.
Why This Role Stands Out
- Proactive hunting and intelligence is the job here, not something you squeeze in between alerts.
- Multiple customer environments across different sectors, so the threat picture is genuinely varied rather than one estate seen over and over.
- Deep exposure to Microsoft Sentinel, Microsoft Defender and Microsoft Entra, with room to go as far into KQL as you want to take it.
- The security capability is being built out rather than maintained, so there is real scope to shape how hunting and intelligence are done.
- Funded certifications and a personal technical budget, with proper support to keep your skills current.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key Responsibilities
- Run proactive threat hunts across customer environments using Microsoft Sentinel and Microsoft Defender.
- Write and tune KQL queries, hunting hypotheses and detection rules.
- Collect, analyse and contextualise threat intelligence from open source, commercial and Microsoft feeds, and turn it into something the team can act on.
- Track threat actors, campaigns and tradecraft relevant to the customer base, and report on what actually matters to them.
- Provide intelligence context during investigation and escalation of significant incidents.
- Improve detection coverage and reduce noise across monitored environments.
- Produce clear threat intelligence reporting for internal teams and for customers.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Ideal Experience
- Demonstrable threat hunting experience using the Microsoft security stack, particularly Microsoft Sentinel and Microsoft Defender.
- Strong KQL, with the ability to write your own hunting queries rather than run someone else's.
- Threat intelligence experience across collection, analysis and reporting.
- Working knowledge of MITRE ATT&CK and using it to frame hunts and measure detection coverage.
- Understanding of attacker tradecraft across identity, endpoint and cloud.
- Experience in a SOC, MSSP or multi-customer environment is useful.
- Certifications such as SC-200 are welcome but not essential.
If you are strong on hunting and want the intelligence side to be a real part of the role rather than a background task, this one is worth a conversation.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location