CTI Specialist- Nation State Threats

Assembly, Bristol, United Kingdom

BT Group

From Ultra Fast Full Fibre broadband to TV & Mobile, BT helps UK families, communities & companies reach their potential. Find more BT products here.

View all jobs at BT Group

Apply now Apply later

Why this job matters

BT Group is one of the most critical of all UK Critical National Infrastructure. 
Our job is simple -  defend it from Cyber Attack. 
Your role at BT is pivotal in helping us achieve this. You will have access to an unparalleled level of data and security tooling to help us achieve our goal of being the world’s most trusted connector of people, devices and machine by 2030. 

This role follows hybrid working (3 days in the office, 2 days from home) in the following locations: Bristol, Ipswich Manchester
 

SC Clearance eligibility is advantageous 
 

What you’ll be doing

  • Utilize technical datasets (both proprietary and open-source) to uncover new insights into Chinese APT activity, identifying key infrastructure, TTPs, and adversarial behaviours.
  • Leverage commercial tools, proprietary platform, and OSINT to track the infrastructure and operational activity of Chinese threat actors, focusing on their evolving techniques and attack surfaces.
  • Maintain up-to-date knowledge of the latest developments in APT threat landscape, specifically focusing on China.
  • Provide critical intelligence support for security incident response, conducting investigations into key indicators, TTPs, and artefacts to aid in ongoing incidents.
  • Identify and propose new datasets for ingestion, and develop analytics methods to improve intelligence gathering, tracking, and reporting.
  • Leading collaboration activities with internal teams across the organisation in order to provide further internal understanding of potential adversaries and attack vectors.
  • Work closely with the Capability Development team to ensure that the necessary data and analytics are correctly designed, integrated, and deployed in our proprietary platform, enabling continuous tracking of adversary infrastructure and activities.
  • Relationship management within the CTI community. Representation of BT in a wide range of intelligence exchange forums, to ensure impactful collaboration across the Telco and National Security communities including direct engagement with NCSC and NCA.
  • Delivery of verbal presentations and threat briefs, in-person and virtually, to internal and external stakeholders at all seniority levels.

 

Who are we looking for?
Skills/Experience

Must Have

  • 4+ years of experience in Information Security and/or Threat Intelligence
  • Proven expertise in OSINT collection and analysis.
  • Strong proficiency in SQL and Python for data analysis and automation.
  • Experience in network analysis, including identifying malicious network traffic, communication patterns, and threat actor infrastructure, with in-depth knowledge of TCP/IP and related protocols for detecting intrusions and analyzing infrastructure.
  • Familiarity with Censys, Shodan, and other threat intelligence tools.
  • Experience in tracking multiple state-sponsored activity groups (experience with Chinese adversaries is a plus, but not mandatory).
  • Strong written reporting skills for creating clear, concise, and actionable intelligence reports.
  • Knowledge and understanding of current security threats, threat models, frameworks, and common mitigations.
  • Excellent people skills with the ability to communicate complex information effectively to both technical and non-technical audiences.

Nice to Have

  • Experience within another Telecommunications or CNI environment.
  • Relevant certifications in the threat intelligence domain (e.g., GIAC GCTI, CREST CRTIA, or similar).
  • Hands-on experience with commercial CTI tools and platforms (e.g., Crowdstrike, Mandiant, Anomali).

Benefits

At BT, we entertain, educate, and empower millions of people every single day. We’re a brand built on connecting people – whether that’s friends, family, businesses, or communities. Working here, you’ll receive an attractive salary and a range of competitive benefits, but – more than that – you’ll be joining an ambitious organisation with a culture of togetherness, collaboration, and inclusivity, that takes a genuine and proactive interest in your progress and development. 

  • Competitive salary 
  • 10% on target bonus 
  • BT Pension scheme, minimum 5% Employee contribution, BT contribution 10% 
  • 25 days annual leave (not including bank holidays), increasing with service 
  • Huge range of flexible benefits including cycle to work, healthcare, season ticket loan 
  • World-class training and development opportunities 
  • Option to join BT Shares Saving schemes. 
  • Discounted broadband, mobile and TV packages 
  • Access to 100’s of retail discounts including the BT shop 

About us

BT is part of BT Group, along with EE, Openreach, and Plusnet.

Millions of people rely on us every day to help them live their lives, power their businesses, and keep their public services running. We connect friends to family, clients to colleagues, people to possibilities. We keep the wheels of business spinning, and the emergency services responding. 

We value diversity and celebrate difference. ‘We embed diversity and inclusion into everything that we do. It’s fundamental to our purpose: we connect for good.’

We all stick to the same values: Personal, Simple, and Brilliant. From day one, you’ll get stuck in to tough challenges, pitch in with ideas, make things happen. But you won’t be alone: we’ll be there with help and support, learning and development.  

This is your chance to make a real difference to the world: to be part of the digital transformation of countless lives and businesses. Grab it.

 

A FEW POINTS TO NOTE:

Although these roles are listed as full-time, if you’re a job share partnership, work reduced hours, or any other way of working flexibly, please still get in touch.

We will also offer reasonable adjustments for the selection process if required, so please do not hesitate to inform us.

DON'T MEET EVERY SINGLE REQUIREMENT?

Studies have shown that women and people who are disabled, LGBTQ+, neurodiverse or from ethnic minority backgrounds are less likely to apply for jobs unless they meet every single qualification and criteria. We're committed to building a diverse, inclusive, and authentic workplace where everyone can be their best, so if you're excited about this role but your past experience doesn't align perfectly with every requirement on the Job Description, please apply anyway - you may just be the right candidate for this or other roles in our wider team.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0
Category: Threat Intel Jobs

Tags: Analytics APT Automation Clearance CREST CrowdStrike GCTI GIAC Incident response OSINT Python SHODAN SQL TCP/IP Threat intelligence TTPs

Perks/benefits: Career development Competitive pay Flex hours Salary bonus Team events

Region: Europe
Country: United Kingdom

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.