Vice President - Senior Threat Hunter
London, England, United Kingdom
CLS Group
CLS's innovative settlement, processing and data solutions reduce risk and deliver efficiency.About CLS:
CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.
Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.
CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.
Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.
Job information:
- Functional title - Senior Threat Hunter
- Department – IT Security
- Corporate level – Vice President
- Report to – Executive Director
- Location - London, onsite 2 days per week
Job purpose:
CLS is seeking a highly motivated, and skilled Senior Threat Hunter to join a global threat management team. The role will be located in London. The position will report to the Head of Cyber Threat Intelligence and will proactively identify, investigate, and mitigate advanced cyber threats across our organization’s network and systems. Leveraging a deep understanding of the latest attack techniques, threat actor tactics, and security tools, you will help safeguard our infrastructure and ensure the resilience of our networks. The ideal candidate will be aware of industry trends and frameworks and how they could impact our business. This role will also be responsible for mentoring others on the team.
This position requires someone with an analytical mind, a quick learner, and the ability to create and deliver briefings, propose, and execute program initiative’s/improvements, and collaborate with a wide range of key stakeholders.
Key responsibilities include:
- Lead proactive efforts to identify and mitigate sophisticated cyber threats, leveraging a variety of tools, techniques, and data sources
- Research, document, and develop Use Cases and Hypotheses for proactive hunting in cyber security tools including SIEM, EDR, and IDS/IPS (extract TTPs and behaviors from research to apply to logging and tool queries/hunts and detections)
- Research, document and develop threat detections based on behavioral attributes of actors, malware operators, and general threats
- Identify and execute tuning/configuration changes to improve detection or reporting capabilities
- Perform deep analysis of alerts, network traffic, and security data to detect anomalous activity, indicators of compromise, and advanced persistent threats (APTs)
- Collaborate with the Security Operations team to investigate and respond to active incidents as needed
- Translate threat intelligence into actionable threat hunting hypotheses
- Maintain clear documentation of threat hunting activities, findings, and lessons learned.
- Produce reports for both executive and technical stakeholders and be able to brief all stakeholders.
- Develop and maintain threat models for key assets within the ecosystem
- Map existing controls to MITRE ATT&CK TTPs and assist with developing new mitigations
- Actively support external intelligence sharing engagements with other financial institutions and government partners
Knowledge, skills and abilities:
- 6-10+ years of direct threat hunting experience
- 5+ years of progressive experience in information security (cyber security) field, preferable in Threat Intelligence, Security Operations or Incident Response roles
- Understanding of intelligence lifecycle and risk management
- Knowledge of fundamentals of threat actors’ TTPs
- Familiarity with MITRE ATT&CK framework and mapping
- Experience with threat intelligence platforms and analyzing indicators of compromise, TTPs, and adversary behavior
- Knowledge of TCP/IP, network protocols, and deep packet inspection
- Threat Modeling expertise
- Excellent interpersonal and relationship management skills
- Individual contributor whilst also contributing to a small team
- Self-motivated with ability to work with minimal supervision
Qualifications and certifications:
- Bachelor’s Degree in Cybersecurity studies, Computer Science, Intelligence Studies, International Relations, or related discipline
- Security certification such as SANS GIAC (or equivalent) ideally GCFA, GNFA or working towards certification (or equivalent)
- Experience with threat intelligence and SOC/CIRT interaction
- Splunk experience is highly preferred
- Scripting or automation knowledge, especially Python experience is highly preferred
- Experience with SIEM, EDR solutions, network monitoring tools, and other cyber security tools
- Experience with threat intelligence vendors
- Ability to work on-site at least twice a week in London and/or participate in local intelligence sharing groups
- Financial sector experience
Our commitment to employees:
At CLS, we celebrate diversity and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:
- Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
- 2 paid volunteer days so that you can actively support causes within your community that are important to you.
- Generous parental leave policies to ensure you can enjoy valuable time with your family.
- Parental transition coaching programmes and support services.
- Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
- Affinity Groups (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about DE&I.
- Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
- Active support of flexible working for all employees where possible.
- Monthly ‘Heads Down Days’ with no meetings across the whole company.
- Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
- Private medical insurance and dental coverage.
- Social events that give you opportunities to meet new people and broaden your network across the organisation.
- Annual flu vaccinations.
- Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
- Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
- All employees have access to Discover – our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
- Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation Computer Science EDR GCFA GIAC GNFA IDS Incident response IPS Malware MITRE ATT&CK Monitoring Python Risk management SANS Scripting SIEM SOC Splunk TCP/IP Threat intelligence TTPs
Perks/benefits: 401(k) matching Career development Fitness / gym Flex hours Health care Medical leave Parental leave Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.