Detection Engineering Support : Translate research findings into technical detection artefacts, such as YARA, Sigma, or Snort rules, to strengthen proactive threat hunting and detection capabilities.
Incident Response Integration : Act as the Tier- 3 intelligence lead during critical incidents, providing real‑time threat context, infrastructure pivoting, and attribution support to the CERT team.
Vulnerability Intelligence : Monitor and prioritise newly disclosed CVEs based on the organisation’s technology stack, providing actionable, risk‑based assessments to patching and infrastructure teams.
...
Integrate threat intelligence into security platforms including SIEM, EDR, Threat Intelligence Platforms (TIPs), and CrowdStrike.
Monitor emerging threats, zero-day vulnerabilities, active exploitation campaigns, and changes in adversary behaviour.
Lead and execute end-to-end cybersecurity incident response activities including triage, investigation, containment, eradication, recovery, and post-incident analysis.
...