Home Disciplines Threat intelligence & threat hunters
THREAT INTELLIGENCE & HUNTING
Threat intelligence and threat hunting recruitment
Threat intelligence is the discipline most likely to produce work nobody uses. Hiring well here means finding analysts who write for a decision rather than for a feed, and hunters who form hypotheses instead of running saved queries.
What we place
- CTI ANALYST
- Collection, assessment and reporting. Judged on whether the output changes what the business or the SOC does next.
- THREAT HUNTER
- Hypothesis-driven hunting across endpoint and log telemetry, feeding findings back into detection content.
- THREAT RESEARCHER
- Adversary tracking, infrastructure analysis and malware triage — most common in vendors and large banks.
- STRATEGIC INTELLIGENCE
- Briefs for executives and risk committees. A writing and judgement role as much as a technical one.
- CTI LEAD
- Owns requirements, stakeholders and the intelligence cycle, and defends the function’s value at budget time.
- BRAND & EXPOSURE
- Digital risk, credential exposure and takedown work. Often mislabelled as intelligence when it is monitoring.
How we screen
We ask for a piece of intelligence someone produced and what changed because of it. The strongest candidates name a decision: a detection written, a control prioritised, a supplier reviewed. Weaker candidates describe volume — feeds consumed, reports issued, indicators enriched.
For hunters, we ask what hypothesis they last tested and how they knew the hunt was finished. Hunting without a hypothesis is browsing, and it is the most common gap we find in candidates whose CVs read well.
The market, honestly
The functions are small and concentrated. In South Africa, real CTI capability sits mainly in the large banks, telecoms and a handful of MSSPs, which makes the candidate pool tight and well networked. In the UK, financial services and government supply chains hire steadily, and clearance requirements narrow parts of the market further.
Because good analysts are as much writers as technologists, we screen written output where clients allow it. A sanitised report tells you more in five minutes than an hour of interview.
If the role is described as threat intelligence but the day job is monitoring a feed and forwarding alerts, strong candidates will work that out in the first interview. Better to name it accurately.
Where we recruit
Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.
Common questions
What is the difference between threat intelligence and threat hunting?
Intelligence produces assessments that inform decisions. Hunting tests hypotheses in your own telemetry to find what detection missed. Some people do both well; most lean clearly one way, and we say which.
Do you place threat hunters into SOC teams?
Yes, frequently. Hunting usually sits at L3 in a security operations function, and the strongest hunters we place also write detection content.
Is intelligence experience from government or military transferable?
Often very. Analytical tradecraft, sourcing discipline and clear writing transfer well. What sometimes does not is the commercial pace and the need to justify the function to a budget holder.
How do you assess intelligence writing?
With a sanitised sample where the candidate can share one, or a short structured exercise. We are looking for a clear judgement, stated confidence and a recommendation, not a summary of open-source news.
Related disciplines
Talk to us about your search
A short conversation is usually enough to tell you whether we can help.