Find jobs

Senior Security Specialist – Threat Hunting

Yolk Recruitment Ltd
Cardiff · posted 22 August 2026
Location
Cardiff, Wales
Category
IT & Technology

Role: Senior Security Specialist - Threat Hunting

Location: Cardiff (hybrid)

Salary: Band 7

Pension: 20%

The Opportunity

Digital Health and Care Wales vision is to provide world leading digital services, empowering people to live healthier lives, and transforming health and care for everyone in Wales. It is a multi-award-winning organisation, and was twice voted the UK's Best Place to Work in IT.

Job Summary

Support Digital Health and Care Wales in protecting critical systems, applications and sensitive data by leading proactive threat hunting, improving detection capabilities, and providing expert cyber security guidance. The role is a senior technical position within the Cyber Security Operations Centre (CSOC) and includes participation in the cyber on-call rota.

Key Responsibilities

  • Lead proactive threat hunting using intelligence-led and hypothesis-driven approaches.
  • Investigate complex security incidents and provide technical escalation within the CSOC.
  • Develop and optimise SIEM detections, analytics, use cases and KQL queries to improve threat detection and reduce false positives.
  • Identify gaps in logging, monitoring and telemetry across cloud, identity, endpoint, network and application environments.
  • Analyse threat intelligence and emerging risks to improve cyber resilience.
  • Produce technical reports, recommendations and threat hunting outcomes.
  • Provide expert security advice and mentor colleagues through training and knowledge sharing.
  • Collaborate with technical teams and stakeholders to enhance cyber security capabilities across NHS Wales.
  • Degree (or equivalent experience) in Cyber Security, IT or a related technical discipline.
  • Strong knowledge of cyber security operations, threat hunting, incident response and security monitoring.
  • Experience with SIEM platforms (ideally Microsoft Sentinel), KQL or similar analytics tools.
  • Good understanding of cloud, endpoint, identity, network and application security.
  • Knowledge of security frameworks such as NIST or ISO 27001.

Experience

  • Proven experience in cyber security operations, SOC, incident response or threat hunting within a complex environment.
  • Experience analysing security events and telemetry from multiple sources.
  • Experience improving detection capabilities, developing security use cases and tuning SIEM alerts.
  • Experience producing technical reports and security recommendations.

Yolk Recruitment is an equal opportunities employer and embraces diversity in our workforce.

We employ the best people for the job at hand and actively encourage applications from all qualified candidates, regardless of gender, age, race, religion, sexual orientation, disability, educational background, parental status, gender identity or any other protected characteristic.

We champion and celebrate diversity at Yolk allowing our team to bring their whole selves to work.

#J-18808-Ljbffr
← Back to job search
Apply for this job