Cyber Threat Specialist (Blue Team)

Sorry, this job was removed at 12:08 p.m. (CST) on Monday, Apr 13, 2026
Be an Early Applicant
London, Greater London, England, GBR
In-Office
Fintech • Financial Services
The Role
Cyber Threat Specialist (Blue Team)

Shift Pattern:

Standard 40 Hour Week (United Kingdom)

Scheduled Weekly Hours:

40

Corporate Grade:

E - Associate

Reporting Line:

(UK Division) Information Technology

Location:

UK-London

Worker Type:

Permanent

Overall Purpose of Role

The Cyber Threat Specialist works in the Threat Detection & Response Team which focuses on defensive cyber security services to the LME and LME Clear. Working closely with peers within the Information Security function and stakeholders across the wider group, they will define and deliver a modern and effective defensive cyber security capability.

The role will primarily focus on defensive security disciplines (detection engineering, incident handling, investigation and forensics, SOAR automation, threat hunting, threat intelligence). The successful candidate should have a minimum of 3 years of experience in hands-on defensive security operations and up to date knowledge of attacker TTPs. The successful candidate will work closely with IT Engineering, Security Engineering, and Infrastructure teams to ensure that security controls are effectively implemented and maintained across LME’s platforms.

Key Responsibilities

Detection Engineering

  • Design, implement, and validate high-fidelity detection and response rules.
  • Lead the testing of rules against detection frameworks and support the continuous optimisation and recertification of existing detection content.

Incident Response

  • Lead and/or support investigations across host, identity, email, SaaS, and cloud workloads.
  • Support forensic and investigation work as needed, including malware analysis.
  • Participate in on-call duties and after-hours support for incident escalations.

Security Engineering & Automation

  • Assist in the deployment and maintenance of security tools and platforms (e.g., DLP, E-Mail Security, Endpoint Protection, SIEM, SOAR, WAF).
  • Develop and support the automation of security tools, configuration, and updates using scripting (e.g. Bash, Python, PowerShell).

Threat Hunting

  • Lead threat hunting exercises based on defined threat models and specific attack scenarios.
  • Perform analysis of existing data to identify anomalous patterns and convert findings into new detections / control enhancements.
  • Participate in Blue/Purple/Red Team testing, identifying gaps/weaknesses in monitoring capabilities and recommend/implement changes.

Threat Intelligence

  • Operationalise threat intel (ISACs, OSINT) into detections, hunts, and control enhancements.
  • Review emerging threat intelligence and produce concise advisories as needed.
  • Stay up to date with current and emerging trends that represent a threat to the LME.

Threat Triage

  • Escalation point for junior analysts to ensure timely triage of alerts from the SIEM/SOAR platform.
  • Support the MSSP by maintaining and improving triage runbooks to help reduce MTTD/MTTR.

Qualifications Required

  • University degree in Computer Science, Information Management, or related field, or equivalent experience.
  • Desirable: One of, or similar to, the following professional qualifications: GIAC (GCIA, GCDA, GCFA, GCIH, GSOC, etc.), Microsoft (SC-200, AZ-500), Security Blue Team (BTL2).
  • Desirable: Demonstrable activity on GitHub showing code / tools development.

Required Knowledge and Experience

Minimum of 3 years’ hands-on experience in at least two of: detection engineering, incident response, security engineering, threat hunting, threat intelligence; exposure to the rest.

Excellent hands-on experience in / understanding of:

  • Security tooling (e.g. EDR, DLP, SIEM, SOAR).
  • Threat investigation and incident response.
  • MITRE ATT&CK, cyber kill chain, and common attacker tradecraft.
  • Offensive tooling e.g. Kali, Cobalt Strike, Metasploit, Bloodhound, Mimikatz, etc.
  • Networking and security protocols (TCP/IP, HTTPS, DNS, Firewalls, Proxy).
  • Operating systems (Windows, Linux/Unix, Kubernetes).
  • Scripting or programming (Bash, Python, PowerShell).
  • CI/CD tools and cloud platforms (e.g., Ansible Tower, Bitbucket, Pipelines, Azure)
  • Secure network architectures and technologies.

Personal Qualities

  • Curiosity about emerging threats and technologies
  • Ability to assess and prioritize tasks/risks
  • Excellent attention to detail
  • Strong analytical and problem-solving skills.
  • Effective communicator with good documentation habits.
  • Team-oriented, proactive, and adaptable in a fast-paced environment.
  • Willingness to learn and grow within a critical infrastructure environment.
  • Commitment to continuous learning

The LME is committed to creating a diverse environment and is proud to be an equal opportunity employer. In recruiting for our teams, we welcome the unique contributions that you can bring in terms of education, ethnicity, race, sex, gender identity, expression and reassignment, nation of origin, age, languages spoken, colour, religion, disability, sexual orientation and beliefs. In doing so, we want every LME employee to feel our commitment to showing respect for all and encouraging open collaboration and communication.

Hong Kong Exchanges Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Hong Kong Exchanges and has not been reviewed or approved by Hong Kong Exchanges.

  • Retirement Support Employer retirement contributions and provident fund structures are described as notably above statutory baselines, with certain entities in the group offering even higher employer pension rates. This strengthens perceived long-term value and helps total compensation feel more robust.
  • Healthcare Strength Core coverage includes medical and dental insurance alongside life and personal-accident protection, with health checkups and comprehensive plans highlighted. This breadth of health protection is seen as a meaningful pillar of the package.
  • Leave & Time Off Breadth Paid leave spans multiple categories, including parental and volunteering time, in addition to standard annual and sick leave. This variety adds non-cash value and supports work-life needs.

Hong Kong Exchanges Insights

Similar Jobs

LogicMonitor Logo LogicMonitor

Business Development Representative

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software
Easy Apply
Hybrid
London, Greater London, England, GBR
1100 Employees

Navan Logo Navan

Senior Product Manager

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
London, Greater London, England, GBR
3300 Employees

bet365 Logo bet365

Software Engineer

Digital Media • Gaming • Software • Esports • Automation
In-Office
Manchester, Greater Manchester, England, GBR
10000 Employees

Vantor Logo Vantor

General Manager

Aerospace • Artificial Intelligence • Computer Vision • Software • Analytics • Defense • Big Data Analytics
In-Office or Remote
2 Locations
2500 Employees
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Hong Kong, Hong Kong
1,723 Employees
Year Founded: 2000

What We Do

HKEX Group is a global exchange group, operating dynamic and integrated financial markets in Asia and Europe. From our home in the financial hub of Hong Kong and an additional base in London, we provide world-class facilities for trading and clearing securities and derivatives in Equities, Commodities, Fixed Income and Currency. Uniquely positioned at the intersection of Chinese and international capital flows, Hong Kong has long been Connecting China with the World. With the accelerated opening-up of China’s capital markets, HKEX continues to be at the forefront of this historic transition, which we believe will Shape the Global Market Landscape

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account