Recruitment open: Cyber Threat Analysts (multiple vacancies)

SUVAT is recruiting four Cyber Threat Analysts to join our Threat Analysis Division. These roles offer the opportunity to work at the forefront of the United Kingdom's response to spam, malware, and cyber threats. Applications close on 30 November 2025.

Application deadline: 30 November 2025, 23:59 GMT

Number of vacancies: 4

Salary range: £42,000 – £55,000 per annum (depending on experience and location)

Locations: London

Contract type: Permanent, full-time

About the role

As a Cyber Threat Analyst at SUVAT, you will play a central role in analysing the growing threats posed by spam, malware, and cyber criminal activity. Working within our Threat Analysis Division, you will analyse malicious software, produce actionable threat assessments, and contribute to the development of guidance that helps organisations across all sectors defend themselves.

Your work will directly inform SUVAT's advisories, published guidance, and engagement with international partners. You will collaborate closely with colleagues across SUVAT and with external cyber security organisations.

Key responsibilities

  • Malware analysis — conduct static and dynamic analysis of malicious software samples to determine capabilities, communication protocols, and attribution indicators. Produce detailed technical reports suitable for both specialist and non-specialist audiences.
  • Threat analysis production — collect, collate, and analyse information from multiple sources to produce assessed threat reports. Identify trends, track threat actor groups, and provide timely warning of emerging campaigns.
  • Open-source research — monitor publicly available sources, including security research publications, dark web forums, and social media, to identify new threats, vulnerabilities, and indicators of compromise relevant to the UK.
  • Indicator development and sharing — develop and curate indicators of compromise (IOCs) and detection signatures for dissemination to partner organisations and critical national infrastructure operators.
  • Stakeholder engagement — brief internal and external stakeholders, including organisations and industry partners, on the current threat landscape and provide tailored advice on mitigations.

What we are looking for

Essential requirements

  • A degree in computer science, cyber security, information technology, or a related discipline — or equivalent professional experience demonstrating the required competencies.
  • Demonstrable experience in at least one of the following areas: malware analysis, threat intelligence, incident response, or penetration testing.
  • Strong analytical skills and the ability to communicate complex technical information clearly, both in writing and verbally.

Desirable qualifications and experience

  • Professional certifications such as GIAC Reverse Engineering Malware (GREM), CREST Certified Threat Intelligence Manager (CCTIM), or equivalent.
  • Experience with malware analysis tools and sandboxing environments (e.g., IDA Pro, Ghidra, Cuckoo Sandbox, ANY.RUN).
  • Familiarity with structured threat intelligence frameworks such as MITRE ATT&CK, STIX/TAXII, and the Diamond Model.
  • Programming or scripting skills in Python, PowerShell, or similar languages.
  • Experience of working in cyber security, technology, or related analytical roles.

What we offer

SUVAT offers a competitive benefits package alongside the opportunity to work on issues of genuine national importance:

  • Salary of £42,000 – £55,000 per annum, dependent on experience and location.
  • Employer pension contribution.
  • 25 days annual leave, rising to 30 days after five years of service, plus public holidays.
  • Flexible working arrangements, including hybrid working (minimum three days per week in the office).
  • Access to funded professional development and training, including attendance at conferences and pursuit of professional certifications.
  • Employee assistance programme and wellbeing support.

Diversity and inclusion

SUVAT is committed to building a workforce that reflects the diversity of the United Kingdom. We welcome applications from all backgrounds, regardless of age, disability, gender identity, race, religion, sexual orientation, or socio-economic background. We guarantee an interview to disabled applicants who meet the minimum criteria for the role.

We recognise that cyber security talent comes from many pathways, and we value diverse perspectives in our analytical work. If you are unsure whether your experience meets the requirements, we encourage you to apply.

How to apply

Applications should be submitted through the SUVAT careers portal. You will be asked to provide:

  1. A current CV (maximum two pages).
  2. A personal statement (maximum 750 words) explaining how your skills and experience meet the essential requirements of the role.
  3. Details of two professional referees.

The closing date for applications is 30 November 2025 at 23:59 GMT. Shortlisted candidates will be invited to an assessment centre in January 2026, which will include a technical exercise, a written assessment, and a competency-based interview.

Apply now: Visit the SUVAT careers page to submit your application.

Contact

For informal enquiries about the role, please contact the SUVAT Recruitment Team at recruitment@suvat.uk. For queries about the application process or reasonable adjustments, email hr@suvat.uk.

← Back to all news