Threat Hunting and Detection Engineering Specialist - NESO
About the Role
National Energy System Operator’s (NESO) strength lies in our people. We’re shaping the future where clean, affordable energy is accessible for all. Every day is an opportunity to make a real difference by accelerating the progress of sustainable GB energy, keeping people connected, and society thriving as we create a brighter tomorrow.
We are creating a greenfield Cyber Security Operations function and looking for a talented Threat Hunting & Detection Engineering (THaDE) Specialist to join our growing team. The role allows you to assist in delivering innovative threat hunting, detection engineering, and security automation services, supporting the evolution of NESO’s Security strategy and securing the UK’s most critical systems.
The post holder will use collaboration and communication skills to share vision with stakeholders, ensuring the capability is delivered appropriately. They will nurture talent, foster a proactive security culture, and strengthen the organisation’s resilience by effectively delivering an essential area of comprehensive cyber defence in a rapidly changing threat landscape.
This role can be based from Wokingham or Warwick and we continue to offer hybrid working from office and home. We are open to full‑time and part‑time applicants, as well as flexible working arrangements.
Key Accountabilities
* Guide and support the threat hunting and content development functions of the THaDE Team.
* Develop and maintain security content, such as rules, signatures, indicators, dashboards, reports, etc., to enhance the detection and response capabilities of the CSOC.
* Help develop, review, and implement threat hunting and content development policies, standards, procedures, and best practices.
* Help develop, review and implement security automation capability to expedite, enrich and enhance operational security.
* Coordinate and collaborate with internal and external stakeholders, such as IT teams, business units, vendors, auditors, and regulators.
* Contribute to Incident Tiger team investigations with the wider Cyber Defence Team and Incident Management to act as an expert technical resource.
About You
* Passionate about securing unique, complex and critical systems against advanced persistent threats.
* Experience researching the latest attack techniques and building mechanisms to detect them in large data sets.
* Solid experience using SIEM query languages and security automation technology.
* Strong communicator with excellent writing skills.
Qualifications
* Relevant degree‑level qualification or equivalent experience with a strong background in providing threat hunting services in a large hybrid environment, within a government or critical infrastructure domain.
* Significant hands‑on experience in threat hunting, content development, security engineering, operations, or a related field with demonstrable experience leading security teams or projects.
Don’t meet every single requirement? Studies show that women and people of colour are less likely to apply for jobs unless they meet every single qualification. At NESO, we are committed to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience or qualifications don’t match exactly, we encourage you to apply anyway. You might just be the right person for our growing business in this role or another one.
Benefits
A competitive salary up to £65,000 per annum – dependent on experience and capability. As well as your base salary, you will receive a bonus based on company performance, 26 days annual leave as standard, and a competitive contributory pension scheme where we will double match your contribution to a maximum company contribution of 12%.
* Full support and career‑development resources to expand your skills, enhance your expertise, and maximise your potential along your career journey.
* A diverse and inclusive community of belonging, where teammates are empowered to bring ideas to the table.
* Generous Total Rewards Plan – comprising health, finance and wealth, work/life balance, and career benefits.
About Us
The creation of National Energy System Operator (NESO) is driven by an urgent need to unify and optimise our approach to energy. A more integrated and coordinated strategy is needed to meet the unprecedented challenges of climate change, ensuring secure energy supply, and keeping costs manageable for consumers.
Join us and empower your potential, energise our team, and be part of something bigger. Your energy, our future, together.
About the National Energy System Operator (NESO)
In Autumn of 2024, the ESO transitioned to National Energy System Operator, or NESO for short. Previously denoted as the Future System Operator (FSO), the new National Energy System Operator is the independent body responsible for planning Great Britain’s electricity and gas networks and operating the electricity system.
NESO, including all of its existing roles, are now at the heart of the new National Energy System Operator. We will build on our existing roles, capabilities, and ways of working significantly to create an organisation the energy system and its users need. Our new capabilities will enable us to look across vectors, including electricity, natural gas and hydrogen, and consider the trade‑offs between them.
The organisation is set up as a public corporation with its own board of independent directors, with complete operational independence from government, the regulator and any and all commercial interest. As was the ESO, NESO will be licensed and regulated by Ofgem through price control agreements and obligated to identify optimal solutions to system operations and planning in the most sustainable, affordable and secure way for all.
The time to deliver is now. As part of our team, you won’t just be touching the lives of almost everyone in Great Britain – you’ll be shaping the way we use and consume energy for generations to come.
More Information
This role closes on 17th December 2025 at 23:59, however we encourage candidates to submit their application as early as possible and not wait until the published closing date as this can vary.
We work towards the highest standards in everything we do, including how we support, value and develop our people. Our aim is to encourage and support employees to thrive and be the best they can be. We celebrate the difference people can bring into our organisation, and welcome and encourage applicants with diverse experiences and backgrounds, and offer flexible and tailored support, at home and in the office.
We’re committed to building a workforce that represents the communities we serve, and a working environment in which each individual feels valued, respected, fairly treated, and able to reach their full potential.
#J-18808-Ljbffr