Threat Assessment Lead

4 days ago


Manchester, United Kingdom Home Office Full time

**Details**:
**Reference number**:

- 412934

**Salary**:

- £60,300 - £66,330
- New entrants to the Civil Service will start their role on the salary band minimum: £60,300 for National Roles.
You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills assessment, with a value of up to £20,100 (location dependent)
- A Civil Service Pension with an employer contribution of 28.97%

GBP

**Job grade**:

- Grade 7

**Contract type**:

- Permanent

**Business area**:

- HO - Digital Data and Technology - Cyber Security

**Type of role**:

- Digital
Information Technology
Security

**Working pattern**:

- Full-time

**Number of jobs available**:

- 1

**Contents**:

- Location
- About the job
- Benefits
- Things you need to know

**Location**:

- Manchester - Soapworks

**About the job**:
**Job summary**:
Cyber Security at the Home Office is critical to protecting a large government department and safeguarding critical digital infrastructure. The Cyber Security Operations Centre (CSOC) Threat Intelligence team is tasked with understanding and contextualising the Home Office’s cyber threat landscape. The team manages the department’s intelligence requirements, based on assessed threats to Home Office systems, then seeks to obtain and analyse data to identify threats and their potential impact. The specialised team of six works alongside other CSOC areas to provide awareness of threats, allowing for the deployment of targeted defences and the sharing of timely and actionable guidance.

The **Threat Intelligence Lead** plays a critical role in the success of the Cyber Security Operations Centre (CSOC) by overseeing all threat intelligence activities. This includes defining intelligence requirements, managing collection and analysis, and ensuring timely dissemination of insights. The role supports protective monitoring, contributes to incident response, and leads the development of team members through line management and professional development.

**Job description**:
As the Threat Intelligence Lead, your day-today responsibilities will be to:

- Lead the delivery of cyber threat intelligence processes, ensuring outputs align with organisational policies and effectively communicate findings.
- Analyse complex threat intelligence to assess risk, prioritise vulnerabilities, and inform strategic mitigation efforts.
- Define tools and policies to assess the threat landscape and advise on risk reduction strategies.
- Maintain and enhance the Threat Intelligence Platform to support automated intelligence and incident investigations.
- Collaborate with stakeholders to develop tactical threat management plans and oversee their execution.
- Manage the Threat Intelligence team, aligning their work with CSOC operational goals and strategic direction.
- Oversee the use of information systems to prioritise cyber risks and support the vulnerability management team with expert guidance.

**Hybrid Working**

**Person specification**:
**Essential Skills**

You’ll bring a strong interest in threat intelligence and demonstrate experience in:

- Operating within a Security Operations Centre (SOC), including threat and risk analysis.
- Leading technical responses to cyber incidents and collaborating across vulnerability management, threat hunting, and monitoring teams.
- Using platforms such as SIEM, EDR, and threat intelligence tools to support investigations and analysis.
- Tracking global cyber trends, adversary campaigns, and geopolitical developments to produce timely, actionable intelligence.
- Evaluating intelligence from OSINT, commercial feeds, government advisories, and internal sources to assess relevance and reliability.
- Producing clear, audience-appropriate threat reports and managing or coaching diverse cyber teams.

**SFIA capability framework**

Skills for the Information Age (SFIA) is the technical framework that sets the standard capability and development of all IT Operations levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org)

We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.

**SFIA levels of responsibility** - Use the SFIA Levels of responsibility to understand what would be expected for each Technical Skill listed below.

**SFIA Technical skills**

The essential technical skills required for this role are listed below and are reflective of the Home Office Government Digital and Data Profession Career Framework.

**Qualifications**
- Desirable to have certification in one or more of the following: CRTIA, CRTIM, CRISC, CISSP, CEH, CCSP and equivalent.

**Technical skills**:
We'll assess you against these technical skills during the selection process:

- Incident management (USUP) - Level 4
- Problem management (PBMG) - Level 4
- Security operations (SCAD) - Level 3
- Performance management (PEMT) - Level 3
- Resourcing



  • Manchester, United Kingdom Canonical Full time

    Join to apply for the Threat Intelligence Lead role at CanonicalJoin to apply for the Threat Intelligence Lead role at CanonicalThe Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and...


  • Manchester, United Kingdom Canonical Full time

    Join to apply for the Threat Intelligence Lead role at CanonicalJoin to apply for the Threat Intelligence Lead role at CanonicalThe Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and...

  • Threat Hunter

    6 days ago


    Manchester, United Kingdom NCC Group Full time

    Threat Hunter UK (Manchester, Cheltenham or London) We are seeking a highly capable and hands-on Threat Hunter to design and lead a professional threat hunting capability focused on identifying sophisticated adversaries through hypothesis-driven analysis and automation. You will be responsible for proactively detecting and analysing advanced threats across...


  • Manchester, United Kingdom BT Full time

    **Threat Hunting Specialist**: - Job Req ID: 49288 - Posting Date: 21 Jul 2025 - Function: Cyber Security - Unit: Networks - Location: New Bailey, Manchester, United Kingdom - Salary: Competitive with Great Benefits **Why this job matters**: BT Group is one of the most critical of all UK Critical National Infrastructure. Our job is simple - defend it from...


  • Manchester, United Kingdom Razorblue Group Ltd Full time

    RazorBlue role We are looking for a Threat Intelligence Analyst to join our growing team of like-minded tech people. Should you choose to accept, your responsibilities will encompass: Delivering strategic and operational threat intelligence to strengthen razorblue and client security. Monitoring threat feeds, OSINT, and internal telemetry for emerging risks...


  • Manchester, United Kingdom NCC Group Full time

    Role: Senior Threat Intelligence Consultant Location: Manchester/London/Cheltenham (Hybrid) Thanks for checking out our job opening; we are excited that YOU are interested in learning more about NCC Group. We are on a mission to make society a safer and more secure place. Our people are the ones who make that possible; a global community of talented...


  • Manchester, United Kingdom UK Home Office Full time

    Salary : £44,720 (plus a capability allowance of up to £12,680)Location : Manchester (hybrid with 60% office attendance)Advert close : 4th December Job summary Cyber Security Response at the Home Office is at the front end of protecting a large government department and safeguarding critical digital infrastructure. This role manages the response procedures...


  • Manchester, United Kingdom Cyber UK Full time

    Hybrid working from one of our UK offices (Manchester, Cheltenham or London.)Thanks for checking out our job opening; we are excited that YOU are interested in learning more about NCC Group.We are on a mission to make society a safer and more secure place. Our people are the ones who make that possible; a global community of talented individuals working...


  • Greater Manchester, United Kingdom National Enabling Programmes (a programme of the Police Digital Service) Full time

    NMC Senior Cyber Threat Hunter (Wigan/Hybrid) Join to apply for the NMC Senior Cyber Threat Hunter (Wigan/Hybrid) role at National Enabling Programmes (a programme of the Police Digital Service). Join Police Digital Service as NMC Senior Cyber Threat Hunter - Hybrid - starting salary £65,000pa About Police Digital Service and NMC At PDS, we empower UK...


  • Manchester, United Kingdom BT Group Full time

    A leading telecommunications firm is seeking a skilled professional to enhance its managed security services through automation and AI. The candidate will understand best practices, collaborate with stakeholders, and own threat intelligence for security operations. Responsibilities include benchmarking BT Security practices and developing strategies for...