Cyber Threat Intelligence Analyst
Home Office · Salford, England
Cyber Threat Intelligence Analyst at Home Office, based in Salford, England, paying £41,750 - £44,250 per annum. This is a permanent role.
- Salary
- £41,750 - £44,250 per annum
- Location
- Salford, England
- Contract
- Permanent
- Posted
- 1 day ago
- Closes
- 2 Oct 2026
- Sector
- Security
26% below the typical rate for security
Reference 3689139e179f61f81d08ff1cdee2af451f6d3ed7
About the role
Job summary
The Home Office works to build a safe, fair and prosperous UK. We achieve this through our work on counter-terrorism, policing, crime, drugs policy, immigration and passports.
Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.
The Home Office Cyber Security Operations Centre (CSOC) operates 24/7/365 to safeguard the department from cyber threats. The CSOC’s Threat Intelligence team is a core function and is responsible for collecting, analysing, exploiting, and disseminating intelligence to stakeholders to inform decision making and mitigate risks.
As a Cyber Threat Intelligence Analyst, you’ll use your skills and expertise to assist in meeting emerging threats and implement complex solutions. Additionally, you’ll help in the development of the Home Office cyber risk response, focussing on process improvement. You will also support the response to security incidents, communicating with other organisational business areas to ensure an effective response and mitigate against future incidents.
Job description
You will be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.
The Cyber Threat Intelligence Analyst supports the development of intelligence requirements by capturing stakeholder needs to guide individual and team collection efforts to ensure the timely delivery of threat intelligence that supports CSOC detection and Home Office protective measures. This also includes disseminating intelligence across HMG and operational partners where appropriate.
Key responsibilities
- Assisting in carrying out threat intelligence activities in line with team procedures and the organisation’s response policies and processes.
- Helping provide security advice and guidance on control implementation to inform mitigation strategies, escalating where appropriate.
- Helping to conduct intelligence and incident response exercises (e.g. red teaming, threat hunting, table tops and analytical exercises) by supporting design and implementation.
- Communicating investigation results, supporting improvement and development of responses to new threats. Assisting in post-incident review activities to improve monitoring, detection, and response.
- Supporting in identifying and classifying security threats to networks, systems and applications based on threat actor capabilities and motivations. Assisting stakeholders in the understanding of threats through a structured approach and the creation of relevant products.
- Continuously monitoring the cyber threat landscape to identify trends, emerging threats, and vulnerabilities, using appropriate tooling and processes.
- Supporting the triaging and prioritising of vulnerabilities using threat intelligence, supporting implementation of mitigating measures, assisting to provide standardised products on ways to improve control mechanisms and mitigate risk - including producing CVE advisories / enrichment products.
- Continuously seeking to identify service and process improvements increasing your knowledge of industry best practices, good judgment and problem-solving skills to execute security operations and investigations.
An employee may be required to carry out other duties within the scope of the grade and within the limits of their skill, competence and training.
Working Pattern
Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Travel
Occasional travel may be required to other work locations within the UK according to business needs and may include overnight stays. All related costs will be reimbursed in line with Home Office policy.
Person specification
Essential Criteria
You’ll have a demonstrable passion for Cyber Security with the following skills, knowledge or some experience in:
- Awareness of cybersecurity principles, such as threat analysis, vulnerability research, intelligence analysis
- Communicating in a verbal and written manner, and a good understanding of the use of different channels and formats for different audiences
- Building strong partnerships with peers across the technology organisation
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework).The six technical skills for this role align to Cyber Threat Intelligence Analyst. Use the SFIA levels of responsibility to understand what would be expected for each technical skill listed. Please see below the relevant six technical skills for Cyber Threat Intelligence Analyst:
Strategy and Architecture
- Security and Privacy
- Threat intelligence (THIN) – Level 2
Delivery and Operation
- Service Management
- Service level management (SLMO) – Level 2
- Incident management (USUP) – Level 2
- Problem management (PBMG) – Level 3
- Security Services
- Security operations (SCAD) – Level 2
Relationships and Engagement
- Stakeholder Management
Stakeholder relationship management (RLMT) – Level 3 Generic Level 3 descriptor)
Behaviours
We'll
Reference: 3689139e179f61f81d08ff1cdee2af451f6d3ed7 · Posted 1 day ago · Closes 2 Oct 2026 · Listed via Home Office
Apply for this job
This role is listed via Home Office. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.