5 hours ago

Cyber Threat Intelligence Manager

HM Revenue & Customs

Hybrid
Contractor
£132,000
Hybrid

Job Overview

Job TitleCyber Threat Intelligence Manager
Job TypeContractor
Offered Salary£132,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

Cyber Threat Intelligence Manager

We want to maximise the potential of everyone who chooses to work for us. We offer a great work life balance. You have the opportunity to work at any of our brand-new Regional Centres and to also work remotely. Contracts vary in length dependent upon the project with the possibility to extend. Your time spent with us short or long term will be invaluable - your skills and expertise are needed to deliver the largest projects in Government. There really couldn’t be a better time to join HMRC for your new contract opportunity!

The Fraud Prevention Centre (FPC) is HMRC’s dedicated hub for tackling identity-based fraud at scale, protecting the integrity of the UK’s tax system and safeguarding public funds. As part of HMRC Security’s Identity team, the FPC combines advanced analytics, intelligence, and cutting-edge technology to identify and disrupt fraudulent activity before it impacts customers.

About the Role

In this critical role as Cyber Threat Intelligence Manager, you will shape and drive our intelligence strategy providing actionable insights on emerging threats, guiding proactive defence measures, and ensuring HMRC stays ahead of adversaries. Working at the heart of HMRC’s digital transformation, you’ll collaborate across security teams and the wider organisation to deliver intelligence that underpinning trust and resilience in our services.

You will establish and lead a team to maintain a threat intelligence taxonomy grounded in MITRE ATT&CK, mapping adversary TTPs to HMRC-relevant techniques and detection logic to ensure consistency and traceability from intel to action. By structuring intelligence using STIX/TAXII standards and operationalising indicators in MISP, you’ll enable rapid enrichment, correlation, and automated distribution of high-fidelity IOCs to the right teams.

Working across the FPC and wider HMRC, you’ll enable threat-informed, real-time interventions, integrating threat intelligence platforms with SIEM and orchestration technology. You’ll establish feedback loops with the SOC, red/purple teams, and data science functions to validate signal quality, tune detections against ATT&CK techniques, and continuously uplift coverage. Your approach will embed measurable coverage metrics (e.g., ATT&CK heatmaps, detection maturity scores) and ensure intelligence is actionable, timely, and resilient against evolving fraud threats.

Join us to lead intelligence to combat fraud harness advanced tools, shape strategy, access world-class training, and make a real impact by protecting millions of taxpayers and safeguarding the UK’s digital future.

Key Responsibilities

  • Oversee and task intelligence collection and analysis from multiple sources (FPC teams, teams across HMRC, open-source, commercial feeds, internal telemetry)
  • Lead the acquisition and analysis of cybercrime tools that pose a threat to HMRC services to inform appropriate controls for detection and response
  • Transform raw data into actionable intelligence for proactive threat detection and fraud prevention, mapped to a taxonomy tailored MITRE ATT&CK.
  • Work with Engineering to operationalise intelligence through platforms like MISP, ensuring integration with SIEM, SOAR, and detection technologies.
  • Manage real-time exploitation of intelligence, enabling automated enrichment and distribution of indicators, supporting proactive analytical teams.
  • Produce intelligence reports and contribute data to FPC dashboards for leadership, including threat trends and control effectiveness.
  • Provide expert advice on aspects of cybercrime threats and techniques, supporting stakeholders across HMRC through the FPC advisory function.
  • Work closely with FPC analysts, incident response, and wider HMRC teams to validate intelligence and improve detection logic.
  • Provide training and guidance to drive consistency in intelligence reporting and promote its wider use across HMRC teams, including the application of organisational and wider standards for data handling and intelligence sharing.
  • Provide technical leadership to the FPC, championing leading methodologies in cyber threat intelligence practices and their application in a fraud context

Essential Criteria

  • Proven experience in threat intelligence operations, including collection, analysis, and dissemination of actionable intelligence.
  • Ability to develop and maintain intelligence taxonomies, ensuring consistency and traceability from indicators to detection logic.
  • Strong understanding of cyber threat landscapes, adversary tactics, techniques, and procedures (TTPs), and frameworks such as MITRE ATT&CK.
  • Excellent stakeholder engagement skills, with experience collaborating across security teams and wider business units.
  • Knowledge of fraud prevention techniques and how threat intelligence supports proactive defence in large-scale environments.

Desirable Criteria

  • Certifications such as GCTI (GIAC Cyber Threat Intelligence), CISM, or equivalent.
  • Experience with automation and orchestration for intelligence workflows.
  • Understanding of regulatory and compliance requirements relevant to HMRC and UK government security standards.

Our Values

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact your designated recruiter to request accommodation.

Key skills/competency

  • Threat Intelligence
  • MITRE ATT&CK
  • Fraud Prevention
  • Cybercrime Analysis
  • SIEM/SOAR
  • MISP
  • STIX/TAXII
  • Stakeholder Engagement
  • Security Strategy
  • Detection Engineering

Tags:

Cyber Threat Intelligence Manager
Threat Intelligence
Fraud Prevention
Cybercrime Analysis
Security Strategy
Incident Response
Risk Management
Stakeholder Engagement
Reporting
Data Analysis
Detection Engineering
MITRE ATT&CK
SIEM
SOAR
MISP
STIX/TAXII
Threat Hunting
Open-Source Intelligence
Commercial Feeds
Telemetry
Automation

Share Job:

How to Get Hired at HM Revenue & Customs

  • Research HMRC's culture: Study their mission, values, recent news, and public sector focus on LinkedIn and Glassdoor.
  • Tailor your resume: Highlight extensive experience in threat intelligence, fraud prevention, and MITRE ATT&CK application.
  • Showcase public sector impact: Emphasize your ability to deliver security solutions within large government organizations.
  • Prepare for technical depth: Be ready to discuss MITRE ATT&CK, SIEM/SOAR integration, and cybercrime analysis.
  • Demonstrate collaboration: Provide examples of successful cross-functional team engagement in security operations.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background