
Senior Response Manager - Home Office Cyber Security Threat Intelligence
Senior Response Manager - Home Office Cyber Security Threat Intelligence at Home Office in Salford
About the role
Job summary
Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.
The Senior Response Manager with Cyber Threat Intelligence is responsible for supporting threat intelligence activities, including the monitoring, analysis and investigation of cyber security threats, events and incidents. Working as part of a specialist Threat Intelligence team, you will help develop and enhance capabilities to address emerging threats, implement complex intelligence-led solutions, and deliver strategic initiatives focused on threat analysis, risk reduction and continuous improvement across the organisation. You will also support the development and management of intelligence-driven responses to security incidents, collaborating with stakeholders across the business to ensure effective incident handling and strengthen defences against future threats.
You’ll be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office . Applicants can raise any queries to the email address at the bottom of the advert.
Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.
Job description
Threat intelligence professionals support the identification, analysis and assessment of threats whilst helping to improve organisational readiness through exercises, threat hunting hypothesis generation and red team activity. The Threat Intelligence function also advises product and service owners on emerging threats, risks and potential mitigations.
As a Senior Response Manager in Cyber Threat Intelligence, your main responsibilities will be to;
- Carrying out threat intelligence activities in line with defined Standard Operating Procedures.
- Providing advice on mitigation and escalating to a team leader where appropriate.
- Helping to conduct incident response exercises including red teaming and threat-hunting. Communicating the results of investigations and risk mitigations to improve the response to new threats and attack vectors. Conducting post-incident reviews.
- Identifying, analysing and classifying threats, adversary tactics, techniques and procedures (TTPs), security vulnerabilities in networks, systems and applications and mitigating or eliminating their impact. Assisting in the prioritisation of those vulnerabilities through a risk-based approach.
- Triaging intelligence findings, recommending mitigating measures, and supporting vulnerability management activities by providing advice on ways to improve control mechanisms and reduce risk.
- Defining intelligence requirements, methodologies and tools needed to identify and assess threats. Communicating common mitigation strategies and threat trends. Continuously seeking to identify potential service and process improvements leveraging your knowledge of industry best practices, good judgment and problem-solving skills to execute security operations and investigations.
Working Pattern
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Person specification
Essential Skills
You’ll have a demonstrable passion for Threat Intelligence , with the following skills, knowledge or experience in:
- Conducting Threat Intelligence analysis, collection and investigations within a Security Operations Centre environment, with an understanding of vulnerability research, malware analysis and digital forensic techniques.
- Communicating complex threat intelligence and threat assessments to technical and non-technical audiences using analytical frameworks and probabilistic language.
- Using common threat analysis models and frameworks such as STIX, MITRE ATT&CK, Cyber Kill Chain and Diamond Model.
- Building strong partnerships across technical teams, suppliers and stakeholders.
- Leading or managing a team in a technical environment and supporting the development of intelligence requirements and capabilities.
- Utilising Security Information and Event Management (SIEM) and Threat Intelligence Platforms (TIPs).
- Applying cyber security risk and control frameworks such as NIST, ISO27001, Cyber Essentials and NCSC guidance.
SFIA capability framework
Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org) .
We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.
Delivery and Operation
- Service Management • Incident management (USUP) – Level 3
- Problem management (PBMG) – Level 3
- Security Services • Security operations (SCAD) – Level 3
People and skills
- People management • Performance management (PEMT) – Level 3 ( Generic Level 3 descriptor)
- Resourcing (RESC) – Level 3
Relationships and engagement
- Stakeholder management • Stakeholder relationship management (RLMT) – Level 3 ( Generic Level 3 descriptor)
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Changing and Improving
- Communicating and Influencing
Technical skills
We'll assess you against these technical skills during the selection process:
- Incident management (USUP) – Level 3
- Security operations (SCAD) – Level 3
- Stakeholder relationship management (RLMT) – Level 3
Benefits
Alongside your salary of £49,850, Home Office contributes
£14,441 towards you being a member of the Civil Service Defined Benefit Pension scheme.
Find out what benefits a Civil Service Pension provides (opens in a new window).
Why work for us...
Find out more information at : Benefits - Home Office Careers, but some of the primary ones are:
- A Civil Service Pension with employer contribution rates of at least 28.97%.
- In-year reward scheme for one-off or sustained exceptional personal or team achievements.
- 25 days annual leave on appointment, rising with service.
- 8 days of public holidays, plus 1 additional privilege day.
- Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.
Sign-up on our website to receive emails with information about careers at the Home Office.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window) , and will assess your Behaviours, Experience and Technical skills.
As part of the application process, you will be asked to complete a CV and 1000-word personal statement:
- CV – include a brief employment history outlining for each role, the organisation, job title, dates in post, and key responsibilities and achievements. Any recent employment gaps should be explained. A second section should set out the skills and experience most relevant to this role, drawing on your career, training, and other relevant activities without repeating the employment history. Focus on the evidence that best demonstrates your capability to meet the role requirements.
- Personal statement - this should present a clear and coherent narrative explaining why you are applying, what you would bring to the role, and how your experience meets the essential criteria. Use well ‑ chosen examples to illustrate your impact, drawing on STAR ‑ style thinking where helpful, but ensure the statement reads as a single, flowing document rather than a set of isolated responses.
To ensure you are assessed on merit alone, we ask you to anonymise your application. This means removing personal identifiers such as your name, age, and place of education. You do not need to remove your employment history, job titles, or any information about your work.
Watch our three short videos on how to apply for our roles: Applying - Home Office Careers.
Problems during the application process
If you experience problems accessing this advert, or you think you’ve made a mistake on an initial application, please contact hocandidates.grs@cabinetoffice.gov.uk, including the vacancy reference, at least two working days before the vacancy closes. Further information can be found on our website .
Do not create or attempt to submit another application, online test or use a different Civil Service Jobs account to proceed as this would be in violation of the candidate declaration.
Sift Stage
The sift will be held on the CV and Personal Statement . Please read the essential skills for this position carefully. We will only consider those who meet the listed requirements.
In the event of a high number of applications received, the sift will be held on the Personal Statement only .
Interview Stage
Candidates reaching the required standard will then be invited to attend an interview. The interview will assess your Technical Skills (SFIA Framework) and behaviours using technical and behaviour-based questions.
At the beginning of the interview, you will be required to deliver a presentation. The presentation topic will be provided prior to you at least 48 hours before your interview.
If you are invited to an interview, you will be required to bring a range of documentation for the purposes of establishing identity and to aid any pre-employment checks. Please see the attached list of Home Office acceptable ID documents.
Sift and Interview dates
The sift will commence from 5 October 2026.
Interviews are expected to take place from 26 October 2026. (Subject to the Panel’s operational requirements/priorities).
Interviews will be conducted remotely via MS Teams.
We will try to meet the dates set out in the advert. There may be occasions when these dates will change. You will be provided with sufficient notice of the confirmed dates.
Further information
If you have previously made an unsuccessful application for a role with the same essential skills and are not able to demonstrate how you have developed these skills since your last application, please reconsider applying as your application is unlikely to be successful.
In order to process applications without delay, we will be sending a Criminal Record C
