
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst at Home Office in Salford
About the role
Job summary
The Home Office works to build a safe, fair and prosperous UK. We achieve this through our work on counter-terrorism, policing, crime, drugs policy, immigration and passports.
Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.
The Home Office Cyber Security Operations Centre (CSOC) operates 24/7/365 to safeguard the department from cyber threats. The CSOC’s Threat Intelligence team is a core function and is responsible for collecting, analysing, exploiting, and disseminating intelligence to stakeholders to inform decision making and mitigate risks.
As a Cyber Threat Intelligence Analyst, you’ll use your skills and expertise to assist in meeting emerging threats and implement complex solutions. Additionally, you’ll help in the development of the Home Office cyber risk response, focussing on process improvement. You will also support the response to security incidents, communicating with other organisational business areas to ensure an effective response and mitigate against future incidents.
Job description
You will be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.
The Cyber Threat Intelligence Analyst supports the development of intelligence requirements by capturing stakeholder needs to guide individual and team collection efforts to ensure the timely delivery of threat intelligence that supports CSOC detection and Home Office protective measures. This also includes disseminating intelligence across HMG and operational partners where appropriate.
Key responsibilities
- Assisting in carrying out threat intelligence activities in line with team procedures and the organisation’s response policies and processes.
- Helping provide security advice and guidance on control implementation to inform mitigation strategies, escalating where appropriate.
- Helping to conduct intelligence and incident response exercises (e.g. red teaming, threat hunting, table tops and analytical exercises) by supporting design and implementation.
- Communicating investigation results, supporting improvement and development of responses to new threats. Assisting in post-incident review activities to improve monitoring, detection, and response.
- Supporting in identifying and classifying security threats to networks, systems and applications based on threat actor capabilities and motivations. Assisting stakeholders in the understanding of threats through a structured approach and the creation of relevant products.
- Continuously monitoring the cyber threat landscape to identify trends, emerging threats, and vulnerabilities, using appropriate tooling and processes.
- Supporting the triaging and prioritising of vulnerabilities using threat intelligence, supporting implementation of mitigating measures, assisting to provide standardised products on ways to improve control mechanisms and mitigate risk - including producing CVE advisories / enrichment products.
- Continuously seeking to identify service and process improvements increasing your knowledge of industry best practices, good judgment and problem-solving skills to execute security operations and investigations.
An employee may be required to carry out other duties within the scope of the grade and within the limits of their skill, competence and training.
Working Pattern
Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Travel
Occasional travel may be required to other work locations within the UK according to business needs and may include overnight stays. All related costs will be reimbursed in line with Home Office policy.
Person specification
Essential Criteria
You’ll have a demonstrable passion for Cyber Security with the following skills, knowledge or some experience in:
- Awareness of cybersecurity principles, such as threat analysis, vulnerability research, intelligence analysis
- Communicating in a verbal and written manner, and a good understanding of the use of different channels and formats for different audiences
- Building strong partnerships with peers across the technology organisation
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework).The six technical skills for this role align to Cyber Threat Intelligence Analyst. Use the SFIA levels of responsibility to understand what would be expected for each technical skill listed. Please see below the relevant six technical skills for Cyber Threat Intelligence Analyst:
Strategy and Architecture
- Security and Privacy • Threat intelligence (THIN) – Level 2
Delivery and Operation
- Service Management • Service level management (SLMO) – Level 2
- Incident management (USUP) – Level 2
- Problem management (PBMG) – Level 3
- Security Services • Security operations (SCAD) – Level 2
Relationships and Engagement
- Stakeholder Management
Stakeholder relationship management (RLMT) – Level 3 Generic Level 3 descriptor)
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
Technical skills
We'll assess you against these technical skills during the selection process:
- Threat Intelligence (THIN) – Level 2
- Service Level Management (SLMO) – Level 2
- Incident Management (USUP) – Level 2
- Problem Management (PBMG) – Level 3
- Security Operations (SCAD) – Level 2
- Stakeholder Relationship Management (RLMT) – Level 3
Benefits
In addition to your salary, a career with the Home Office offers a range of benefits, including:
- A Civil Service pension with an employer contribution of 28.97%.
- In-year reward scheme for one-off or sustained exceptional personal or team achievements.
- 25 days annual leave on appointment, rising with service to 30 days.
- Eight days of public holidays, plus one additional privilege day.
- New entrants to the Civil Service will start their role on the salary band minimum £41,750 for National Roles. Recruitment and Retention Allowance (RRA): Up to £5000 is available for candidates who demonstrate exceptional skills and experience evidenced at interview stage. The advertised role is eligible for a Digital Capability Allowance. Successful candidates with exceptional skills and experience may apply for a Recruitment and Retention Allowance. The allowance values are set by the Home Office, subject to remaining in a qualifying role. This allowance is non-contractual, non-pensionable, subject to an annual review and could be withdrawn at any time. Please see the Home Office Digital Recruitment and Retention Allowance Careers page for more information. For both new entrants and existing civil servants, the total compensation offer is a combination of base salary and, if applicable, a capability-based allowance.
- Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.
- See more of our benefits on our careers website.
- Sign-up on our website to receive emails with information about careers at the Home Office
- Things you need to know
- Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window) , and will assess your Behaviours, Experience and Technical skills.
This gives us the best possible chance of finding the right person for the job, drives up performance and improves diversity and inclusivity.
We will endeavour to conduct the selection process in line with the dates indicated below, but cannot guarantee that these will not, where necessary, be revised.
Application – by 1st October 2026
As part of the application process, you will be asked to complete:
- CV
- Personal Statement (maximum 1000 words).
- Evidence of the Behaviour Making Effective Decisions (maximum of 250 words per Behaviour).
Your CV should consist of your career history and skills/experience , including any key achievements in each role. Your CV will be scored against the experience required for the role as noted within the essential criteria.
The Personal Statement should be aligned to and demonstrate how you meet the skills and experience set out in the essential criteria, detailed in the job description.
For guidance and information on how to construct your application (CV, Personal Statement and Behaviours), you are encouraged to visit Civil Service Careers website.
Sift – commencing 5th October 2026
The sift will be held on the Personal Statement and the CV .
Should a high volume of applications be received, an initial sift will be conducted on the Personal Statement. Candidates who pass the initial sift will then be progressed to a full sift that will consist of all the remaining elements submitted (CV and Behaviour Making Effective Decisions). Candidates who fail to meet the minimum pass score for the initial sift will not have their remaining submitted elements scored and will only receive a sift score for that assessed at the initial sift.
Interview – commencing 26th October 2026
If you are successful at sift stage, you will be invited to an interview that will be Behaviours (as listed in the job advert) and Technical Skills based questions. All Behaviours listed in the selection process will be scored at the interview.
The interview will take place on MS Teams
For guidance on the Technical skills, please refer to the SFIA Framework Skills directory A–Z — English
In addition, candidates will be asked to prepare a 10-minute presentation that will be delivered at interview. The presentation question/scenario will be provided to you with your interview invitation (should you be successful at sift). Slides will be accepted.
The presentation will be assessed against SFIA Framework and will be assessed against the Technical Skills: T hreat Intelligence (THIN) – Level 2, Service Level Management (SLMO) – Level 2 and Security Operations (SCAD) – Level 2
For guidance and information on what to expect and how to prepare for an interview, you are encouraged to visit Civil Service Careers .
Problems during the application process
If you experience problems accessing this advert, or you think you’ve made a mistake on an initial application, please contact hocandidates.grs@cabinetoffice.gov.uk, including the vacancy reference, at least two working days before the vacancy closes. Further information can be found on our website .
Do not create or attempt to submit another application, online test or use a different Civil Service
