Job Title: Cyber Threat Intelligence Manager
Location: Hybrid
Duration: 6 Months
Start Date: ASAP
Rate: Competitive (Inside IR35)
We want to maximise the potential of everyone who chooses to work for us. We offer a great work life balance. You have the opportunity to work at any of our brand-new Regional Centres and to also work remotely. Contracts vary in length dependent upon the project with the possibility to extend.
Your time spent with us short or long term will be invaluable - your skills and expertise are needed to deliver the largest projects in Government. There really couldn’t be a better time to join HMRC for your new contract opportunity!
The Fraud Prevention Centre (FPC) is HMRC’s dedicated hub for tackling identity-based fraud at scale, protecting the integrity of the UK’s tax system and safeguarding public funds. As part of HMRC Security’s Identity team, the FPC combines advanced analytics, intelligence, and cutting-edge technology to identify and disrupt fraudulent activity before it impacts customers.
In this critical role as Threat Intelligence Lead, you will shape and drive our intelligence strategy providing actionable insights on emerging threats, guiding proactive defence measures, and ensuring HMRC stays ahead of adversaries. Working at the heart of HMRC’s digital transformation, you’ll collaborate across security teams and the wider organisation to deliver intelligence that underpins trust and resilience in our services.
You will establish and lead a team to maintain a threat intelligence taxonomy grounded in MITRE ATT&CK, mapping adversary TTPs to HMRC-relevant techniques and detection logic to ensure consistency and traceability from intel to action. By structuring intelligence using STIX/TAXII standards and operationalising indicators in MISP, you’ll enable rapid enrichment, correlation, and automated distribution of high-fidelity IOCs to the right teams.
Working across the FPC and wider HMRC, you’ll enable threat-informed, real-time interventions, integrating threat intelligence platforms with SIEM and orchestration technology. You’ll establish feedback loops with the SOC, red/purple teams, and data science functions to validate signal quality, tune detections against ATT&CK techniques, and continuously uplift coverage. Your approach will embed measurable coverage metrics (e.g., ATT&CK heatmaps, detection maturity scores) and ensure intelligence is actionable, timely, and resilient against evolving fraud threats.
Join us to lead intelligence to combat fraud harness advanced tools, shape strategy, access world-class training, and make a real impact by protecting millions of taxpayers and safeguarding the UK’s digital future.
Person Specification:
Essential Criteria::
Desirable Criteria
Our Values
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact your designated recruiter to request accommodation.
Mae’r wefan hon yn defnyddio cwcis.
Rydym yn defnyddio cwcis i bersonoli cynnwys fel argymhellion swyddi, ac i ddadansoddi ein traffig. Rydych yn cydsynio i’n cwcis os ydych yn clicio "Rwy’n Derbyn". Os byddwch yn clicio ar "Nid wyf yn derbyn", yna ni fyddwn yn defnyddio cwcis ond efallai y bydd gennych brofiad defnyddiwr dirywio. Gallwch newid eich gosodiadau trwy glicio ar y cysylltiad Gosodiadau ar frig y ddyfais
Mae’r cwcis hyn yn angenrheidiol er mwyn i’r wefan weithredu ac ni ellir eu diffodd yn ein systemau. Fel arfer, dim ond mewn ymateb i gamau a wnaed gennych sy’n gyfystyr â chais am wasanaethau, megis gosod eich dewisiadau preifatrwydd, mewngofnodi neu lenwi ffurflenni. Gallwch osod eich porwr i’ch rhwystro neu eich rhybuddio am y cwcis hyn, ond ni fydd rhai rhannau o’r wefan yn gweithio wedyn.
Mae’r cwcis hyn yn ein galluogi i gyfrif ymweliadau a ffynonellau traffig fel y gallwn fesur a gwella perfformiad ein gwefan. Maen nhw’n ein helpu ni i wybod pa dudalennau sydd fwyaf a lleiaf poblogaidd a gweld sut mae ymwelwyr yn symud o gwmpas y wefan. Os na fyddwch yn caniatáu’r cwcis hyn, ni fyddwn yn gwybod pryd rydych wedi ymweld â’n gwefan, ac ni fyddwn yn gallu monitro ei berfformiad.