Job Title: Cyber Threat Intelligence Manager
Location: Hybrid
Duration: 6 Months
Start Date: ASAP
Rate: Competitive (Inside IR35)
We want to maximise the potential of everyone who chooses to work for us. We offer a great work life balance. You have the opportunity to work at any of our brand-new Regional Centres and to also work remotely. Contracts vary in length dependent upon the project with the possibility to extend.
Your time spent with us short or long term will be invaluable - your skills and expertise are needed to deliver the largest projects in Government. There really couldn’t be a better time to join HMRC for your new contract opportunity!
The Fraud Prevention Centre (FPC) is HMRC’s dedicated hub for tackling identity-based fraud at scale, protecting the integrity of the UK’s tax system and safeguarding public funds. As part of HMRC Security’s Identity team, the FPC combines advanced analytics, intelligence, and cutting-edge technology to identify and disrupt fraudulent activity before it impacts customers.
In this critical role as Threat Intelligence Lead, you will shape and drive our intelligence strategy providing actionable insights on emerging threats, guiding proactive defence measures, and ensuring HMRC stays ahead of adversaries. Working at the heart of HMRC’s digital transformation, you’ll collaborate across security teams and the wider organisation to deliver intelligence that underpins trust and resilience in our services.
You will establish and lead a team to maintain a threat intelligence taxonomy grounded in MITRE ATT&CK, mapping adversary TTPs to HMRC-relevant techniques and detection logic to ensure consistency and traceability from intel to action. By structuring intelligence using STIX/TAXII standards and operationalising indicators in MISP, you’ll enable rapid enrichment, correlation, and automated distribution of high-fidelity IOCs to the right teams.
Working across the FPC and wider HMRC, you’ll enable threat-informed, real-time interventions, integrating threat intelligence platforms with SIEM and orchestration technology. You’ll establish feedback loops with the SOC, red/purple teams, and data science functions to validate signal quality, tune detections against ATT&CK techniques, and continuously uplift coverage. Your approach will embed measurable coverage metrics (e.g., ATT&CK heatmaps, detection maturity scores) and ensure intelligence is actionable, timely, and resilient against evolving fraud threats.
Join us to lead intelligence to combat fraud harness advanced tools, shape strategy, access world-class training, and make a real impact by protecting millions of taxpayers and safeguarding the UK’s digital future.
Person Specification:
Essential Criteria::
Desirable Criteria
Our Values
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact your designated recruiter to request accommodation.
This website uses cookies.
We use cookies to personalise content such as job recommendations, and to analyse our traffic. You consent to our cookies if you click "I Accept". If you click on "I Do Not Accept", then we will not use cookies but you may have a deteriorated user experience. You can change your settings by clicking on the Settings link on the top right of the device
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. If you do not allow these cookie we will not know when you have visited our site, and will not be able to monitor its performance.