Job Title: Cyber Threat Intelligence Manager
Location: Hybrid
Duration: 6 Months
Start Date: ASAP
Rate: Competitive (Inside IR35)
SC Required
We want to maximise the potential of everyone who chooses to work for us. We offer a great work life balance. You have the opportunity to work at any of our brand-new Regional Centres and to also work remotely. Contracts vary in length dependent upon the project with the possibility to extend.
Your time spent with us short or long term will be invaluable - your skills and expertise are needed to deliver the largest projects in Government. There really couldn’t be a better time to join HMRC for your new contract opportunity!
The Fraud Prevention Centre (FPC) is HMRC’s dedicated hub for tackling identity-based fraud at scale, protecting the integrity of the UK’s tax system and safeguarding public funds. As part of HMRC Security’s Identity team, the FPC combines advanced analytics, intelligence, and cutting-edge technology to identify and disrupt fraudulent activity before it impacts customers.
In this critical role as Threat Intelligence Lead, you will shape and drive our intelligence strategy providing actionable insights on emerging threats, guiding proactive defence measures, and ensuring HMRC stays ahead of adversaries. Working at the heart of HMRC’s digital transformation, you’ll collaborate across security teams and the wider organisation to deliver intelligence that underpins trust and resilience in our services.
You will establish and lead a team to maintain a threat intelligence taxonomy grounded in MITRE ATT&CK, mapping adversary TTPs to HMRC-relevant techniques and detection logic to ensure consistency and traceability from intel to action. By structuring intelligence using STIX/TAXII standards and operationalising indicators in MISP, you’ll enable rapid enrichment, correlation, and automated distribution of high-fidelity IOCs to the right teams.
Working across the FPC and wider HMRC, you’ll enable threat-informed, real-time interventions, integrating threat intelligence platforms with SIEM and orchestration technology. You’ll establish feedback loops with the SOC, red/purple teams, and data science functions to validate signal quality, tune detections against ATT&CK techniques, and continuously uplift coverage. Your approach will embed measurable coverage metrics (e.g., ATT&CK heatmaps, detection maturity scores) and ensure intelligence is actionable, timely, and resilient against evolving fraud threats.
Join us to lead intelligence to combat fraud harness advanced tools, shape strategy, access world-class training, and make a real impact by protecting millions of taxpayers and safeguarding the UK’s digital future.
Person Specification:
Essential Criteria::
Desirable Criteria
Discovering Direct IT Contract Opportunities for Contract Spy members.