NMC Cyber Threat Intelligence Specialist

gb Police Digital Services
Wigan, UK
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
£45,000.0
Working hours
Regular working hours

Tech stack

Business Analytics Applications Intelligence Analysis Intrusion Detection and Prevention Log Analysis Open Source Intelligence Phishing Reduced Instruction Set Computing Security Information and Event Management Malware Cyber Threat Analysis Cybercrime

Job description

This is an opportunity to play your part and protect our company, our customers and our communities from cyber attack. Be part of a dedicated team and get ready to be challenged every day to make the most of your skills and experience. You’ll learn from those around you, and from training and development resources to become even better at what you do. With the best technology at your fingertips, you’ll be part of a friendly and flexible working environment where your contribution is always valued.

The National Management Centre provide visibility and control of information risks for Policing. It supports the 24x7x365 nature of the police operations, providing a threat detection and response capability for digital services before, during and after cyber attacks, enabling stakeholders to understand and proactively manage risk across the technology estate at both the national and force level.

As a member of the Threat Intelligence team, you’ll be involved with:

  • Developing awareness for the policing community of the cyber risks to critical services by continually assessing the threat landscape and informing stakeholders.
  • Reporting cyber risks to service, executive, and operational stakeholders for mitigation decisions.
  • Limiting the impact of known cyber risks by engaging forces in pre-incident planning and preparatory activities.
  • Constraining attack surfaces through proactive threat intelligence working directly alongside the threat hunting and malware service, * Provide expertise and support through the use of analytical products to assist mitigation practices at a tactical and operational level.
  • Analysis of advanced persistent threats including the tactics, techniques, and procedures (TTPs) of attackers.
  • Conduct analysis at a tactical and or operational level, identifying and using appropriate analytical tools and techniques to interpret gaps, patterns and trends, assess threat, risk and harm and make recommendations in support of decision making, prioritization and resource allocation.
  • Ability to correlate intelligence from a variety of sources, to develop and lead understanding and analysis of contextually relevant threats.
  • To lead independent analysis of projects and the development of materials for specific subjects of concern.
  • Ability to work proactively to serve the policing community with limited direct oversight or guidance.
  • Perform a broad range of tasks, bringing together output from stakeholders within Cyber SOC, Malware, Threat Hunting and Vulnerability teams.
  • Preparing and delivering analytical alerts, reports, and briefings to stakeholders to provide a clear and concise evidence-based understanding of the subject matter, including providing advice and guidance.
  • Provide analysis of threat data from a variety of sources resulting in the generation of actionable threat intelligence.
  • Responsible for developing an understanding of the cyber risks facing policing, performing core intelligence tasks focusing on social, cultural and geopolitical context of cyber intelligence analysis., You can find out more here: Benefits - Police Digital Service (pds.police.uk)

Diversity, equity and inclusion

We are committed to equal opportunity for all and will not discriminate on any grounds. We encourage applications from people from the widest possible span of experience. We particularly welcome applications from Black, Asian and Minority Ethnic (BAME) candidates and people with disabilities.

Working Arrangements

At the NMC, you will benefit from hybrid working, getting the advantages of both face-to-face team engagement and home working. NMC employees have the opportunity to work in our new modern office environment for in-person collaboration, however you will also get the opportunity to work from home 2 days a week.

All applicants must be eligible for NPPV3 and SC clearances. Successful applicants will require NPPV3 clearance to have been approved before starting with PDS.

Requirements

  • Knowledge of current threat landscape including specific awareness of adversarial cyber actors, including their TTPs
  • Experience in utilising open-source intelligence and the development of tools to assist with this
  • Experience in conducting malware, phishing, and SIEM log analysis
  • Knowledge of relevant cyber threat intelligence sources
  • Demonstrated ability to manage customer relationships
  • Proven ability to translate cyber threats to the relevant audience, both verbally and written.
  • Ability to generate clear and concise reports and presentations for stakeholders, from technical analysts to management and senior leadership teams.
  • Experience in internal and external stakeholder management and engagement
  • Experience of working in an intelligence environment, ideally as an intelligence researcher or analyst
  • Ability to work independently within a cyber environment with limited oversight and/or guidance
  • Experience within an active cyber incident

Desirable Experience

  • 3+ years of experience in an analytical role with specific focus on cyber threats (experience in intelligence and research from other areas specifically military or law enforcement encouraged to apply)
  • CREST Registered Threat Intelligence Analyst
  • Demonstrated experience in developing and delivering cybercrime or risk reduction recommendations and / or strategies
  • Completed Intelligence Analysis course (e.g. NIAT, RISC UK or similar)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

43 sec

Software engineering journey and local Manchester roots

Jonathan Tang · Coffee With Developers

Videos

See all

Related articles

See all