Cyber Threat Intelligence Analyst

Lloyds Banking Group
Bristol, UK
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£48,987.0 - £54,430.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Computer Telephony Integration Graph Database Data Intelligence Open Source Intelligence Phishing Mitre Att&ck Cyber Threat Analysis Cybercrime

Job description

In this role you’ll be conducting intelligence collection, monitoring infrastructure, analysing threat actors, and investigating campaigns. These activities help pinpoint threats relevant to the Group and assist in making timely operational decisions.

Alongside core intelligence responsibilities, you will help advance automated intelligence workflows, AI-assisted analysis capabilities, and intelligence tooling that boost the speed, quality, and scalability of CTI operations.

The role provides the chance to build expertise in threat actor tracking, infrastructure analysis, CTI platforms, automation, AI, and intelligence engineering while directly supporting cyber defence operations.

Why join us?

We’re investing billions in our people, places and tech to change the way we meet the needs of our 28 million customers. We’re growing, and we’d love you to be part of the journey., Our ambition is to be the leading UK business for diversity, equity and inclusion supporting our customers, colleagues and communities, and we’re committed to creating an environment in which everyone can thrive, learn and develop.

Requirements

  • Understanding of cyber threat intelligence concepts, threat actor monitoring, campaign evaluation, intelligence lifecycle oversight, and intelligence documentation.
  • Strong technical curiosity and desire to continuously learn new technologies and analytical approaches.
  • Experience examining threat infrastructure, indicators of compromise, adversary TTPs, phishing activity, malware campaigns, or cyber criminal ecosystems.
  • Strong analytical approach with the ability to assess technical threat information and communicate findings clearly.
  • Understanding of APIs, data enrichment pipelines, workflow automation, and intelligence data management.
  • Experience applying OSINT techniques as part of structured intelligence collection and analysis activities to develop actionable intelligence on threat actors, infrastructure, data breaches, and emerging threats.

And any experience of these would be great

  • Knowledge of MITRE ATT&CK, Diamond Model, Cyber Kill Chain, STIX/TAXII, and structured analytic techniques.
  • Experience building enrichment or collection workflows using APIs.
  • Experience using graph databases, knowledge graphs, or relationship analysis platforms.
  • Understanding of cloud-hosted infrastructure, adversary infrastructure abuse, and cybercrime ecosystem monitoring.

We know that great talent comes from many backgrounds. Whilst this job advert may reference specific years of experience, we recognise that skills are developed in many ways, so if you have relevant, transferable experience, we encourage you to apply.

Benefits & conditions

We were one of the first major organisations to set goals on diversity in senior roles, create a menopause health package, and a dedicated Working with Cancer Initiative.

We offer reasonable workplace adjustments for colleagues with disabilities, including flexibility in office attendance, location and working patterns. And, as a Disability Confident Leader, we guarantee interviews for a fair and proportionate number of applicants who meet the minimum criteria for the role with a disability, long-term health or neurodivergent condition through the Disability Confident Scheme.

We provide reasonable adjustments throughout the recruitment process to reduce or remove barriers. Just let us know what you need.

We also offer a wide-ranging benefits package, which includes:

  • A generous pension contribution of up to 15%
  • An annual performance-related bonus
  • Share schemes including free shares
  • Benefits you can adapt to your lifestyle, such as discounted shopping
  • 28 days’ holiday, with bank holidays on top
  • A range of wellbeing initiatives and generous parental leave policies

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.theguardian.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all