> Markdown version of [/jobs/ext/2356259-threat-intelligence-lead](https://www.wearedevelopers.com/jobs/ext/2356259-threat-intelligence-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Intelligence Lead - **Company:** Everywhen, part of the Ardonagh Group - **Location:** London, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Computer Telephony Integration, Intelligence Analysis, Intrusion Detection and Prevention, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Operating System Security - **Published:** August 13, 2026 - **Apply:** https://www.reed.co.uk/jobs/threat-intelligence-lead/57235044 ## About the Role We're looking for an experienced Cyber Threat Intelligence professional who can combine their strong technical expertise with the ability to develop our CTI capability and turn complex intelligence into clear, actionable business insights. * MITRE ATT&CK training/certification is essential. * Experience developing Priority Intelligence Requirements (PIRs). * Strong experience working closely with SOC, Incident Response, Vulnerability Management, Security Engineering and Risk. * Experience managing the end-to-end intelligence lifecycle. * Significant Cyber Threat Intelligence (CTI) or closely related cyber security experience. * Strong experience analysing strategic, operational, and tactical threat intelligence. * Practical experience with MITRE ATT&CK, threat actor profiling, IOC analysis, threat hunting and intelligence-led detection engineering. * Evidence of leading/developing a CTI capability. * Relevant professional certification such as GCTI, CRTIA, CPTIA, GIAC, or CISSP is desirable., * Analytical Thinking (Solving) * Communication Skills (Key) * Curiosity (Personal Trait) * Intelligence Analysis (Level) * Leadership and Management (Certhe) * Mentoring Programs * Operating System Security * Research Skills (Evaluation) * Stakeholder Management (Business) * Team Management ## Description An exciting remote-based opportunity has arisen for a Threat Intelligence Lead to join our Technology team, reporting to the Chief Information Security Officer. You will design and lead the company's cyber threat intelligence (CTI), security testing and proactive threat-hunting programmes, helping to protect our customers, assets and brands across our global operations. Working closely with our internal and external security operations teams, you will anticipate, assess and mitigate threats. The intelligence you provide will support strategic decisions, incident response and continuous improvements to our cyber resilience. This pivotal Cyber Security role requires strong technical expertise, intelligence capability and commercial awareness within a regulated financial environment. What you will do as our Threat Intelligence Lead: This is an overview and not an exhaustive list of responsibilities. Collaborating with your Line Manager, you will develop your own objectives but focus on all of the following and more: * Lead the development of our CTI function, establishing clear governance, processes, intelligence priorities and measurable outcomes. * Represent the organisation in key external intelligence-sharing forums, including FS-ISAC, the NCSC's CiSP and relevant industry partnerships. * Use the MITRE ATT&CK framework to identify and analyse attacker tactics, techniques and procedures and strengthen our detection capabilities. * Develop the Proactive Threat Hunting Initiative, using intelligence and security tools to identify emerging threats, attack paths and vulnerabilities and security gaps. * Oversee the collection and analysis of tactical, operational and strategic threat intelligence, with a particular focus on threats affecting insurance and financial services sectors. * Proactively search for malicious activity, anomalies and emerging threats across enterprise networks, endpoints and cloud environments. * Provide clear, actionable intelligence and threat landscaping briefings to senior leaders, Board committees and key stakeholders across the business. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)