Senior Response Manager – Home Office Cyber Security Threat Intelligence

Company: United Kingdom Government
Apply for the Senior Response Manager – Home Office Cyber Security Threat Intelligence
Location: Salford
Job Description:

Overview

As a Senior Response Manager in Cyber Threat Intelligence, you will lead intelligence-driven threat analysis and incident response efforts to reduce risk across Home Office digital services. You will join a specialist team to mature threat intel capabilities, guide complex responses, and drive strategic initiatives that strengthen defences against evolving threats. You collaborate with cross-functional stakeholders to translate insights into concrete security improvements. This role offers impactful work at scale within a supportive, development-focused culture.

Pay / Benefits

  • Civil Service Pension with employer contribution
  • 25 days annual leave plus holidays
  • 8 public holidays plus an additional privilege day
  • Hybrid working options (minimum 60% in office)

Responsibilities

  • Conduct threat intelligence activities following defined SOPs
  • Advise on mitigations and escalate to team lead when needed
  • Facilitate incident response exercises including red teaming and threat-hunting
  • Communicate investigation findings and risk mitigations to diverse audiences
  • Perform post-incident reviews to capture lessons
  • Identify and classify threats, adversary TTPs, and vulnerabilities; assess and mitigate impact
  • Prioritise vulnerabilities using risk-based approaches and support vulnerability management
  • Define intelligence requirements and tools for threat identification and assessment
  • Share mitigations and threat trends; seek service/process improvements across security operations

Key requirements

  • Threat intelligence analysis, collection and investigations in a SOC environment
  • Ability to communicate complex threat intel to technical and non-technical audiences
  • Experience with threat analysis models/frameworks (STIX, MITRE ATT&CK, Cyber Kill Chain, Diamond Model)
  • Strong partnership and stakeholder engagement across technical teams and suppliers
  • Experience leading or managing a team in a technical environment
  • Proficiency with SIEM and Threat Intelligence Platforms (TIPs)
  • Knowledge of cyber security risk and control frameworks (NIST, ISO27001, Cyber Essentials, NCSC)
  • Strong communication and influencing abilities
  • Collaborative mindset and cross-functional teamwork
  • Problem-solving and sound judgment
  • SIEM
  • Threat Intelligence Platforms (TIPs)
  • Threat modeling and risk assessment

Posted: September 20th, 2026