Skip to main content
AfterDuty

Cyber Threat Intelligence (CTI) Lead - Senior Manager

Lloyds Banking Group · Edinburgh, Scotland

Salary
£107,304 – £138,864Estimated
Type
Full-time
Posted
Yesterday

Overview

Your experience running intelligence operations in policing—managing the National Intelligence Model, producing analytical products, and making threat assessments under uncertainty—maps directly onto this role's core requirements. You already know how to set intelligence requirements, lead a team of analysts, and communicate complex findings to senior decision-makers, which is exactly what Lloyds needs to embed threat intelligence into their security operations.

About this role

End Date

Tuesday 18 August 2026

£92,701 - £109,060

We support flexible working – click here for more information on flexible working options

Flexible Working Options

Hybrid Working, Job Share

Job Description Summary

A senior leader or principal specialist who translates strategy into effective security capabilities.

Shapes policy, operating models and priorities, and provides leadership across multiple security disciplines or teams.

Job Description

JOB TITLE: Cyber Threat Intelligence Senior Manager

London: £107,304-£138,864

*HOURS:*Full-time

*WORKING PATTERN:*Our work style is hybrid, which involves spending at least two days per week, or 40% of our time, at one of our office sites

About this opportunity

This is a pivotal moment to join Lloyds Banking Group and the Chief Security Office as we transform how security is delivered across the Group.

As the Cyber Threat Intelligence Lead, you’ll lead a specialised intelligence team responsible for identifying, analysing, and producing actionable intelligence on significant cyber threats. You will play a critical role in ensuring intelligence is embedded in security systems and controls, and our cyber defence teams are threat-led to protect the UK's largest digital bank.

What you’ll be doing

  • Significant Cyber Threat Intelligence experience, with strong knowledge of adversaries, campaigns and intelligence-led cyber defence.
  • Experience setting direction and leading high-performing, specialist teams in a complex organisation.
  • Deep knowledge of intelligence tradecraft, including intelligence requirements, structured analysis and the clear assessment of uncertainty.
  • The technical credibility to drive the embedding of threat intelligence into security operations and control systems.
  • The capability to drive operational excellence in the collection and analysis of threat intelligence through the usage of leading CTI and AI tooling.
  • A record of turning complex intelligence into practical recommendations and measurable outcomes.
  • The ability to influence senior leaders and communicate clearly with technical and non-technical audiences.
  • An inclusive and improvement-focused leadership style that develops people and challenges established thinking.
  • Formal intelligence training or qualifications would be useful, but they are not essential. We also welcome candidates who have developed strong intelligence tradecraft through relevant professional experience.

Why join us?

We’re transforming at pace. Investing billions in our people, data and tech to change the way we meet the needs of our 28 million customers. We’re growing, and we’d love you to be part of the journey.

This is a place for you

Our ambition is to be the leading UK business for diversity, equity and inclusion supporting our customers, colleagues and communities and we’re committed to creating an environment in which everyone can thrive, learn and develop.

We also offer a wide-ranging benefits package, which includes

  • A generous pension contribution of up to 15%
  • An annual performance-related bonus
  • Share schemes including free shares
  • Benefits you can adapt to your lifestyle, such as discounted shopping
  • 30 days’ holiday, with bank holidays on top
  • A range of wellbeing initiatives and generous parental leave policies

Ready for a career where you’ll learn and thrive? Apply today and find out more.

At Lloyds Banking Group, we're driven by a clear purpose; to help Britain prosper. Across the Group, our colleagues are focused on making a difference to customers, businesses and communities. With us you'll have a key role to play in shaping the financial services of the future, whilst the scale and reach of our Group means you'll have many opportunities to learn, grow and develop.

We keep your data safe. So, we'll only ever ask you to provide confidential or sensitive information once you have formally been invited along to an interview or accepted a verbal offer to join us which is when we run our background checks. We'll always explain what we need and why, with any request coming from a trusted Lloyds Banking Group person.

We're focused on creating a values-led culture and are committed to building a workforce which reflects the diversity of the customers and communities we serve. Together we’re building a truly inclusive workplace where all of our colleagues have the opportunity to make a real difference.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Edinburgh

Why this fits a police background — match score 75/100

  • Intelligence & OSINT
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Threat Analyst

    SCC · Birmingham

    Full-time

    Your background in intelligence analysis and threat assessment from policing maps directly to producing structured threat intelligence deliverables. You are used to researching hostile actors, evaluating sources, and writing concise briefings for different audiences, which is exactly what this role demands. Your incident response experience and disciplined approach to evidence and reporting would let you contribute from day one, while any gaps in specific tooling can be trained.

    Posted Today

  • Cyber Incident Responder

    CYFOR · Manchester

    Full-time

    £40,000 – £50,000Estimated

    Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

    Posted Yesterday

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday