Get more replies from employers
Send a job-specific resume in minutes.
Lloyds Banking Group in Bristol is seeking a Cyber Threat Intelligence Analyst to join our security team, focusing on intelligence collection, threat monitoring and analysis to protect our networks.
The role emphasizes developing automated workflows, AI-assisted analysis, and integration with CTI platforms while offering a flexible hybrid work pattern and opportunities to grow in threat actor tracking, infrastructure analysis and intelligence engineering.
End Date Friday 21 August 2026
Salary Range £48,987 - £54,430
We support flexible working – Flexible Working Options Hybrid Working, Job Share
Job Description
JOB TITLE: Cyber Threat Intelligence Analyst
SALARY: £48,987 - £54,430
LOCATION(S): Edinburgh or Bristol
HOURS: Full-time
WORKING PATTERN: Our work style is hybrid, which involves spending at least two days per week, or 40% of our time, at one of our office sites. Colleagues with disabilities can be supported with workplace adjustments including hybrid working expectations in line with our Flexibility Works policy.
In this role you’ll be conducting intelligence collection, monitoring infrastructure, analysing threat actors, and investigating campaigns. These activities help pinpoint threats relevant to the Group and assist in making timely operational decisions. Alongside core intelligence responsibilities, you will help advance automated intelligence workflows, AI-assisted analysis capabilities, and intelligence tooling that boost the speed, quality, and scalability of CTI operations. The role provides the chance to build expertise in threat actor tracking, infrastructure analysis, CTI platforms, automation, AI, and intelligence engineering while directly supporting cyber defence operations.
We’re investing billions in our people, places and tech to change the way we meet the needs of our 28 million customers. We’re growing, and we’d love you to be part of the journey.
Understanding of cyber threat intelligence concepts, threat actor monitoring, campaign evaluation, intelligence lifecycle oversight, and intelligence documentation. Strong technical curiosity and desire to continuously learn new technologies and analytical approaches. Experience examining threat infrastructure, indicators of compromise, adversary TTPs, phishing activity, malware campaigns, or cyber criminal ecosystems. Strong analytical approach with the ability to assess technical threat information and communicate findings clearly. Understanding of APIs, data enrichment pipelines, workflow automation, and intelligence data management. Experience applying OSINT techniques as part of structured intelligence collection and analysis activities to develop actionable intelligence on threat actors, infrastructure, data breaches, and emerging threats. And any experience of these would be great Knowledge of MITRE ATT&CK, Diamond Model, Cyber Kill Chain, STIX/TAXII, and structured analytic techniques. Experience building enrichment or collection workflows using APIs. Experience using graph databases, knowledge graphs, or relationship analysis platforms. Understanding of cloud-hosted infrastructure, adversary infrastructure abuse, and cybercrime ecosystem monitoring.
We know that great talent comes from many backgrounds. Whilst this job advert may reference specific years of experience, we recognise that skills are developed in many ways, so if you have relevant, transferable experience, we encourage you to apply. This is a place for you: Our ambition is to be the leading UK business for diversity, equity and inclusion supporting our customers, colleagues and communities, and we’re committed to creating an environment in which everyone can thrive, learn and develop.
We were one of the first major organisations to set goals on diversity in senior roles, create a menopause health package, and a dedicated Working with Cancer Initiative. We offer reasonable workplace adjustments for colleagues with disabilities, including flexibility in office attendance, location and working patterns. And, as a Disability Confident Leader, we guarantee interviews for a fair and proportionate number of applicants who meet the minimum criteria for the role with a disability, long-term health or neurodivergent condition through the Disability Confident Scheme. We provide reasonable adjustments throughout the recruitment process to reduce or remove barriers. Just let us know what you need.
We also offer a wide-ranging benefits package, which includes:
We keep your data safe. So, we’ll only ever ask you to provide confidential or sensitive information once you have formally been invited along to an interview or accepted a verbal offer to join us which is when we run our background checks. We’ll always explain what we need and why, with any request coming from a trusted Lloyds Banking Group person.
We’re focused on creating a values-led culture and are committed to building a workforce which reflects the diversity of the customers and communities we serve. Together we’re building a truly inclusive workplace where all of our colleagues have the opportunity to make a real difference.