Cyber Threat Intelligence Analyst

LLOYDS BANKING GROUP

Bristol

On-site

GBP 49,000 - 54,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working
Generous pension (up to 15%)
Annual performance bonus
Share schemes
28 days of holiday + bank holidays

Job summary

Lloyds Banking Group is seeking a Cyber Threat Intelligence Analyst to monitor threat actors, analyse campaigns, and support cyber defence operations. The role involves contributing to intelligence workflows and tooling to improve speed, quality and scalability of CTI operations.

The position offers hybrid working between Edinburgh or Bristol, with a strong emphasis on developing AI-assisted analysis capabilities and threat-actor tracking.

Qualifications

  • Understanding of cyber threat intelligence concepts and lifecycle.
  • Experience evaluating threat campaigns and adversary TTPs.
  • Ability to document findings clearly for operational use.

Responsibilities

  • Conduct intelligence collection, monitor infrastructure, and analyse threat actors.
  • Investigate campaigns and provide actionable intelligence to support cyber defence.
  • Advance automated intelligence workflows and AI-assisted analysis capabilities.

Skills

Cyber threat intelligence
Threat actor monitoring
Threat analysis
OSINT techniques
APIs & automation
Data enrichment pipelines
CTI workflows
Analytical thinking

Tools

CTI platforms
Graph databases
Knowledge graphs
STIX/TAXII
API integration

Job description

Posted date

Posted Today

Job ID

161510

We’re rebooting an icon and building the future of finance.

Find out why you should join us.

Agile Working Options

Job Share; Hybrid Working

Job description
JOB TITLE:

Cyber Threat Intelligence Analyst

SALARY:

£48,987 - £54,430

LOCATION(S):

Edinburgh or Bristol

HOURS:

Full-time

WORKING PATTERN

Our work style is hybrid, which involves spending at least two days per week, or 40% of our time, at one of our office sites. Colleagues with disabilities can be supported with workplace adjustments including hybrid working expectations in line with our Flexibility Works policy.

What you’ll be doing

In this role you’ll be conducting intelligence collection, monitoring infrastructure, analysing threat actors, and investigating campaigns. These activities help pinpoint threats relevant to the Group and assist in making timely operational decisions.

Alongside core intelligence responsibilities, you will help advance automated intelligence workflows, AI-assisted analysis capabilities, and intelligence tooling that boost the speed, quality, and scalability of CTI operations.

The role provides the chance to build expertise in threat actor tracking, infrastructure analysis, CTI platforms, automation, AI, and intelligence engineering while directly supporting cyber defence operations.

Why join us?

We’re investing billions in our people, places and tech to change the way we meet the needs of our 28 million customers. We’re growing, and we’d love you to be part of the journey.

What we’re looking for?
  • Understanding of cyber threat intelligence concepts, threat actor monitoring, campaign evaluation, intelligence lifecycle oversight, and intelligence documentation.
  • Strong technical curiosity and desire to continuously learn new technologies and analytical approaches.
  • Experience examining threat infrastructure, indicators of compromise, adversary TTPs, phishing activity, malware campaigns, or cyber criminal ecosystems.
  • Strong analytical approach with the ability to assess technical threat information and communicate findings clearly.
  • Understanding of APIs, data enrichment pipelines, workflow automation, and intelligence data management.
  • Experience applying OSINT techniques as part of structured intelligence collection and analysis activities to develop actionable intelligence on threat actors, infrastructure, data breaches, and emerging threats.
And any experience of these would be great
  • Knowledge of MITRE ATT&CK, Diamond Model, Cyber Kill Chain, STIX/TAXII, and structured analytic techniques.
  • Experience building enrichment or collection workflows using APIs.
  • Experience using graph databases, knowledge graphs, or relationship analysis platforms.
  • Understanding of cloud-hosted infrastructure, adversary infrastructure abuse, and cybercrime ecosystem monitoring.

We know that great talent comes from many backgrounds. Whilst this job advert may reference specific years of experience, we recognise that skills are developed in many ways, so if you have relevant, transferable experience, we encourage you to apply.

This is a place for you:

Our ambition is to be the leading UK business for diversity, equity and inclusion supporting our customers, colleagues and communities, and we’re committed to creating an environment in which everyone can thrive, learn and develop.

We were one of the first major organisations to set goals on diversity in senior roles, create a menopause health package, and a dedicated Working with Cancer Initiative.

We offer reasonable workplace adjustments for colleagues with disabilities, including flexibility in office attendance, location and working patterns. And, as a Disability Confident Leader, we guarantee interviews for a fair and proportionate number of applicants who meet the minimum criteria for the role with a disability, long-term health or neurodivergent condition through the Disability Confident Scheme.

We provide reasonable adjustments throughout the recruitment process to reduce or remove barriers. Just let us know what you need.

We also offer a wide-ranging benefits package, which includes:

  • A generous pension contribution of up to 15%
  • An annual performance-related bonus
  • Share schemes including free shares
  • Benefits you can adapt to your lifestyle, such as discounted shopping
  • 28 days’ holiday, with bank holidays on top
  • A range of wellbeing initiatives and generous parental leave policies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

LLOYDS BANKING GROUP • City of Edinburgh

Hybrid
GBP 49,000 - 54,000
Pension up to 15%
Annual bonus
Share schemes
+3
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Lloyds Banking Group • West of England

Hybrid
GBP 49,000 - 54,000
15% pension contribution
Annual bonus (performance-related)
Share schemes including free shares
+4
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Lloyds Bank plc • Bristol

Hybrid
GBP 49,000 - 54,000
Flexible Working Options
Hybrid Working
Job Share
Cyber Threat Intelligence (CTI) Lead - Senior Manager
Cyber Threat Intelligence (CTI) Lead - Senior Manager

LLOYDS BANKING GROUP • Manchester

Hybrid
GBP 93,000 - 120,000
Pension up to 15%
Performance bonus
Share schemes
+3
Cyber Threat Intelligence (CTI) Lead - Senior Manager
Cyber Threat Intelligence (CTI) Lead - Senior Manager

LLOYDS BANKING GROUP • City of Edinburgh

On-site
GBP 93,000 - 139,000
Hybrid working
Job Share
Annual performance bonus
+2
Cyber Threat Intelligence (CTI) Lead - Senior Manager
Cyber Threat Intelligence (CTI) Lead - Senior Manager

LLOYDS BANKING GROUP • Greater London

Hybrid
GBP 93,000 - 139,000
Pension up to 15%
Annual bonus
Share schemes
+3
Cyber Threat Intelligence (CTI) Lead - Senior Manager
Cyber Threat Intelligence (CTI) Lead - Senior Manager

LLOYDS BANKING GROUP • Bristol

Hybrid
GBP 93,000 - 139,000
Pension up to 15%
Annual bonus
Share schemes
+3
Cyber Threat Intelligence (CTI) Lead - Senior Manager | Edinburgh, UK
Cyber Threat Intelligence (CTI) Lead - Senior Manager | Edinburgh, UK

Lloyds Bank plc • City of Edinburgh

Hybrid
GBP 93,000 - 109,000
Pension up to 15%
Annual bonus
Share schemes
+4
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Cyber UK • City of Edinburgh

On-site
GBP 55,000 - 75,000
40 days annual leave
16% employer pension contribution
Private healthcare
+1
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Lloyds • West of England

On-site
GBP 65,000 - 90,000
Holiday allowance
Flexible working
Family leave
+6