What The Role Is
The job holder will support the Deputy Director (Technical Operations) in leading and developing Cyber Threat Intelligence (CTI) capabilities for the Ministry of Home Affairs (MHA) and the Home Team Science and Technology Agency (HTX). This role is responsible for building and leading a specialised cyber threat intelligence team to provide timely, actionable intelligence and risk assessments that support strategic decision‑making during both peacetime and crisis situations. The role contributes directly to strengthening the protection, resilience, and security posture of MHA’s digital systems and networks.
What You Will Be Working On
- Lead and develop a high performing cyber threat intelligence team with deep technical expertise in threat intelligence, threat modelling, and adversary analysis.
- Establish and enhance cyber threat intelligence frameworks, methodologies, and threat management models to assess and communicate security risks to senior management.
- Provide strategic cyber threat intelligence and informed impact assessments to support HTX and Home Team Departments (HTDs) in decision making related to attack surfaces and threat exposure.
- Serve as a subject matter expert in cyber threat intelligence during crisis situations, providing timely and credible intelligence to support operational and strategic responses.
- Deliver early warning and detection of emerging cyber threats, including sector specific and nation state threats relevant to MHA and HTX.
- Produce timely threat analysis, intelligence assessments, and briefings for senior leadership.
- Work closely with HTDs, internal stakeholders, and senior management to provide sense making of the overall cybersecurity posture across MHA systems.
- Collaborate with wider Government agencies, industry partners, and strategic counterparts on cyber threat intelligence sharing and joint analysis efforts.
- Contribute to whole of government cybersecurity intelligence initiatives and cross sector threat assessments.
What We Are Looking For
- Degree in Computer Science, Information Technology, or related Engineering discipline; GCTI is preferred, and other relevant certifications, including ENCE, GCFA, GCIA, GREM, and GNFA, will also be taken into consideration.
- At least 8 years of relevant experience in Cyber Threat Intelligence (CTIH), Digital Forensics and Incident Response (DFIR), and/or SOC environments, including 5 years of hands‑on CTIH/DFIR experience.
- Strong technical leadership in cyber investigations, threat intelligence, and incident response.
- Knowledge of cyber kill chain processes, MITRE ATT&CK framework, and cybersecurity incident management.
- Proven ability to drive strategic capability development and communicate complex intelligence to senior stakeholders.
- High integrity, resilience, strong leadership and communication skills, with a positive and learning oriented mindset.