At a Glance
- Tasks: Lead the Threat Intelligence team to enhance NHS cyber resilience and protect patient data.
- Company: Join NHS England, a leader in healthcare innovation and cyber security.
- Benefits: Enjoy competitive pay, additional RRP, and opportunities for professional growth.
- Why this job: Make a real difference in healthcare by safeguarding vital information and systems.
- Qualifications: Experience in cyber security and threat intelligence is essential.
- Other info: Dynamic role with potential for career advancement in a supportive environment.
The predicted salary is between 48000 - 72000 £ per year.
Overview
Cyber Operations purpose is to support safe care and build public trust by building NHS England’s cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate’s purpose of delivering the best care and outcomes for the NHS.
The Cyber Operations sub-directorate consists of 4 operational areas:
- Cyber Security Operations Unit (CSOU)
- Cyber Delivery Unit (CDU).
- Cyber Improvement Programme.
- Chief Information Security Office Function (CISO)
The role leads the CSOCs Threat Intelligence team within NHS England CSOC comprised of four primary functions:
- Intelligence Collection & Analysis – Perform collection, aggregation, analysis and contextualisation of healthcare and security information to produce actionable CTI.
- Cybersecurity Threat & Risk Assessment – Perform high-level risk assessments of current and emerging threats to the health & social care estate.
- Intelligence Dissemination & Reporting – Produce stakeholder-specific intelligence reporting for stakeholders.
- Specialist CTI Support – Provides specialist CTI support to CSOC during high complexity incidents.
The post of Cyber Security Lead Analyst – Threat Intelligence has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 30% per annum.
Please be aware that RRP is none contractual and subject to review.
As a Cyber Security Lead Analyst (Threat Intelligence) you will:
- Ensure the objectives and activities of the Threat Intelligence teams and Assessments are aligned with overarching CSOC strategy.
- Represent the function at operational and managerial meetings, including regularly reporting to senior leadership.
- Acts as an escalation point for national cyber threat advisories (NHS High Severity Alerts).
- Acting as an escalation point for technical, operational and strategic threat intelligence queries.
- Be responsible for the management and production of Key Performance Indicators (KPI) for the function.
- Manage the resource allocation and workload across the function, including developing innovative solutions to improve quality and efficiency.
- Manage the relationships and process integration between the Threat Intelligence and Threat Hunting teams.
- Drive continuous improvement initiatives for the function, for the benefit of the wider CSOC.
Our work supports the NHS to deliver high quality services for patients and best value for taxpayers.
Our staff bring expertise across hundreds of specialisms — including clinical, operational, commissioning, technology, data science, cyber security, software engineering, education, and commercial — enabling us to design and deliver high-quality NHS services.
We lead the NHS in England by:
- Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities
- Making the NHS a great place to work, where our people can make a difference and achieve their potential
- Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care
- Optimising the use of digital technology, research, and innovation
- Delivering value for money
Earlier this year, the Government announced that NHS England will gradually merge with the Department of Health and Social Care, leading to full integration. The aim is to create a smaller, more strategic centre that reduces duplication and eliminates waste.
If successful at interview, we will initiate an Inter Authority Transfer (IAT) via the Electronic Staff Record (ESR). This retrieves key data from your current or previous NHS employer to support onboarding, including competency status, Continuous Service Dates (CSD), and annual leave entitlement. You may opt out at any stage of the recruitment process.
Please see the attached Job Description and Person Specification for more information about the role and responsibilities.
Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes
Important: Please be aware there are residency requirements you need to meet:
All NHS England Cyber Security personnel must hold Security Clearance level as a minimum. To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role – will still be considered.
Please make sure you meet these requirements before applying for this role. You don’t need to have SC already, however, failure to achieve the requirements for SC after offer will result in the job offer being withdrawn. For further advice please check
https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc
Please be aware that should you be successful in this position, you will be hired to the job title of Security Lead (Analyst) and this job title is advertised to attract the right skills needed for the role.
Secondment
Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
Please note that the reason for the fixed term of this contract isshort term vacancy
This advert closes on Sunday 2 Nov 2025
#J-18808-Ljbffr
Cyber Security Lead - Threat Intelligence | NHS England employer: NHS England
Contact Detail:
NHS England Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Lead - Threat Intelligence | NHS England
✨Tip Number 1
Network like a pro! Get out there and connect with people in the cyber security field. Attend industry events, join online forums, and don’t be shy about reaching out to professionals on LinkedIn. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Prepare for those interviews! Research NHS England’s cyber operations and think about how your skills align with their mission. Practice common interview questions and come up with examples that showcase your experience in threat intelligence and risk assessment.
✨Tip Number 3
Show your passion for cyber security! During interviews, let your enthusiasm shine through. Talk about recent trends in cyber threats and how you stay updated. This will demonstrate your commitment to the field and make you stand out as a candidate.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the NHS England team and contributing to their mission of improving healthcare through cyber resilience.
We think you need these skills to ace Cyber Security Lead - Threat Intelligence | NHS England
Some tips for your application 🫡
Tailor Your Supporting Statement: Make sure to customise your supporting statement to highlight how your skills and experiences align with the key criteria mentioned in the job description. Use specific examples to demonstrate your expertise in cyber security and threat intelligence.
Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements! Quantify your successes where possible, like improvements in cyber resilience or successful threat assessments. This will help us see the impact you've made in previous roles.
Be Clear and Concise: Keep your application clear and to the point. Avoid jargon unless it’s relevant to the role. We want to understand your qualifications without wading through unnecessary fluff. Clarity is key!
Apply Through Our Website: Remember to apply through our website for a smoother process. It’s the best way to ensure your application gets to us directly and is considered promptly. We can’t wait to see what you bring to the table!
How to prepare for a job interview at NHS England
✨Know Your Cyber Security Stuff
Make sure you brush up on the latest trends and threats in cyber security, especially those relevant to the healthcare sector. Be ready to discuss specific examples of how you've handled threat intelligence or risk assessments in the past.
✨Align with NHS Values
Familiarise yourself with NHS England's mission and values. During the interview, demonstrate how your personal values align with theirs, particularly around delivering high-quality services and improving patient care.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your problem-solving skills in high-pressure situations. Think of examples where you've successfully managed a cyber incident or led a team through a complex challenge.
✨Showcase Your Leadership Skills
As a Cyber Security Lead, you'll need to demonstrate strong leadership abilities. Prepare to discuss your experience in managing teams, resource allocation, and driving continuous improvement initiatives within a cyber security context.