Our customers demand a first-class service which is safe and secure. To support this, our Security Operations team is currently looking for an ambitious and experienced Cyber Threat Intelligence professional.
You'll excel when working in fast paced environments where you are responsible for maintaining high standards of operational output. You'll also be an advocate of threat intelligence and be passionate about it having a positive impact on operations, driving the development of our CTI function to effectively meet business demand.
You'll take ownership for the production and dissemination of high quality intelligence products to meet customer requirements, alongside supporting the Security Operations team in Cyber Incident Response.
Working within our Cyber Security function, the Cyber Threat Intelligence (CTI) Consultant role will be a major part of day-to-day collection, analysis, and dissemination of threat intelligence across the organisation. This role is instrumental in contextualising threat intelligence into an actionable form and ensuring its relevance for appropriate stakeholders.
This is an opportunity, to work in a respected, and proven team where we must continue to develop personally, professionally, and collectively to remain successful. To that end, we focus heavily on skills development for the future and offer the opportunity of earning enhanced pay awards for particular skillsets.
We are happy to consider flexible working approaches to help you perform at your best.
At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected.
For this job you'll be located at our nearest regional hub. There will be a need to regularly connect with colleagues for collaboration events in one of our office sites. This is anticipated to be as and when needed in Swindon. If your application is successful, your hiring manager will provide further details on how this works. You can also find out more about our approach to hybrid working here .
If we receive a high volume of relevant applications, we may close the advert earlier than the advertised date, so please apply as soon as you can.
What you'll be doingYou'll have a strong understanding of the cyber threats facing large organisations, along with the technical mitigations appropriate to those threats. As well as this, you'll have a natural passion and curiosity for security and intelligence and be able to blend technical details with traditional intelligence tradecraft to produce concise, relevant, robust, and timely assessments, for technical and non-technical consumers.
You'll be responsible for co-ordinating and delivering tasks throughout the cyber threat intelligence lifecycle, including the collection of data from social media, dark web, news stories and vendors/partners to produce appropriate, refined, and robust intelligence products to answer customer requirements and provide actionable insights. You'll assist a team of junior analysts and have a passion for developing both operational processes and colleague skillsets.
Working as part of a multi-disciplinary team, you'll need to communicate your assessments to an audience across multiple levels and departments. We work closely with our peers in other organisations, as well as our vendors, and the role will also be central in managing and developing these relationships.
About you - Have a solid appreciation of cyber threats faced by large organisations, including the tools, techniques and procedures used by attackers and the mitigations appropriate to defeat them, often but not always, technical in nature.
- Have exceptional communication skills, both written and verbal, with confidence presenting and reporting to audiences of varying levels of technical expertise.
- Possess experience defining and influencing the direction of a threat intelligence. function, as well as handling and disseminating material when responding to tactical, operational, and strategic objectives.
- Comfortable partnering with detection engineering, SOC, and Incident Response SMEs to translate strategic intelligence into new detection content, alert tuning, and response playbook enhancements.
- Have a demonstrable systematic and analytical approach to problem solving with the ability to collect and review technical and non-technical data to produce high quality actionable products in response to intelligence requirements.
- Be comfortable working with industry standard cyber threat frameworks, analytical techniques, common cyber security tooling.
- Have experience working with or within a Cyber Security Operations Centre (SOC), and a good knowledge of security operations and incident response activities.
- Have experience either working within the Financial Services sector or with an established understanding of the threats faced by the Financial Sector.
- Have a passion for mentoring people and developing/upskilling more junior colleagues.
- Demonstrable experience capturing lessons learned from threat hunts and incident investigations, refining intelligence triage processes and sharing technical findings via detailed reports and workshops.
Our customer first behaviours put customers and members at the heart of how we work together. They are the set of behaviours that every colleague needs to display, in every role:
- Feel what customers feel - We step into our customers' shoes, using their feedback and insights to empathise with them and to understand their needs, so that every decision we make starts and finishes with our customers in mind
- Say it straight - We are brave in speaking out and saying what we think - we're honest and direct with good intent, openly sharing diverse perspectives to reach the best conclusions and using language everyone can understand
- Push for better - We don't settle for mediocrity, we challenge the status quo, taking responsibility for continuous improvement and personal development
- Get it done - We prioritise what will have the greatest impact, we are decisive, and we take accountability for delivering brilliant customer outcomes.
You can strengthen your application by showing how our customer first behaviours resonate with you, and where you may have already demonstrated these.
The extras you'll getThere are all sorts of employee benefits available at Nationwide, including:
- A personal pension - if you put in 7% of your salary, we'll top up by a further 16%
- Up to 2 days of paid volunteering a year
- Life assurance worth 8x your salary
- A great selection of additional benefits through our salary sacrifice scheme
- Wellhub - Access to a range of free and paid options for health and wellness
- Access to an annual performance related bonus
- Access to training to help you develop and progress your career
- 25 days holiday, pro rata
Banking - but fairer, more rewarding, and for the good of societyWe forge our own path at Nationwide.
As a mutual, we're owned by our members - those customers who bank, save or have a mortgage with us. We challenge the financial sector status quo. We don't see customers as the engine of our own profit. We share our profits with them and put their needs first. Always there when they need us. Supporting them and their lives.
If you're inspired by fairer finances, passionate about making a meaningful impact, and truly care about our customers, you're one of us.
At Nationwide, you are challenged to grow and rewarded for doing so. Valued. Recognised. Inspired to be your best. As a community we want our working lives to count. As a team, we celebrate what we achieve. As a standard-setter, we work for the good of customers, communities, and broader society.
We are Purpose-driven. Uncompromisingly Customer. Unstoppably Nationwide.
What to do nextIf this role is for you, please click the 'Apply Now' button. You'll need to attach your up-to-date CV and answer a few quick questions for us.
We respond to everyone, so we will be in contact shortly after the closing date to let you know the outcome of your application.
#LI-POST