Hiscox
Cyber Threat Intelligence Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Build a brilliant future with Hiscox
Position: Cyber Threat Intelligence Lead
Reporting to: Head of Cyber Fusion
Type: Permanent
Band: II
Company Description
Hiscox is a diversified international insurance group with a powerful brand, strong balance sheet and plenty of room to grow. Listed on the London Stock Exchange and headquartered in Bermuda (with the bulk of group leadership sitting in London), Hiscox has over 3,000 staff across 14 countries and 34 offices.
Structured by geography and product, Hiscox’s long-held business strategy has helped them grow from a niche Lloyd’s underwriter to an international insurance group with a powerful and trusted consumer brand. Hiscox is comprised of the following business units:
- London Market
- Reinsurance & Insurance Linked Securities (ILS)
- Hiscox Retail USA
- Hiscox Retail UK
- Hiscox Retail Europe
For the financial year 2024, GWP grew to $4,766.9m with net premiums earned of $3,675.6m, returning a record pre-tax profit of £685.4M.
At Hiscox, our corporate values are considered crucial to our success. They are:
- Courage: dare to take a risk
- Human: clear, fair, and inclusive
- Ownership: passionate, commercial, and accountable
- Integrity: do the right thing, however hard
- Connected: together, build something better
The Role
The Cyber Threat Intelligence Lead is responsible for leading and maturing the organisation’s threat intelligence capability and ensuring intelligence drives security strategy, investment decisions and operational priorities across the business. Acting as the senior subject matter expert for cyber threats, the role holder will deliver strategic, operational and tactical intelligence products, provide leadership across the Cyber Fusion Centre and influence senior stakeholders across Technology and the wider business.
The role holder will contribute directly to the development and maintenance of the cyber security strategy, ensuring it remains aligned to the evolving threat landscape. They will work closely with the Head of Cyber Fusion and Chief Resilience and Security Officer to identify emerging threats, assess organisational exposure and recommend strategic improvements.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
You will play a pivotal role in defending our business from cyber threats. By continuously monitoring, analysing and actioning intelligence, you will be on the front line of protecting our business assets and interests from harm.
The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary.
Key Responsibilities
- Cyber Threat Intelligence
- Lead the end-to-end threat intelligence lifecycle and maintain intelligence requirements aligned to business objectives.
- Develop and maintain strategic, operational and tactical threat intelligence products.
- Provide regular threat briefings and intelligence updates to senior leadership and executive stakeholders.
- Contribute directly to the development and evolution of the Cyber Security Strategy.
- Act as the principal cyber threat intelligence advisor to the Head of Cyber Fusion and Chief Resilience and Security Officer.
- Develop threat-led action plans and influence remediation priorities across Technology and business functions.
- Embed a threat-led approach across vulnerability management, detection engineering, threat hunting, security architecture and incident response activities.
- Assess emerging threats, adversary activity, geopolitical developments and industry trends relevant to Hiscox.
- Develop and maintain intelligence sources, including OSINT, commercial intelligence feeds, industry partnerships and government engagement.
- Support major incident response activities through threat analysis, attribution assessments and remediation guidance.
- Build relationships with external intelligence sharing communities, government agencies and industry bodies.
- Present complex intelligence findings clearly to both technical and non-technical audiences.
- Drive understanding of the threat landscape across Technology Leadership and key business stakeholders.
- Coach and develop junior threat intelligence analysts and support future team growth.
- Establish threat intelligence methodologies, standards and quality controls.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Candidate Profile
Essential experience
- Experienced in cyber threat intelligence, cyber security operations, government intelligence, military intelligence or law enforcement environments.
- Strong understanding of the intelligence lifecycle and threat intelligence frameworks.
- Experience producing strategic intelligence assessments and executive-level briefings.
- Experience influencing senior stakeholders and driving security improvements through intelligence-led recommendations.
- Excellent analytical, research and critical thinking skills.
- Strong knowledge of threat actor tactics, techniques and procedures (TTPs).
- Experience mentoring or developing junior analysts.
- Excellent communication, presentation and stakeholder management skills.
- Experience within financial services or other regulated industries is desirable.
- Industry recognised certifications such as GCTI, CCTIM, GCFA, GREM, GPEN or equivalent are desirable.
Desirable experience
- Threat-intelligence-led detection and IOC operationalisation.
Diversity and flexible working at Hiscox
At Hiscox we care about our people. We hire the best people for the job, and we are committed to diversity and creating a truly inclusive culture, which we believe drives success.
Working life does not always have to be in the office so we have introduced hybrid working to encourage a healthy work life balance.
This hybrid working model is set by the team rather than the business to enable you to manage your own personal work-life balance. We see it as the best of both worlds; structure and sociability on one hand, and independence and flexibility on the other.
#LI-JC1 #LI-Hybrid
Work with amazing people and be part of a unique culture
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location