Skip to main content
AfterDuty

Attack Monitoring Analyst (GSOC)

LSEG (London Stock Exchange Group) · London, Greater London

Type
Full-time
Posted
2 days ago

Overview

Your experience managing high-pressure incidents and following strict protocols translates to the structured incident response required here. Your investigative mindset and attention to detail will help in triaging security events and root-cause analysis, but the role demands deep technical expertise in SIEM, networks, and programming that most policing roles do not provide, so significant retraining would be necessary.

About this role

ROLE PROFILE

The London Stock Exchange Group seeks an experienced, dedicated and driven Attack Monitoring Analyst to join the Global Security Operations team!

ROLE SUMMARY

LSEG Security Operations is a central function employing people, process and technology to continuously monitor and respond to cyber security incidents.

This role is for an Attack Monitoring Analyst for the Global Security Operations Centre (GSOC). The role is responsible for identifying and responding to cyber security incidents and improving the defensive capabilities of the GSOC.

The ideal candidate will have a solid technical background, with a firm understanding of modern attack techniques coupled with knowledge of the typical lifecycle of an attack.

SHIFT

Role operates on a "follow-the-sun" shift rotation. Shifts are 1200hrs - 0000hrs (midday to midnight) London Time using a 4 days on, 4 days off rotation.

RESPONSIBILITIES

• Triage security events and employ a methodical and coherent response to security incidents adopting playbooks where necessary.

• Competently operate a chosen SIEM (e.g. Splunk/QRadar/LogRhythm) for incident investigations, or for the development of monitoring dashboards.

• Utilise playbooks, existing knowledge and accurate online resources for guidance when responding to incidents.

• Utilise online resources for researching and collecting threat intelligence to improve the SOC’s abilities to detect cyber-attacks.

• Develop new, or improve existing run books and use cases based on investigations and knowledge of modern attacks.

• Stay up to date with current vulnerabilities, attacks, and countermeasures.

• Identify, respond and remediate cyber events generated through monitoring technologies.

EXPERIENCE

• Preferred experience with operating or administrating a SIEM (e.g. Splunk/QRadar/LogRhythm).

• Solid understanding of networks including the TCP/IP stack, typical organisation architectures, and common protocols abused by malware.

• Experience in security event analysis & triage, incident handling and root-cause identification.

• Understanding of tools, techniques and procedures that attackers use to compromise organisations, ideally from direct experience.

• Knowledge of cyber security either academically or within corporate environments.

• Ability to work in a fast-paced and demanding environment while remaining calm.

• Strong verbal and written communication and collaboration skills.

• Security industry specific and core technical accreditations such as OSCP, GIAC, CCNA.

• Certification demonstrating SIEM operational competences.

• Proficient with one or more programming languages (e.g. Python, PowerShell, Java, C#).

Career Stage

Associate

London Stock Exchange Group (LSEG) Information

Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.

LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.

Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, *Excellence*and *Change*underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.

Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.

We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone’s race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.

You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.

LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.

Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it’s used for, and how it’s obtained, your rights and how to contact us as a data subject .

If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Intelligence & OSINT
  • Investigative casework
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday

  • Privacy Operations Manager

    Thomson Reuters · London

    Full-time

    Your experience managing sensitive information under strict legal frameworks like PACE, RIPA, and CPIA gives you a strong foundation for privacy compliance and data protection. The incident command and risk assessment skills you developed in policing translate directly to coordinating cyber incident response and conducting privacy impact assessments. Your ability to lead operational teams and work across agencies prepares you to embed privacy-by-design principles and manage global privacy operations.

    Posted 2 days ago

  • Your experience managing complex incidents, assessing threats, and coordinating multi-agency responses in policing directly prepares you for leading cyber security engagements and advising clients on risk and resilience. The role's focus on stakeholder management, conducting assessments, and developing security strategies mirrors the analytical and command skills you've honed, and your security clearance eligibility is a strong asset in this defence and security consultancy.

    Posted 5 days ago