Skip to main content
AfterDuty

Cyber Security Analyst

CCL Global · London, Greater London

Type
Full-time
Posted
21 days ago

Overview

Your analytical mindset and incident response discipline from policing transfer to cyber threat investigation.

About this role

Job Description

Cyber Security Analyst

London / Hybrid

CCL Global are currently working with a leading public sector organisation who are seeking an experienced Associate Security Analyst for a contract opportunity. The successful applicant will join the organisation’s Cyber Defence team, supporting the investigation and response to cyber security threats and incidents across a large-scale digital environment.

Contract: Inside IR35 (umbrella)

Key duties will include

  • Triaging and investigating cyber security alerts and incidents.
  • Analysing systems, files, network traffic and cloud environments to understand potential cyber incidents.
  • Supporting the technical response to incidents, including containment, eradication and recovery.
  • Using SIEM and EDR security tools to investigate and respond to threats.
  • Supporting the coordination of cyber security incidents and contributing to post-incident reviews.
  • Identifying opportunities to improve incident investigation and response capabilities.
  • Working closely with wider Cyber Defence teams to strengthen security operations.
  • Developing and maintaining incident response playbooks, plans and knowledge base articles.
  • Providing guidance, coaching and support to junior and apprentice security analysts.
  • Participating in an out-of-hours on-call rota as part of the wider cyber defence function.

Requirements

  • Active SC clearance is mandatory.
  • At least 2–3 years' experience working as a Cyber Security Analyst or in a similar security operations role.
  • Proven experience investigating and responding to cyber security incidents.
  • Hands-on experience with SIEM tools, ideally Splunk.
  • Experience with Microsoft Sentinel, Microsoft Defender and/or KQL.
  • Strong understanding of threat actor TTPs and common cyber attack techniques.
  • Experience using security tools such as EDR and SIEM platforms.
  • Strong analytical and problem-solving skills.
  • Good verbal and written communication skills.
  • Experience working with cloud environments, such as AWS, would be beneficial.
  • Experience working within an Agile environment would be beneficial.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Incident command & response
  • Investigative casework
  • Security operations
  • Training & coaching delivery

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Security Architect - (Active SC Clearance Required)

    Sanderson Government & Defence · London

    Contract

    £500 – £550 a dayEstimated

    Your experience managing risk and applying security standards in policing gives you a strong foundation for security architecture.

    Posted Yesterday

  • Your evidence handling, chain of custody, and investigative discipline from policing are directly applicable to digital forensic investigations.

    Posted 7 days ago

  • Information Security Analyst

    Howard Kennedy LLP · London

    Full-time

    Your incident response and investigative discipline from policing directly apply to triaging and managing security alerts.

    Posted 7 days ago

  • SOC Team Lead

    Methods Business and Digital Technology · London

    Full-time

    £45,000 – £50,000Estimated

    Your incident command and crisis management experience translates directly to leading a SOC under pressure.

    Posted 8 days ago