About this role
Security Clearance: Active SC Clearance required (Must be a British National and eligible to obtain higher levels of UK security clearance)
We're working with a leading organisation supporting critical national security programmes, who are looking to recruit an experienced*Security Analys*t to join their 24/7 Security Operations Centre (SOC)
You'll play a key role in monitoring, detecting and responding to cyber security threats across complex enterprise environments, working with industry-leading technologies includin*g Elast*ic an*d Splu*nk. This is an excellent opportunity for someone who thrives in a fast-paced operational environment and enjoys working on high-profile, mission-critical systems.
Key Responsibilities
- Monitor security alerts and events across enterprise environments usi*ng Elas*tic a*nd Spl*unk
- Investigate, triage and respond to security incidents in line with established playbooks and SLAs
- Perform threat hunting and proactive analysis to identify malicious activity.
- Analyse logs from endpoints, networks, cloud services and security tools to detect suspicious behaviour
- Escalate incidents where appropriate and work closely with engineering and incident response teams
- Develop and improve SIEM detection rules and alert tuning to reduce false positives
- Produce clear incident reports and maintain accurate documentation
- Participate in the on-call rota and support major incident response when required
- Contribute to the continuous improvement of SOC processes, tooling and operational procedures
Skills & Experience
- Experience working withi*n a 24/7 Security Operations Centre (*SOC) or equivalent cyber security environment
- Strong hands-on experience us*ing Ela*stic and*/or Sp*lunk for security monitoring and investigations
- Good understanding of SIEM technologies, log analysis and threat detections
- Knowledge of security frameworks such as MITRE ATT&CK and the Cyber Kill Chain
- Experience investigating phishing, malware, endpoint, identity and network security incidents
- Familiarity with Windows, Linux, Active Directory and cloud environments (AWS, Azure or Microsoft 365)
- Strong analytical and problem-solving skills with the ability to make decisions under pressure
- Excellent written and verbal communication skills
Essential Require
- Active SC Clearance
- British National, with eligibility to obtain higher levels of UK security clearance
- Willingness to wo*rk a 24/7 rotating shift pattern (4 days on rotation)*
- Able to work from the London office as required
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background
- Police experience explicitly valued
- Incident command & response
- Investigative casework
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |