Skip to main content
AfterDuty

Cyber Security Analyst

eTeam · London, Greater London

Type
Contract
Posted
7 days ago

Overview

Your investigative mindset and threat assessment skills are an unusual fit for red teaming, but deep technical hacking is rarely a direct transition.

About this role

Role: Principal Offensive Security Operator

Contract Length: 12 months

IR35: In scope

Interview Process: Teams Interview

The Role

You will conduct safe, simulated cyber-attack simulations against our technology estates, acting as a real-world adversary might, to test our defences, highlight weaknesses and contribute cyber security expertise and insight in support of the department’s strategic security decision-making functions. You will be familiar with exploitation methodologies across a wide range of technologies, from classic enterprise technology stacks to modern digital services. You will have a well-developed ability to tactically assess and to execute a diversity of attack types, including chained attacks and evasion techniques, to achieve your desired goal.

You have a keen instinct for evading detection and avoiding disruption to clients operations.

Key Responsibilities

Designing and executing threat intelligence-based full-spectrum cyber-attack simulations, including long-term campaign planning, persistence, and post-exploitation operations against the client. Adopting a red team approach, discovering high-impact weaknesses across the organisation’s most important technology estates and business areas, and validating whether the overarching cyber security apparatus is working effectively.

Communicating technical findings in clear risk and impact-focused terms to senior stakeholders, enabling effective understanding and support for strategic decision-making.

Development and implementation of tools and methodologies to augment and to automate team offensive and analytical capability.

Mentoring junior Red Team members to improve their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cyber security in the department.

Person Specification

Essential

Proven ability to plan and execute complex, multi-phase operations.

Scenario-driven adversary simulation

Threat intelligence analysis and assessment

Exploitation of a wide range of technologies, including infrastructure, web application and cloud platforms: Microsoft Entra, Active Directory, M365, macOS. Kubernetes, CI/CD, AWS, Azure.

Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets

Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft

Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure, including relevant architectural and operational patterns of at-scale deployment and administration of complex legacy and modern enterprise environments.

Experience using, developing and deploying tools in support of red teaming activities, including attack infrastructure, C2 frameworks and infrastructure-as-code technologies.

Strong communication skills with the ability to clearly explain complex technical issues related to vulnerabilities and risk to diverse audiences, including senior stakeholders, in support of vulnerability management, threat mitigation, and risk-based decision-making.

Participation in GCASE / GBEST / CBEST / TIBER engagements.

Desirable

Experience in threat and/or vulnerability research, including publication and presentation to the wider cyber security community.

Background in a related a discipline, such as protective monitoring, incident response, security engineering or security architecture.

Certifications in the field of red team: CCSAS, CRTL

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Training & coaching delivery

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago