Skip to main content
AfterDuty

Cyber Security Analyst

Sapphire Β· Glasgow, Scotland

Type
Full-time
Posted
17 days ago

Overview

Your incident response discipline and ability to follow procedures under pressure translate directly to triaging security alerts in a SOC.

About this role

πŸ” Tier 1 Security Analyst – Entry Level

πŸ“ Glasgow Office | πŸ•’ Full-time | Shift-based | 24/7 Rota Support (4 on / 4 off)

We have an exciting opportunity to join our Scottish office in Glasgow City Centre as a Tier 1 Security Analyst (T1SA) based in a state-of-the-art Security Operations Centre (SOC).

Description

The role of a T1SA is responsible for the first point of contact with security alerts. The primary responsibility is triaging security alerts following security playbooks and processes as part of initial incident investigations. Resolving or escalating Security Incidents as required and partaking in incident response tasks to assist with post-incident reviews will be central to the role.

T1SAs are responsible for being resourceful, adaptive and creative with the ability to work under pressure, including but not limited to working to mitigate the impact of live and ongoing security incidents.

This role encompasses building experience while leveraging the team’s expertise to accelerate learning and understanding of the Managed Services that are being delivered. This includes building expertise in cybersecurity and making use of the training resources that will be provided.

Key Activities & Responsibilities

  • Monitor and respond to security alerts generated by technologies such as SIEM, EDR, Microsoft Sentinel, vulnerability management, phishing and threat intelligence solutions within a given SLA.
  • Performing triage, in-depth analysis and investigation as guided by processes and playbooks.
  • Use sophisticated threat intelligence as part of investigations.
  • Conduct security investigations using historical data.
  • Conduct investigations with a wide range of data sets across multiple customer environments.
  • Develop and maintain a strong relationship with the client IT and Information Security team.

Technology Focus

Successful candidates will have a strong awareness of the cyber security industry and demonstrate knowledge with relevant certifications where appropriate for solutions, including XDR, SIEM solutions, Threat Intelligence, EDR, vulnerability management, network, cloud, Artificial Intelligence/Machine learning, SOAR, automation and endpoint security technologies.

You are required to attend the office on your daytime shifts.

🌍 We’re Committed to Inclusion

Sapphire is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees

πŸ”— Ready to make a difference?

Apply now and be part of a team that’s shaping the future of cybersecurity

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Glasgow β†’

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analystΒ£32,000–£45,000
DFIR consultantΒ£45,000–£65,000
Senior forensics / IR specialistΒ£60,000–£80,000
Threat-intelligence specialistΒ£55,000–£80,000
Full cyber security & digital forensics salary guide β†’

More cyber security & digital forensics jobs for ex-police

  • Digital Forensics & Insider Risk Analyst

    Morgan Stanley Β· Glasgow

    Full-time

    Your digital forensics and evidence-handling discipline from policing maps directly onto this insider risk investigation role.

    Posted 11 days ago

  • Full-time

    Β£39,767 – Β£45,472Estimated

    Your investigative mindset and intelligence analysis experience from policing directly apply to identifying and assessing cyber threats.

    Posted 16 days ago

  • Full-time

    Your incident command and evidence-handling skills directly apply to coordinating cyber incident response and maintaining chain-of-custody.

    Posted 17 days ago

  • Cyber Security Analyst

    The Scottish Government Β· Glasgow

    Full-time

    Β£62,111 – Β£77,439Estimated

    Your experience managing incidents, assessing threats, and leading multi-agency responses in policing directly translates to leading cyber incident management and risk assessments. The role's emphasis on stakeholder engagement and policy development mirrors the collaborative and procedural work you did in command or investigation roles. While deep technical cyber expertise may require upskilling, your operational discipline and strategic thinking make you a strong candidate for this managerial position.

    Posted 19 days ago