About this role
Cyber Security Operations Specialist
We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment.
You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate.
Key responsibilities
- Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments.
- Lead or support incident response, including containment, eradication, recovery and escalation.
- Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities.
- Reduce false positives and improve detection coverage using threat intelligence and incident learnings.
- Investigate threats using frameworks such as MITRE ATT&CK.
- Work closely with internal IT, engineering and security teams, alongside external security providers.
- Maintain and improve security playbooks, procedures, documentation and response processes.
- Support security reporting, compliance and audit activity.
- Provide technical guidance and support to junior members of the security team.
Key skills and experience
- Strong background in Security Operations, SOC or Incident Response.
- Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.
- Experience investigating security incidents across cloud and on-premise environments.
- Knowledge of Windows environments, with working knowledge of Linux/Unix.
- Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework.
- Experience improving detection logic, alert quality and security controls.
- Strong stakeholder communication and incident management skills.
- Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial.
Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications.
The role will involve participation in an out-of-hours incident response rota, with occasional travel where required.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Bristol →Why this fits a police background
- Intelligence & OSINT
- Incident command & response
- Investigative casework
- Working to legislation & regulation
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |