Skip to main content
AfterDuty

Cyber Security Operations Specialist

Tank Recruitment · Bristol, South West England

Type
Full-time
Posted
8 days ago

Overview

Your incident command, evidence handling, and investigative skills are directly relevant to leading cyber incident response.

About this role

Cyber Security Operations Specialist

We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment.

You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate.

Key responsibilities

  • Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments.
  • Lead or support incident response, including containment, eradication, recovery and escalation.
  • Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities.
  • Reduce false positives and improve detection coverage using threat intelligence and incident learnings.
  • Investigate threats using frameworks such as MITRE ATT&CK.
  • Work closely with internal IT, engineering and security teams, alongside external security providers.
  • Maintain and improve security playbooks, procedures, documentation and response processes.
  • Support security reporting, compliance and audit activity.
  • Provide technical guidance and support to junior members of the security team.

Key skills and experience

  • Strong background in Security Operations, SOC or Incident Response.
  • Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.
  • Experience investigating security incidents across cloud and on-premise environments.
  • Knowledge of Windows environments, with working knowledge of Linux/Unix.
  • Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework.
  • Experience improving detection logic, alert quality and security controls.
  • Strong stakeholder communication and incident management skills.
  • Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial.

Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications.

The role will involve participation in an out-of-hours incident response rota, with occasional travel where required.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Bristol

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Contract

    Your investigative judgement and incident response experience from policing transfer directly to cybercrime analysis.

    Posted 6 days ago

  • SOC Analyst

    BeyondTrust · Bristol

    Full-time

    Your investigative judgement, evidence handling, and ability to work under pressure transfer directly to SOC triage and incident response.

    Posted 9 days ago

  • Your incident response and analytical skills from policing transfer directly to cybercrime detection and disruption.

    Posted 10 days ago

  • Incident Response Analyst

    AXA UK · Bristol

    Full-time

    Your incident command and evidence-handling discipline transfer directly to cyber incident response and forensic investigation.

    Posted 14 days ago