Skip to main content
AfterDuty

Graduate Cybersecurity Analyst

DF Capital · Manchester, Greater Manchester

Type
Full-time
Posted
Today

Overview

Your investigative mindset and incident response experience from policing are relevant, but this entry-level cybersecurity role demands strong technical IT knowledge (networking, cloud, security tooling) that most officers would need significant retraining to acquire. The role is designed for candidates with a computing background, not primarily for transferable policing skills.

About this role

We’re DF Capital – a specialist bank providing award-winning commercial finance, retail finance, and savings products to consumers and small businesses.

Based in Manchester, we serve thousands of customers across the UK and into Europe, supporting their ambitions with tailored financial solutions.

We help our customers realise their ambitions by doing things differently – combining the agility and innovation of a specialist lender with the security and service standards of a regulated bank. Whether it’s flexible lending structures or straightforward savings options, we focus on what matters most to our customers.

In 2025, we launched DF Capital Retail Finance – a subsidiary of DF Capital Bank Limited – to offer specialist hire purchase solutions to retail customers.

Our goal is simple: to do the absolute best for our customers, our communities, and each other.

The Role

The Junior Cyber Security Analyst will help protect DF Capital’s users, devices, cloud services, SaaS platforms and data. The role combines hands-on systems support with cyber security monitoring, secure configuration, vulnerability management, incident response support and emerging AI security controls. It is designed as a development role: strong foundational IT knowledge is expected, but the successful candidate may be fresh from university or early in their career, if they demonstrate the right security mindset, analytical ability and willingness to learn.

  • Monitor and triage alerts from security tooling, endpoint controls, identity platforms, cloud services and SaaS applications, escalating where required.
  • Assist with incident investigation by gathering evidence, checking user/device activity, reviewing logs, documenting actions and supporting containment steps.
  • Maintain accurate service desk and security incident records, ensuring decisions, evidence and follow-up actions are captured clearly.
  • Support strong identity hygiene, including MFA, conditional access, privileged access, joiner/mover/leaver controls and least-privilege access reviews.
  • Assist with endpoint security activities covering device health, encryption, patching, anti-malware/EDR status and secure configuration exceptions.
  • Help identify unusual access patterns, risky sign-ins and account misuse, working with the wider IT team and suppliers to remediate issues.
  • Support secure operation of cloud and SaaS environments by helping review configuration, access, logging, alerting and supplier security evidence.
  • Assist wider IT team with vulnerability remediation, secure configuration baselines and operational resilience activities.
  • Maintain documentation for cloud and SaaS security controls, including asset ownership, logging coverage, support contacts and escalation paths.
  • Support safe adoption of AI-enabled tools by helping assess data protection, prompt/data leakage, access control, model governance and supplier assurance considerations.
  • Assist with monitoring and control activities relating to sensitive data, data classification, data retention and inappropriate sharing of company information.
  • Contribute to AI security guidance, awareness material and practical checks that help colleagues use approved AI tools safely and responsibly.
  • Track vulnerabilities, misconfigurations and control gaps through to remediation, ensuring owners, priorities, evidence and exceptions are documented.
  • Support audit, Cyber Essentials Plus, ITGC, penetration testing and supplier assurance evidence gathering where required.
  • Create and maintain clear, usable procedures, runbooks, knowledge articles and technical notes for both IT colleagues and non-technical stakeholders.
  • Support cyber awareness initiatives, new starter cyber induction and practical guidance for employees on phishing, passwords, AI usage and secure working.
  • Communicate technical information in a clear, calm and approachable way, avoiding unnecessary jargon.
  • Develop a strong understanding of DF Capital’s business, risk appetite and regulatory environment so technical recommendations are proportionate and business aware.

Requirements*

At the very heart of every DF Capital employee is a shared identity and belief in what we are and what we do. It’s about how we see ourselves and what is important to us. You will live our brand values. As such you will be an approachable, empathetic problem solver, with exemplary communications skills. You will avoid the use of unnecessary jargon and display an adaptable, “can-do” attitude.

Essential skills, knowledge and behaviours

  • Degree, apprenticeship, placement experience or equivalent self-directed learning in cyber security, computer science, information technology, cloud, networking or a related discipline.
  • Good foundational understanding of operating systems, especially Windows, with awareness of Linux being beneficial.
  • Understanding of networking fundamentals such as DNS, DHCP, TCP/IP, VPNs, firewalls, web protocols and common authentication flows.
  • Awareness of core cyber security concepts including confidentiality, integrity, availability, phishing, malware, ransomware, vulnerability management, MFA, least privilege and secure configuration.
  • Basic understanding of cloud services, preferably Microsoft Azure and/or AWS, including identity, access, logging and shared responsibility principles.
  • Interest in AI security, including safe use of generative AI, data leakage, prompt injection, model governance, third-party AI tooling and responsible adoption of AI in business processes.
  • Ability to use or learn scripting/querying for investigation and automation, such as PowerShell, Python, SQL or KQL-style log queries.
  • Strong analytical mindset with the ability to investigate issues logically, document evidence and know when to escalate.
  • Clear written and verbal communication skills, including the ability to explain technical risk to non-technical colleagues.
  • High integrity, discretion and respect for confidentiality when handling security events, user information and sensitive business data.
  • Strong sense of ownership, attention to detail and ability to follow tasks through to completion.
  • Willingness to learn new technologies and maintain current knowledge of the cyber threat landscape.

Desirable skills and experience

  • Exposure to Microsoft 365 security, Entra ID, Defender, Intune, Sentinel, CrowdStrike, Arctic Wolf, vulnerability management platforms or similar tooling.
  • Familiarity with security alerts, log review, threat intelligence, incident playbooks, phishing analysis or endpoint investigation.
  • Understanding of regulatory and assurance expectations relevant to financial services, such as GDPR, operational resilience, Cyber Essentials Plus, ITGC or supplier assurance.
  • Experience supporting service desk, application support, cloud administration, infrastructure operations or technical project delivery.
  • Relevant certifications or active study towards certifications such as CompTIA Security+, Network+, Microsoft SC-900, AZ-900, AWS Cloud Practitioner or equivalent.

Benefits*

  • Private medical insurance for you and your partner
  • 10% Employer pension contribution
  • 30-day annual leave entitlement plus Bank/Public Holidays
  • Free Gym Membership
  • Discretionary annual bonus
  • Discretionary share awards
  • Life Assurance
  • Income Protection
  • Save As You Earn company share acquisition scheme
  • Tax efficient salary sacrifice scheme to obtain bicycles and electric vehicles
  • 4 days of paid Volunteering leave to support our local communities and causes important to you
  • A world class workspace; high-end, modern, and sophisticated office bursting with tech located in the creative district of Manchester.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Manchester

Why this fits a police background

  • Evidence & case files
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Cyber Incident Responder

    CYFOR · Manchester

    Full-time

    £40,000 – £50,000Estimated

    Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

    Posted Yesterday

  • Cybercrime Operational Lead

    HM Revenue & Customs · Manchester

    Full-time

    £65,869 – £72,711Estimated

    This role directly taps into your investigative and cybercrime expertise from policing, requiring you to lead digital forensics, intelligence operations, and complex criminal investigations. Your experience with evidence handling, interviewing, and operational command under pressure translates seamlessly into managing cyber threats and coordinating multi-agency responses at HMRC.

    Posted 9 days ago

  • Threat Analyst

    SCC · Birmingham

    Full-time

    Your background in intelligence analysis and threat assessment from policing maps directly to producing structured threat intelligence deliverables. You are used to researching hostile actors, evaluating sources, and writing concise briefings for different audiences, which is exactly what this role demands. Your incident response experience and disciplined approach to evidence and reporting would let you contribute from day one, while any gaps in specific tooling can be trained.

    Posted Today

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday